Ingate

Prepare Ingate devices for QUARK Config Backup.

This guide covers Ingate SIParator SBCs and Ingate Firewalls, which share the same software and administration model.

Create a backup account

In the web UI, create a dedicated administration account named netwatch-backup in the user administration settings. Ingate supports different account permission types; choose a read-only account type if your software version allows it to view the complete configuration, otherwise use a full-access account. QUARK never applies changes either way.

Enable management access

Ingate units restrict configuration access to explicitly allowed networks. In the access control settings for configuration/administration:

  • Allow management access from the network or host address of the Netwatch collector.
  • Enable SSH access to the unit if your deployment uses the CLI; otherwise ensure HTTPS management is permitted for the collector, since Ingate configuration can be retrieved through the management interface.

Keep the allowed-hosts list as narrow as possible — ideally the collector's IP plus your management stations.

Platform notes

  • The Ingate configuration model uses a preliminary configuration that must be applied before it becomes permanent; QUARK backs up the active (applied) configuration and never touches the preliminary one.
  • If you operate a failover pair, back up the active unit; verify after failover tests that the collector can still reach the management address.

Enable backup in Netwatch

Once the device is prepared, open its host in Netwatch (Data collection > Hosts) and add the Config Backup macros — the supported status flag, the model code for this platform, and the credentials you created. See Getting started for the full macro list and values.

On this page