- Products
- Learn
- Local User Groups
- Partners
- More
Policy Insights and Policy Auditor in Action
19 November @ 5pm CET / 11am ET
Access Control and Threat Prevention Best Practices
Watch HereOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Does anyone know of a tool / script or an easy procedure to extract useful parts from a backup file?
I'm thinking of a "migrate export" format by repackaging the relevant files of a backup file and a conversion tool for converting the /config/inital file to clish configuration commands
Any help is appreciated,
Bernhard
In your case I would simply edit the configuration scheme for management backups
/var/CPbackup/schemes/mgmts.cpbakand have it including a migrate export directly into the backup archive. This way you can simply extract it whenever you need it.
Alternatively you could also create a second cron job that performs an migrate export one hour before your backup schedule. Just include the path and filename of the created archive within the INCLUDE_FILES section:
<INCLUDE_FILES>
BERNHARDS_MIGRATE_EXPORT.tgz
</INCLUDE_FILES>
I do know no tool, so the procedure would be to restore on a fresh install before performing migrate export and save configuration.
That's what i am aware of and wanted to avoid. Especialy because i think this is a task where the main parts of the code should be available already (at Check Point at least).
A really cool solution would be a BackupParserUtility (like the new DiagnosticView but fed with a backup-file instead of a cpinfo) and different export Features.
... just dreaming... could also add this request to the "Idea of the year section" ![]()
Such a tool surely is possible - in R77.30, you could perform that manually (by copying fwauth.ndb, lcrulebases_5_0.fws, rulebases_5_0.fws, fgrulebases_5_0.fws, slprulebases_5_0.fws and Objects_5_0.C from SMS /conf), but now, all data is in an SQL database. But honestly, where and for what purpose should such a tool be needed ? If i have a backup, i can get a working configuration in a very short time. And if - on SMS - i never do a migrate export i have only myself to blame 😉
Because it's easy to schedule and upload a backup to an external storage via clish. If i want the same with migrate export I have to write and schedule it myself (for scp, ftp, or whatever destination if want). Why doing it twice if the information is available in the backup file? And most of the time i need a migrate export instead of a full backup...
If you need a migrate export most of the time (i would suppose that for SMS, this is the ideal kind of backup), why not do it that way ? Easy to script and schedule in GAiA ! Is anyone else interested in such a tool ?
In your case I would simply edit the configuration scheme for management backups
/var/CPbackup/schemes/mgmts.cpbakand have it including a migrate export directly into the backup archive. This way you can simply extract it whenever you need it.
Alternatively you could also create a second cron job that performs an migrate export one hour before your backup schedule. Just include the path and filename of the created archive within the INCLUDE_FILES section:
<INCLUDE_FILES>
BERNHARDS_MIGRATE_EXPORT.tgz
</INCLUDE_FILES>
Thanks Danny. That's great alternatives to repackage a migrate export format from the backup.
Any ideas regaring the conversion of the /config/initial to clish configuration commands?
I can only find /config/db/initial and /config/db/initial_db
You are right. The correct path is /config/db/initial.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 25 | |
| 15 | |
| 13 | |
| 10 | |
| 6 | |
| 4 | |
| 3 | |
| 3 | |
| 3 | |
| 2 |
Wed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchWed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY