Ivanti
Prepare Ivanti devices for QUARK Config Backup.
This guide covers Ivanti Connect Secure (ICS) secure access appliances, including appliances originally deployed as Pulse Connect Secure.
Ivanti Connect Secure (ICS)
Create a backup account. In the admin web UI, create a dedicated administrator — for example netwatch-backup — for QUARK. Ivanti Connect Secure supports delegated administrator roles, so assign the account a role limited to read-only access. The account must be able to view and export the system configuration; it does not need rights to modify any settings.
Enable management access. QUARK retrieves the ICS configuration through the appliance's management interface rather than a traditional CLI session, so the backup account must be permitted to sign in to the administrative interface. If you restrict admin sign-in by source address (realm or role restrictions), allow the Netwatch collector's IP address.
Platform notes.
- ICS does not expose its full configuration through an interactive SSH shell; the configuration is retrieved as an export through the management interface. Make sure configuration export is permitted for the backup account's role.
- If your appliance authenticates administrators against an external server (LDAP, RADIUS, SAML), create the backup account as a local administrator instead so backups keep working when the external server is unavailable.
- Retrieved exports can contain sensitive material such as certificates and shared secrets; QUARK stores them encrypted, but treat the backup account credentials with the same care as any other admin credential.
Enable backup in Netwatch
Once the device is prepared, open its host in Netwatch (Data collection > Hosts) and add the Config Backup macros — the supported status flag, the model code for this platform, and the credentials you created. See Getting started for the full macro list and values.