<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Better way to backup a firewall? in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Better-way-to-backup-a-firewall/m-p/170635#M30901</link>
    <description>&lt;P&gt;See, here is the issue...so say, just as an example, you have 2000 series box and you want to restore that backup to say 6000 series appliance. That would NEVER work, as interfaces and everything is different, so 2000 backup could not be restored and thats why you need to have show configuration from old appliance and then copy bits and pieces to new appliance.&lt;/P&gt;
&lt;P&gt;Here is what I always do. On old box, from expert mode, run -&amp;gt; clish -s "show configuration" &amp;gt; /var/log/config.txt and then save the file, copy it to a new appliance to same dir and then from clish on new appliance, run -&amp;gt; load configuration /var/log/config.txt and it would error out depending on the line and then you simply fix the line it complained about and do it again. You may have to do this few times (depending on the config), but it does work.&lt;/P&gt;
&lt;P&gt;Yes, I agree, its not the optimal way, but best I know of.&lt;/P&gt;
&lt;P&gt;Hope that helps.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Tue, 07 Feb 2023 19:13:24 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2023-02-07T19:13:24Z</dc:date>
    <item>
      <title>Better way to backup a firewall?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Better-way-to-backup-a-firewall/m-p/170631#M30900</link>
      <description>&lt;P&gt;We have been using the backup feature on the CLI, using the "add backup local" command, we would then copy the file off and store elsewhere. Recently we had a firewall fail and were shipped a replacement. We changed the OS version to 81.40, and applied the same hotfix, but the build was different, so the backup we had refused to restore because of a different build. We were able to recover by swapping the Hard Drive from the failed unit to the working unit.&amp;nbsp; The question I have is if i can't restore with the backups, why I'm I doing them. I have been copying off the config via CLI, with the idea of restoring the config on a replacement firewall and using a policy push to install the existing firewall rules on it. but there must be a better way to create backup/images/ whatever where it's not as picky about the current state of the replacement hardware when preforming a restore.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Feb 2023 18:42:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Better-way-to-backup-a-firewall/m-p/170631#M30900</guid>
      <dc:creator>TechGromit</dc:creator>
      <dc:date>2023-02-07T18:42:33Z</dc:date>
    </item>
    <item>
      <title>Re: Better way to backup a firewall?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Better-way-to-backup-a-firewall/m-p/170635#M30901</link>
      <description>&lt;P&gt;See, here is the issue...so say, just as an example, you have 2000 series box and you want to restore that backup to say 6000 series appliance. That would NEVER work, as interfaces and everything is different, so 2000 backup could not be restored and thats why you need to have show configuration from old appliance and then copy bits and pieces to new appliance.&lt;/P&gt;
&lt;P&gt;Here is what I always do. On old box, from expert mode, run -&amp;gt; clish -s "show configuration" &amp;gt; /var/log/config.txt and then save the file, copy it to a new appliance to same dir and then from clish on new appliance, run -&amp;gt; load configuration /var/log/config.txt and it would error out depending on the line and then you simply fix the line it complained about and do it again. You may have to do this few times (depending on the config), but it does work.&lt;/P&gt;
&lt;P&gt;Yes, I agree, its not the optimal way, but best I know of.&lt;/P&gt;
&lt;P&gt;Hope that helps.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 07 Feb 2023 19:13:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Better-way-to-backup-a-firewall/m-p/170635#M30901</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-02-07T19:13:24Z</dc:date>
    </item>
    <item>
      <title>Re: Better way to backup a firewall?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Better-way-to-backup-a-firewall/m-p/170636#M30902</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/86221"&gt;@TechGromit&lt;/a&gt;&amp;nbsp; restore from an existing backup requires same hardware, same software release and same hotfixes. The hardware and software release will be mandatory, wrong hotfixes can be used with a changed setting „dbset backup:override_hfs“. Follow&amp;nbsp;&lt;A title="Restore from Gaia system backup fails with &amp;quot;The following hotfixes seem to be missing&amp;quot;" href="https://support.checkpoint.com/results/sk/sk105883" target="_blank" rel="noopener"&gt;Restore from Gaia system backup fails with "The following hotfixes seem to be missing"&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you want a simple restore, you can create snapshots, export them and in the First Time Wizzard of the new appliance you can import these snapshot.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Question about you’re mentioned release 81.40. I think we are talking about 80.40 ?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Feb 2023 19:39:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Better-way-to-backup-a-firewall/m-p/170636#M30902</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2023-02-07T19:39:50Z</dc:date>
