- Products
- Learn
- Local User Groups
- Partners
- More
Quantum Spark Management Unleashed!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Hi!
We're running our management on R81.10 with two dedicated vm's for management and log server.
These days we're looking into our backup and restore routines.
Until now we have been doing backup by scheduling migrate exports and chronjobs for copying the export to a scp-server.
This requires some degree of overhead in regards to custom scripts and chronjobs, so we have been looking into using "system backup" in gaia instead.
It seems to me like this is easier to handle and that you take backup the clish config and all necessary file such as vpnroute.conf in the same backup.
But we're not sure about this so my question is:
What is the trade off by using system backup instead of migrate export, what's the best practice for backup, and what are you guys doing for backup?
Feedback is much appreciated!
br
Jørgen
Hi
I would recommend going over the following SK and CheckMates post:
Best Practices - Backup on Gaia OS
VMware backup vs migrate export vs Gaia snapshot
Hi
I would recommend going over the following SK and CheckMates post:
Best Practices - Backup on Gaia OS
VMware backup vs migrate export vs Gaia snapshot
Put it this way...backup is more for the scenarios where say you make a change on the server and something does not work right and you simply wish to restore to working condition, you can do the restore from latest working backup...link @Tal_Paz-Fridman also explains that. Migrate export (or migrate server) starting from R80.20 is what you would use if you wish to, for example, import all the objects and licenses, along with policy rules (packages), vpn communities, etc, into the new management server.
Andy
Thanks all for the feedback, much appreciated!
From what I understand we want backup for disaster recovery and migrate_export is the one best suited for this.
To bring this topic to life, I was experimenting today with backups for the SMS (VM edition) and if SMS Gaia System backup is restored onto different VM configuration and different IP address it will restore only Gaia part which means objects and policies will be missing (but it will report restore operation as successful). But when I've done the same restore onto the another VM, but with the same configuration (CPU, HDD, RAM, IP address) I've got restored everything including management database (objects and policies) and even hot fixes are restored. I'm talking about R81.10 here.
Regards,
Igor
The backup itself does not actually restore hotfixes, only snapshot can do that.
Andy
I see, but this is different from what I'm experiencing. It was strange to me too, but restore target VM is isolated from the Internet, so unable to update itself automatically and after restore it had a Jumbo HF Take version that was on the original server and that HF version is not downloadable with CPUSE from Check Point anymore, so it had to came with the restore. Also, initially restore operation failed because HF incompatibility between target server and backup, so I had to use 'dbset backup:override_hfs t' command to be able to even continue with the restore.
I believe that these HFs aren't restored for real, but it is maybe just a false report from CPUSE after restore where backup defined what HFs must be installed and CPUSE just "believed" that they are installed indeed after the restore. Also, this test of mine is not exactly a real world example because in my case target server didn't had any HFs installed before restore (due to being isolated from the Internet - I had to use IP address used at the customer site in my lab for restore test) while in real life you will probably install latest HFs before attempting to restore.
Ok, I see what you are saying. I tested this in my lab, as well as with the customer 4 times and not a single time, did we get jumbo back on the box. Actually, every single time we did this, it was restore on EXACT same appliance, so there would be no possibility of issue with the config/interfaces etc...
Andy
Also, according to below, it would appear that is the case as well.
The snapshot creates a binary image of the entire root (lv_current) disk partition. This includes Check Point products, configuration, and operating system.
The log partition is not included in the snapshot. Therefore, any locally stored FireWall logs will not be saved.
System Backup can be used to backup current system configuration. A backup creates a compressed file that contains the Check Point configuration including the networking and operating system parameters, such as routing and interface configuration etc., but unlike a snapshot, it does not include the operating system, product binaries, and hotfixes.
Allows saving Gaia OS configuration settings as a ready-to-run CLI script. This allows you review your current setup and quickly restore the Gaia OS configuration.
For complete backup of the system and maximum confidence, Check Points recommends combining all three methods as part of the backup plan (Snapshot Management, System Backup/Restore, Save/Load Configuration). This will allow multiple restore points, redundancy and reliability of overall restore procedure.
Collect:
Anyway, I was testing it in the first place, but not because of HFs, but because the official documentation is unclear at least to me about SMS. Is the System Backup enough to backup SMS database as well, so that in case of loosing SMS VM I can restore all the policies and objects from the backup to the another VM (same "model")? At the end it was turned to be true, so I do not have to create a script for scheduled 'migrate_server' command execution for database export for backup purpose only.
Yea, thats fair. These days, I always tell customers to be prepared to install jumbo again if they do restore, but either way, I find that show configuration seems to be best method. One customer, they had always done same method for so many years...use isomorphic tool to reinstall new version, then copy all the config and install recommended jumbo for new version. That actually works real well.
Cheers mate.
Andy
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
7 | |
6 | |
4 | |
4 | |
4 | |
3 | |
2 | |
2 | |
2 | |
2 |
Tue 16 Sep 2025 @ 02:00 PM (EDT)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - AmericasWed 17 Sep 2025 @ 04:00 PM (AEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - APACWed 17 Sep 2025 @ 03:00 PM (CEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - EMEAThu 18 Sep 2025 @ 03:00 PM (CEST)
Bridge the Unmanaged Device Gap with Enterprise Browser - EMEAThu 18 Sep 2025 @ 02:00 PM (EDT)
Bridge the Unmanaged Device Gap with Enterprise Browser - AmericasTue 16 Sep 2025 @ 02:00 PM (EDT)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - AmericasWed 17 Sep 2025 @ 04:00 PM (AEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - APACWed 17 Sep 2025 @ 03:00 PM (CEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - EMEAThu 18 Sep 2025 @ 03:00 PM (CEST)
Bridge the Unmanaged Device Gap with Enterprise Browser - EMEAThu 18 Sep 2025 @ 02:00 PM (EDT)
Bridge the Unmanaged Device Gap with Enterprise Browser - AmericasAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY