- Products
- Learn
- Local User Groups
- Partners
- More
Secure Your AI Transformation
9 April @ 12pm SGT / 3pm CET / 2PM EDT
AI Security Masters E6: When AI Goes Wrong -
Hallucinations, Jailbreaks, and the Curious Behavior of AI Agents
Ink Dragon: A Major Nation-State Campaign
Watch HereCheckMates Go:
CheckMates Fest
I was in the process of writing a script that would grab the "show configuration" from every gateway, but found in the /var/tmp directory on my SMS the exact thing I was looking for. The directory contains a file titled "<IP Address>-configuration.elg" for every gateway that is managed by the SMS, and appears to get updated every day early in the morning. This is great, but now I'm trying to figure out where these files are coming from. There's nothing in the crontab that would account for this. What process, script, whatever is running that creates them? The SMS is R80.10.
Have you setup your gateways to actually run a daily backup and store it on the management server?
I checked on our MDS R80.10 and found 4 files there, but they were dated nov 2017, around the time we installed the boxes, so they are not updated.
I do recall that in the MDS in the first months we had the setting "Sync with usercenter - Sync once a day" turned on

Most probably this setting is on in your management and this will collect the config and upload them to the UC.
That is synchronising only devices names with serial numbers so later on licenses appear in UC with actual devices names and not uploading gateways configs to CP.
I have an MDS environment as well (separate from the SMS environment), and it does NOT have the configuration files that the SMS environment has. I have "Sync with User Center" enabled in both environments. I agree with Martin, the "show configuration" is not a part of this Sync.
Although it is not part of it, it would not hurt to turn it off and see what happens for a couple of days.
I just checked some environments and I also found it and also for SMB appliances (1100/1400).
edit: btw. I have it in my lab environment as well, where I have no backup at all!
So I think that confirms it's some kind of out the box behavior, now just to track down what's doing it...
I tried digging through logs in /var/log, $CPDIR/log and $FWDIR/log on Mgmt and GW by looking at timeframe of backup and didn't found any hint from where it comes....
I have a 1400 and a SMS 80.20 and I have the upload settings disabled and do not see the configuration files on the management server.
Maybe the difference is R80.20. I had the Sync disabled up until last week, but I have files in /var/tmp for some old gateways from last November, when Sync was not turned on.
Sort of curious have you checked cron? Just on there off chance (crontab -l) if you know what I mean
In the opening post he wrote that there's nothing in cron.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 79 | |
| 37 | |
| 17 | |
| 14 | |
| 13 | |
| 13 | |
| 11 | |
| 10 | |
| 9 | |
| 8 |
Wed 08 Apr 2026 @ 07:00 PM (CST)
ERM al Descubierto: Amenazas Ocultas que Pondrán a Prueba tu Empresa en 2026Fri 10 Apr 2026 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 45: Harmony SASE updateWed 08 Apr 2026 @ 07:00 PM (CST)
ERM al Descubierto: Amenazas Ocultas que Pondrán a Prueba tu Empresa en 2026Fri 10 Apr 2026 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 45: Harmony SASE updateTue 14 Apr 2026 @ 03:00 PM (PDT)
Renton, WA: Securing The AI Transformation and Exposure ManagementThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY