- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Helloes.
We have a SCP backup running to a server today that i don't recall having any problems with when I set it up. Now we're going to move the backups to a new debian server. Seemed like the easiest thing in the world, but I just can't get it to work. And how are you supposed to troubleshoot?
I can SCP from the FW and transfer files, albeit not to the root directory since it's a chroot environment. But the backups are supposed to be stored in the /fw directory anyhow, and i can SCP files there.
In var/log/messages i can only see "xpand: failed to copy. fallback. trying to copy without the path." and then "exiting fallback".
there's another log called CPbackup.elg that even though there are lots of errors, doesn't have anything related to the problem.
Where do I look?
Funny thing this...
When I created the user, it was created with sh as shell. I didn't think much about it then, but now I changed the shell to bash and added the binary+libs to the chroot environment. And now it works...
So, checkpoints backup program definitly need bash.
It would still have been nice to have some sort of log to look in while troubleshooting, or to use SFTP, but at least it works.
Something that has worked for me in the past is ssh'ing to the backup server from expert mode and accepting the ssh key when prompted,
#ssh backupuser@1.2.3.4
I have added the host-key. I can ssh/scp from the FW to the server.
But I don't understand what the firewall backup function does differently.
EDIT: I would really have liked to use SFTP with keys instead of SCP. Is there any hint if SFTP will be added to the backup functionality?
Check the path and that user has write rights on the target server. If you are convinced there is no config issue, please open a support call for that.
I agree with @_Val_ . I had seen in the past that if you change the path on the server, it works fine. Cant say 100% it would fix it, but worth trying.
Funny thing this...
When I created the user, it was created with sh as shell. I didn't think much about it then, but now I changed the shell to bash and added the binary+libs to the chroot environment. And now it works...
So, checkpoints backup program definitly need bash.
It would still have been nice to have some sort of log to look in while troubleshooting, or to use SFTP, but at least it works.
I agree with you...if you cant find the right log, then it makes it more difficult, for sure. Glad it worked!
Only one small thing, the log in question, for this specific case, should be actually reviewed on the server side 🙂 All what Gaia has here is, "I cannot write to the remote folder". On the server, you should also see why.
Correct, bash should be the default shell for a backup user on the target server.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 23 | |
| 18 | |
| 7 | |
| 5 | |
| 4 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 2 |
Wed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY