<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Backing up Maestro SMO/SGMs in Hyperscale Firewall (Maestro)</title>
    <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Backing-up-Maestro-SMO-SGMs/m-p/170971#M1422</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need some help with the backup procedure/what should be backed up on SGMs in a Maestro deployment. The documentation isn't particularly helpful when it comes to backing up SGMs and just links to the Gaia backup documentation. I understand the backup procedure for an Orchestrator, but;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Is switching to the SMO in each group, and then doing the 3 standard Gaia backups (OS, System, Snapshot) from clish (not gclish?) and then scping them up to the Orchestrator in Expert mode enough to consider that Security Group backed up? Or should the same 3 backups be captured from every gateway in the group?&lt;/LI&gt;&lt;LI&gt;Is it even possible to scp 'up'? using the account that was used to login to the Orchestrator to then copy off device? I found an sk that mentions creating an scpuser on the SMO/SGM and 'pulling' the file using the Orchestrator, but I've rather avoid having to create another account if I can.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
    <pubDate>Fri, 10 Feb 2023 11:56:39 GMT</pubDate>
    <dc:creator>danmn</dc:creator>
    <dc:date>2023-02-10T11:56:39Z</dc:date>
    <item>
      <title>Backing up Maestro SMO/SGMs</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Backing-up-Maestro-SMO-SGMs/m-p/170971#M1422</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need some help with the backup procedure/what should be backed up on SGMs in a Maestro deployment. The documentation isn't particularly helpful when it comes to backing up SGMs and just links to the Gaia backup documentation. I understand the backup procedure for an Orchestrator, but;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Is switching to the SMO in each group, and then doing the 3 standard Gaia backups (OS, System, Snapshot) from clish (not gclish?) and then scping them up to the Orchestrator in Expert mode enough to consider that Security Group backed up? Or should the same 3 backups be captured from every gateway in the group?&lt;/LI&gt;&lt;LI&gt;Is it even possible to scp 'up'? using the account that was used to login to the Orchestrator to then copy off device? I found an sk that mentions creating an scpuser on the SMO/SGM and 'pulling' the file using the Orchestrator, but I've rather avoid having to create another account if I can.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Feb 2023 11:56:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Backing-up-Maestro-SMO-SGMs/m-p/170971#M1422</guid>
      <dc:creator>danmn</dc:creator>
      <dc:date>2023-02-10T11:56:39Z</dc:date>
    </item>
    <item>
      <title>Re: Backing up Maestro SMO/SGMs</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Backing-up-Maestro-SMO-SGMs/m-p/170996#M1423</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;since all SGM have the same config, is not necessary create a backup for each SGM. the best is snapshot from local clish from SMO&lt;/P&gt;
&lt;P&gt;to export the snapshot you can use the webui for SMO to download it or use scp but that user needs expert user /bin/bash to be able to open with winscp or transfer to other device outside the SGM&lt;/P&gt;</description>
      <pubDate>Fri, 10 Feb 2023 13:03:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Backing-up-Maestro-SMO-SGMs/m-p/170996#M1423</guid>
      <dc:creator>Dario_Perez</dc:creator>
      <dc:date>2023-02-10T13:03:19Z</dc:date>
    </item>
    <item>
      <title>Re: Backing up Maestro SMO/SGMs</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Backing-up-Maestro-SMO-SGMs/m-p/171002#M1424</link>
      <description>&lt;P&gt;Some SK referenced in the following thread might also be useful for you:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Maestro/Maestro-Backup-Recommendations/td-p/154332" target="_blank"&gt;https://community.checkpoint.com/t5/Maestro/Maestro-Backup-Recommendations/td-p/154332&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Feb 2023 13:33:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Backing-up-Maestro-SMO-SGMs/m-p/171002#M1424</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-02-10T13:33:08Z</dc:date>
    </item>
    <item>
      <title>Re: Backing up Maestro SMO/SGMs</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Backing-up-Maestro-SMO-SGMs/m-p/171005#M1425</link>
      <description>&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;I'm working on automating the process of creating, pulling, and cleaning up the backups so I won't be able to use the Web UI unfortunately.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The documentation is lacking some of the command outputs and I don't actually have access to a Maestro deployment to test outputs, and I won't know how many Security Groups/SMOs there are ahead of time... is there a useful command that lists &lt;EM&gt;all&amp;nbsp;&lt;/EM&gt;the Security Groups, ideally with the internal management IPs, from the Orchestrator? the lldp command doesn't contain groups, but does contain IPs. I believe the 'show maestro security-group' command requires a group ID (which I won't know) so it can't list them all. The only way I've found so far is by pulling the info from the sgdb.json, but that doesn't have IP addresses unfortunately.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, is there any difference between members in the same group on different chassis? The sgdb.json file has members under a group like 1_1, 1_2, then, 2_1, 2_2.... do I need the backup from 1_1 and 2_1? or will 1_1 suffice?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Feb 2023 13:47:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Backing-up-Maestro-SMO-SGMs/m-p/171005#M1425</guid>
      <dc:creator>danmn</dc:creator>
      <dc:date>2023-02-10T13:47:46Z</dc:date>
    </item>
    <item>
      <title>Re: Backing up Maestro SMO/SGMs</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Backing-up-Maestro-SMO-SGMs/m-p/257941#M3637</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I'm wondering what you did because I have the same intention, automation.&lt;/P&gt;&lt;P&gt;Not only the doc is lacking but is contradictory. Some official sources states that the snapshot is recommended but the cli is giving the impression that is a restoring point.&lt;/P&gt;&lt;P&gt;I'm wondering if the old fashion way is still usable. Meaning if "&lt;SPAN&gt;add backup scp ip...&lt;/SPAN&gt;" is solving a problem in case of a crash.&lt;/P&gt;&lt;P&gt;Thanks for the feedback.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Sep 2025 18:58:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Backing-up-Maestro-SMO-SGMs/m-p/257941#M3637</guid>
      <dc:creator>Catalin_Ciubot2</dc:creator>
      <dc:date>2025-09-22T18:58:19Z</dc:date>
    </item>
  </channel>
</rss>

