Ingate
Prepare Ingate devices for QUARK Config Backup.
This guide covers Ingate SIParator SBCs and Ingate Firewalls, which share the same software and administration model.
Create a backup account
In the web UI, create a dedicated administration account named netwatch-backup in the user administration settings. Ingate supports different account permission types; choose a read-only account type if your software version allows it to view the complete configuration, otherwise use a full-access account. QUARK never applies changes either way.
Enable management access
Ingate units restrict configuration access to explicitly allowed networks. In the access control settings for configuration/administration:
- Allow management access from the network or host address of the Netwatch collector.
- Enable SSH access to the unit if your deployment uses the CLI; otherwise ensure HTTPS management is permitted for the collector, since Ingate configuration can be retrieved through the management interface.
Keep the allowed-hosts list as narrow as possible — ideally the collector's IP plus your management stations.
Platform notes
- The Ingate configuration model uses a preliminary configuration that must be applied before it becomes permanent; QUARK backs up the active (applied) configuration and never touches the preliminary one.
- If you operate a failover pair, back up the active unit; verify after failover tests that the collector can still reach the management address.
Enable backup in Netwatch
Once the device is prepared, open its host in Netwatch (Data collection > Hosts) and add the Config Backup macros — the supported status flag, the model code for this platform, and the credentials you created. See Getting started for the full macro list and values.