<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic AWS PAYG Security Management Server Backup in API / CLI Discussion</title>
    <link>https://community.checkpoint.com/t5/API-CLI-Discussion/AWS-PAYG-Security-Management-Server-Backup/m-p/206863#M8366</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;We are trying to backup our Check Point Security Management Server at regular intervals via a scheduled script (or better solution if it exists?). We are using the Check Point Security Management Server appliance from the AWS Marketplace and are using the PAYG licensing model. We are also running version R81.20.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Question:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Can we use the Management API to export the management database? I found this API call which appears to be very similar to the &lt;STRONG&gt;migrate_server export&lt;/STRONG&gt;&amp;nbsp;CLI command:&lt;/P&gt;&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/latest/APIs/#web/export-management~v1.9.1%20" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/latest/APIs/#web/export-management~v1.9.1%20&lt;/A&gt;&lt;/P&gt;&lt;P&gt;The one thing I'm not sure of is licensing - I don't see an option to exclude licenses. Since we are on PAYG, we have to exclude the license on export/import when using the migrate_server command (although I think the exclude license option is only on the import side now). In the past, I have successfully upgraded our SMS from version R81.10 to R81.20 using the migrate_server export/import commands successfully.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This SK mentions using migrate_server but I didn't see anything for using the Management API:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;How to back up Security Gateways and Security Management Servers deployed in a Public Cloud (Azure, AWS, GCP, OCI)&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk169814" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk169814&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This SK notes the importance of excluding the license on export/import if you are on PAYG licensing model:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;How to perform Advanced Upgrade for CloudGuard Management version in AWS, Azure, or GCP (Side-by-Side upgrade)&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk155632" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk155632&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 22 Feb 2024 15:51:42 GMT</pubDate>
    <dc:creator>jwayne5000</dc:creator>
    <dc:date>2024-02-22T15:51:42Z</dc:date>
    <item>
      <title>AWS PAYG Security Management Server Backup</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/AWS-PAYG-Security-Management-Server-Backup/m-p/206863#M8366</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;We are trying to backup our Check Point Security Management Server at regular intervals via a scheduled script (or better solution if it exists?). We are using the Check Point Security Management Server appliance from the AWS Marketplace and are using the PAYG licensing model. We are also running version R81.20.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Question:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Can we use the Management API to export the management database? I found this API call which appears to be very similar to the &lt;STRONG&gt;migrate_server export&lt;/STRONG&gt;&amp;nbsp;CLI command:&lt;/P&gt;&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/latest/APIs/#web/export-management~v1.9.1%20" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/latest/APIs/#web/export-management~v1.9.1%20&lt;/A&gt;&lt;/P&gt;&lt;P&gt;The one thing I'm not sure of is licensing - I don't see an option to exclude licenses. Since we are on PAYG, we have to exclude the license on export/import when using the migrate_server command (although I think the exclude license option is only on the import side now). In the past, I have successfully upgraded our SMS from version R81.10 to R81.20 using the migrate_server export/import commands successfully.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This SK mentions using migrate_server but I didn't see anything for using the Management API:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;How to back up Security Gateways and Security Management Servers deployed in a Public Cloud (Azure, AWS, GCP, OCI)&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk169814" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk169814&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This SK notes the importance of excluding the license on export/import if you are on PAYG licensing model:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;How to perform Advanced Upgrade for CloudGuard Management version in AWS, Azure, or GCP (Side-by-Side upgrade)&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk155632" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk155632&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2024 15:51:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/AWS-PAYG-Security-Management-Server-Backup/m-p/206863#M8366</guid>
