Chapter 10 Install and System Administration for FortiOS 5.0 : Basic Administration : Firmware : Backup and Restore an encrypted config file from a USB key
  
Backup and Restore an encrypted config file from a USB key
You can save and boot an encrypted configuration file from a USB key. The configuration will only load when rebooting the FortiGate unit with the USB key inserted.
The administrator must back up the configuration to the USB key using the command:
execute backup config usb-mode <password>
administrator backup the configuration, to the USB key ("exec backup config usb-mode")
Insert the USB key into any FortiGate unit running the same image/patch release as the FortiGate unit that created the configuration file
The Administrator runs the CLI command below to reboot the FortiGate unit and load the configuration file from the USB key:
execute restore config usb-mode <password>)
The FortiGate unit saves the password into the flash memory. When system boots, the FortiGate unit loads the configurations from the USB key using the saved password in the flash. This configuration is read-only. That is, no configuration changes can be made while running with the configuration. The administrator is not permitted to make any configuration changes while configurations are loaded from USB (read-only)
If the USB key is removed while the FortiGate unit is running, the FortiGate unit deletes the password from the flash memory and reboots.
See Also
Firmware
Downloading firmware
Upgrading the firmware - web-based manager
 
See Also
Configuration Revision
Upgrading the firmware - CLI
See Also
See Also
Firmware
Downloading firmware
Upgrading the firmware - web-based manager
 
See Also
Configuration Revision
Upgrading the firmware - CLI
Installing firmware from a system reboot using the CLI