    </item>
    <item>
      <title>Re: Better way to backup a firewall?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Better-way-to-backup-a-firewall/m-p/170638#M30903</link>
      <description>&lt;P&gt;Different hardware, yes agreed it will never work.&amp;nbsp; Replacement hardware that is of the same model, a backup/image/snapshot should be restoreable. There may be some leg work involved to get it in the same OS family, like 81.40.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Feb 2023 19:30:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Better-way-to-backup-a-firewall/m-p/170638#M30903</guid>
      <dc:creator>TechGromit</dc:creator>
      <dc:date>2023-02-07T19:30:37Z</dc:date>
    </item>
    <item>
      <title>Re: Better way to backup a firewall?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Better-way-to-backup-a-firewall/m-p/170641#M30906</link>
      <description>&lt;P&gt;What&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1447"&gt;@Wolfgang&lt;/a&gt;&amp;nbsp;said is totally logical and correct and yes, I also believe you meant R80.40. Either way, command he gave actually ensures that backup bypasses any hotfixes needed and then you can install them manually later.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk105883" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk105883&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Feb 2023 19:55:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Better-way-to-backup-a-firewall/m-p/170641#M30906</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-02-07T19:55:21Z</dc:date>
    </item>
    <item>
      <title>Re: Better way to backup a firewall?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Better-way-to-backup-a-firewall/m-p/170643#M30908</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1447"&gt;@Wolfgang&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Question about you’re mentioned release 81.40. I think we are talking about 80.40 ?&lt;/SPAN&gt;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;probably I knew there was an 8 somewhere in the version. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Feb 2023 20:12:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Better-way-to-backup-a-firewall/m-p/170643#M30908</guid>
      <dc:creator>TechGromit</dc:creator>
      <dc:date>2023-02-07T20:12:00Z</dc:date>
    </item>
    <item>
      <title>Re: Better way to backup a firewall?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Better-way-to-backup-a-firewall/m-p/170646#M30909</link>
      <description>&lt;P&gt;In addition to copying Gaia configuration, scheduled backups are also preserving Check Point-specific configuration files (listed in sk160392).&lt;/P&gt;
&lt;P&gt;So for different use cases, any or all may be necessary:&lt;/P&gt;
&lt;P&gt;1. Gaia OS configuration file (created using save configuration &amp;lt;filename&amp;gt;), convenient, since with offline modifications, it could be easily loaded to a different hardware or VM.&lt;/P&gt;
&lt;P&gt;2. Appliance Snapshot (partition image recovery in case of RMA to identical appliance)&lt;/P&gt;
&lt;P&gt;3. Backup (much smaller than snapshot and could be used with last snapshot to bring gateway to the latest known good state)&lt;/P&gt;
&lt;P&gt;More on this in my book "Check Point Firewall Administration R81.10+", "Backup and&lt;BR /&gt;Recovery Methods" section of Chapter 6.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Feb 2023 20:27:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Better-way-to-backup-a-firewall/m-p/170646#M30909</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2023-02-07T20:27:45Z</dc:date>
    </item>
    <item>
      <title>Re: Better way to backup a firewall?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Better-way-to-backup-a-firewall/m-p/170685#M30914</link>
      <description>&lt;P&gt;Look into CDT, tht might be a great backup tool.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Feb 2023 09:13:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Better-way-to-backup-a-firewall/m-p/170685#M30914</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-02-08T09:13:03Z</dc:date>
    </item>
    <item>
      <title>Re: Better way to backup a firewall?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Better-way-to-backup-a-firewall/m-p/170711#M30915</link>
      <description>&lt;P&gt;Best summary of most options is found here: &lt;A href="https://support.checkpoint.com/results/sk/sk108902" target="_blank" rel="noopener noreferrer"&gt;&lt;SPAN&gt;sk108902: Best Practices - &lt;STRONG&gt;Backup&lt;/STRONG&gt; on &lt;STRONG&gt;Gaia&lt;/STRONG&gt; OS&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Feb 2023 12:36:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Better-way-to-backup-a-firewall/m-p/170711#M30915</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-02-08T12:36:40Z</dc:date>
    </item>
  </channel>
</rss>

