Fortinet black logo

Azure Administration Guide

Replacing the FortiAnalyzer

Copy Link
Copy Doc ID df509335-8675-11eb-9995-00505692583a:90501
Download PDF

Replacing the FortiAnalyzer

To replace the FortiAnalyzer:
  1. Create a new FortiAnalyzer resource in Azure in a location accessible by the FortiGate-VM in Subnet 1.
  2. Upload a valid license for the FortiAnalyzer. For details on how to do so, refer to the section Uploading files to the Storage account.
  3. Log in into the FortiAnalyzer-VM.
  4. (Optional) Restore a configuration from a backup.
  5. If necessary, create an admin user for FortiGate Autoscale to use. To retrieve the ones from the initial deployment, refer to the section Retrieving the FortiAnalyzer administrator username and password.
  6. Update the FortiAnalyzer public IP address resource by first dissociating the public IP address from the previous FortiAnalyzer and then associating the public IP address with the new FortiAnalyzer.
  7. If it is necessary to replace the public IP address, you will need to:
    1. Locate the Settings item with key: faz-ip. For details, refer to the section Modifying the Autoscale settings in Cosmos DB.
    2. Update the value to the new public IP address.
    3. Wait up to 60 seconds for the change to become effective.

Retrieving the FortiAnalyzer administrator username and password

During the initial deployment, these were specified in the template parameters FortiAnalyzer Autoscale Admin Username and FortiAnalyzer Autoscale Admin Password. These values can be retrieved after deployment using each of these methods:

  • Look them up in the deployment Inputs. For details, refer to the section Locating deployment Outputs.

  • Use the FortiAnalyzer CLI commands:
    config system admin user
    show

    The first line of the output contains the FortiAnalyzer Autoscale Admin Username.
  • Retrieve them from Key Vault > secrets. The FortiAnalyzer Autoscale Admin Username is stored as faz-autoscale-admin-username. For details, refer to the section Viewing and modifying secrets in the Key vault.

Viewing and modifying secrets in the Key vault

The first time you load the Key vault Secrets, you may need to grant permissions to your account.

To locate the Key vault secrets:
  1. Load the Autoscale resource group. For details, refer to the section To load a resource group:.
  2. Click the name of the item of type Key vault.
  3. From the navigation column, under Settings, select Secrets.
  4. If the warning “You are unauthorized to view these contents” is displayed, you will need to grant permissions to your account. For details on how to do this, refer to the section To grant permissions to your account:.
To grant permissions to your account:
  1. From the navigation column, under Settings, select Access Policies.
  2. From the right hand pane, click + Add Access Policy.
  3. For Configure from template (optional), select Secret Management.
  4. For Select principal *, click None selected and choose your account.
  5. Leave the Authorized application as is.
  6. Click Add.
  7. Click Save to apply the changes of granting your account permissions to the Secrets.
To view a stored secret:
  1. Click the secret you want to modify. In the example below, faz-autoscale-admin-username is selected.
  2. Click the item under CURRENT VERSION.
  3. Click Show Secret Value.
  4. In this example, the secret value is autoscale-admin.
To modify a secret:
  1. Click the secret you want to view. In the example below, faz-autoscale-admin-password is selected.
  2. Click + New Version.
  3. Enter the new secret in the Value * field and then click Create.

Replacing the FortiAnalyzer

To replace the FortiAnalyzer:
  1. Create a new FortiAnalyzer resource in Azure in a location accessible by the FortiGate-VM in Subnet 1.
  2. Upload a valid license for the FortiAnalyzer. For details on how to do so, refer to the section Uploading files to the Storage account.
  3. Log in into the FortiAnalyzer-VM.
  4. (Optional) Restore a configuration from a backup.
  5. If necessary, create an admin user for FortiGate Autoscale to use. To retrieve the ones from the initial deployment, refer to the section Retrieving the FortiAnalyzer administrator username and password.
  6. Update the FortiAnalyzer public IP address resource by first dissociating the public IP address from the previous FortiAnalyzer and then associating the public IP address with the new FortiAnalyzer.
  7. If it is necessary to replace the public IP address, you will need to:
    1. Locate the Settings item with key: faz-ip. For details, refer to the section Modifying the Autoscale settings in Cosmos DB.
    2. Update the value to the new public IP address.
    3. Wait up to 60 seconds for the change to become effective.

Retrieving the FortiAnalyzer administrator username and password

During the initial deployment, these were specified in the template parameters FortiAnalyzer Autoscale Admin Username and FortiAnalyzer Autoscale Admin Password. These values can be retrieved after deployment using each of these methods:

  • Look them up in the deployment Inputs. For details, refer to the section Locating deployment Outputs.

  • Use the FortiAnalyzer CLI commands:
    config system admin user
    show

    The first line of the output contains the FortiAnalyzer Autoscale Admin Username.
  • Retrieve them from Key Vault > secrets. The FortiAnalyzer Autoscale Admin Username is stored as faz-autoscale-admin-username. For details, refer to the section Viewing and modifying secrets in the Key vault.

Viewing and modifying secrets in the Key vault

The first time you load the Key vault Secrets, you may need to grant permissions to your account.

To locate the Key vault secrets:
  1. Load the Autoscale resource group. For details, refer to the section To load a resource group:.
  2. Click the name of the item of type Key vault.
  3. From the navigation column, under Settings, select Secrets.
  4. If the warning “You are unauthorized to view these contents” is displayed, you will need to grant permissions to your account. For details on how to do this, refer to the section To grant permissions to your account:.
To grant permissions to your account:
  1. From the navigation column, under Settings, select Access Policies.
  2. From the right hand pane, click + Add Access Policy.
  3. For Configure from template (optional), select Secret Management.
  4. For Select principal *, click None selected and choose your account.
  5. Leave the Authorized application as is.
  6. Click Add.
  7. Click Save to apply the changes of granting your account permissions to the Secrets.
To view a stored secret:
  1. Click the secret you want to modify. In the example below, faz-autoscale-admin-username is selected.
  2. Click the item under CURRENT VERSION.
  3. Click Show Secret Value.
  4. In this example, the secret value is autoscale-admin.
To modify a secret:
  1. Click the secret you want to view. In the example below, faz-autoscale-admin-password is selected.
  2. Click + New Version.
  3. Enter the new secret in the Value * field and then click Create.