      <dc:creator>jwayne5000</dc:creator>
      <dc:date>2024-02-22T15:51:42Z</dc:date>
    </item>
    <item>
      <title>Re: AWS PAYG Security Management Server Backup</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/AWS-PAYG-Security-Management-Server-Backup/m-p/208488#M8389</link>
      <description>&lt;P&gt;Is this something I should open a support ticket for?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2024 14:07:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/AWS-PAYG-Security-Management-Server-Backup/m-p/208488#M8389</guid>
      <dc:creator>jwayne5000</dc:creator>
      <dc:date>2024-03-12T14:07:10Z</dc:date>
    </item>
    <item>
      <title>Re: AWS PAYG Security Management Server Backup</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/AWS-PAYG-Security-Management-Server-Backup/m-p/208510#M8391</link>
      <description>&lt;P&gt;Try to use GAIA API for run-script:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/latest/GaiaAPIs/index.html#cli/run-script~v1.7%20" target="_blank"&gt;https://sc1.checkpoint.com/documents/latest/GaiaAPIs/index.html#cli/run-script~v1.7%20&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;You can execute commands.&lt;/P&gt;
&lt;P&gt;Another solution, you can add a script that does that, add it to script repository on the MGMT and use it from repository.&lt;/P&gt;
&lt;P&gt;Also, we have a dedicated solution for scheduled snapshot management if it helps you.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2024 15:05:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/AWS-PAYG-Security-Management-Server-Backup/m-p/208510#M8391</guid>
      <dc:creator>Amir_Senn</dc:creator>
      <dc:date>2024-03-12T15:05:33Z</dc:date>
    </item>
    <item>
      <title>Re: AWS PAYG Security Management Server Backup</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/AWS-PAYG-Security-Management-Server-Backup/m-p/208517#M8393</link>
      <description>&lt;P&gt;The management API does allow export/import of configuration similar to migrate_server.&lt;BR /&gt;However, I don't see an option to exclude the export/import of licensing using the API or if the licensing even comes across as part of this process.&lt;BR /&gt;Paging&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/37502"&gt;@Omer_Kleinstern&lt;/a&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2024 15:20:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/AWS-PAYG-Security-Management-Server-Backup/m-p/208517#M8393</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-03-12T15:20:30Z</dc:date>
    </item>
    <item>
      <title>Re: AWS PAYG Security Management Server Backup</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/AWS-PAYG-Security-Management-Server-Backup/m-p/208805#M8399</link>
      <description>&lt;P&gt;I'm using a scheduled script to backup MDS r81.20&amp;nbsp; running on an AWS EC2 instance (BYOL in our case). it was created using&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;mds_backup -b -d DESTINATIONFOLDER -l&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;and then it uploads it to S3.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;-b Batch mode - executes without asking anything.&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;-d &amp;lt;Target&amp;nbsp;Directory&amp;gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Specifies the output directory.&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;If not specified explicitly, the backup file is saved to the current directory.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;Tip : check this out! you already have a script on the Cloudguard instance&amp;nbsp; to connect to S3 bucket.&lt;/P&gt;&lt;P&gt;[Expert@mds:0]# /usr/bin/s3&lt;BR /&gt;usage: s3 [-h] [-i] [-k KMS-KEY-ID] [-r REGION] [-p] [-s DURATION[:METHOD]]&lt;BR /&gt;PATH [DATA]&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anyone have a script to backup security logs for a defined period? let's say script to check and archive logs created in the past 90 days, then ship them to a remote location?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2024 19:38:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/AWS-PAYG-Security-Management-Server-Backup/m-p/208805#M8399</guid>
      <dc:creator>sorinstf</dc:creator>
      <dc:date>2024-03-14T19:38:17Z</dc:date>
    </item>
    <item>
      <title>Re: AWS PAYG Security Management Server Backup</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/AWS-PAYG-Security-Management-Server-Backup/m-p/208808#M8401</link>
      <description>&lt;P&gt;The Linux "find" command can pull out files older than X days and can execute commands based on the result.&lt;BR /&gt;The following is a single line that will automatically back up any files older than 90 days via scp to a system:&lt;/P&gt;
&lt;P&gt;find $FWDIR/log/*.log* $FWDIR/log/*.adtlog* -mtime +90 -exec /bin/scp {} myuser@192.0.2.33:/disk/mybackup \;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2024 20:08:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/AWS-PAYG-Security-Management-Server-Backup/m-p/208808#M8401</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-03-14T20:08:19Z</dc:date>
    </item>
  </channel>
</rss>

