Hillstone Networks

Prepare Hillstone Networks devices for QUARK Config Backup.

This guide covers Hillstone firewalls running StoneOS (E-, T-, and X-series and their virtual equivalents).

Create a backup account

Create a dedicated administrator named netwatch-backup in the web UI under the system administrators settings. StoneOS supports role-based administrators; assign a read-only administrator role (such as the auditor/read-only role available in your release), which is sufficient for QUARK to display the configuration. Use the full administrator role only if your StoneOS version restricts configuration display for read-only roles.

Enable SSH

Allow SSH management on the interface the Netwatch collector will reach: in the interface's management settings, enable SSH alongside your existing management protocols. If you define trusted or permitted management hosts on the firewall, add the collector's IP address.

Platform notes

  • QUARK reads the running configuration with show commands over SSH and never enters configuration mode.
  • On systems using VSYS (virtual systems), create the account at root level so the complete configuration is visible.
  • If administrators are authenticated through an external server (RADIUS/TACACS+/LDAP), a locally defined netwatch-backup account is still recommended so backups keep working during authentication-server outages.

Enable backup in Netwatch

Once the device is prepared, open its host in Netwatch (Data collection > Hosts) and add the Config Backup macros — the supported status flag, the model code for this platform, and the credentials you created. See Getting started for the full macro list and values.

On this page