- Products
- Learn
- Local User Groups
- Partners
- More
The State of Ransomware Q1 2026
Key Trends and Their Impact
Good, Better, Best:
Prioritizing Defenses Against Credential Abuse
AI Security Masters E7:
How CPR Broke ChatGPT's Isolation and What It Means for You
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
CheckMates Go:
CheckMates Fest
Does anyone know of a tool / script or an easy procedure to extract useful parts from a backup file?
I'm thinking of a "migrate export" format by repackaging the relevant files of a backup file and a conversion tool for converting the /config/inital file to clish configuration commands
Any help is appreciated,
Bernhard
In your case I would simply edit the configuration scheme for management backups
/var/CPbackup/schemes/mgmts.cpbakand have it including a migrate export directly into the backup archive. This way you can simply extract it whenever you need it.
Alternatively you could also create a second cron job that performs an migrate export one hour before your backup schedule. Just include the path and filename of the created archive within the INCLUDE_FILES section:
<INCLUDE_FILES>
BERNHARDS_MIGRATE_EXPORT.tgz
</INCLUDE_FILES>
I do know no tool, so the procedure would be to restore on a fresh install before performing migrate export and save configuration.
That's what i am aware of and wanted to avoid. Especialy because i think this is a task where the main parts of the code should be available already (at Check Point at least).
A really cool solution would be a BackupParserUtility (like the new DiagnosticView but fed with a backup-file instead of a cpinfo) and different export Features.
... just dreaming... could also add this request to the "Idea of the year section" ![]()
Such a tool surely is possible - in R77.30, you could perform that manually (by copying fwauth.ndb, lcrulebases_5_0.fws, rulebases_5_0.fws, fgrulebases_5_0.fws, slprulebases_5_0.fws and Objects_5_0.C from SMS /conf), but now, all data is in an SQL database. But honestly, where and for what purpose should such a tool be needed ? If i have a backup, i can get a working configuration in a very short time. And if - on SMS - i never do a migrate export i have only myself to blame 😉
Because it's easy to schedule and upload a backup to an external storage via clish. If i want the same with migrate export I have to write and schedule it myself (for scp, ftp, or whatever destination if want). Why doing it twice if the information is available in the backup file? And most of the time i need a migrate export instead of a full backup...
If you need a migrate export most of the time (i would suppose that for SMS, this is the ideal kind of backup), why not do it that way ? Easy to script and schedule in GAiA ! Is anyone else interested in such a tool ?
In your case I would simply edit the configuration scheme for management backups
/var/CPbackup/schemes/mgmts.cpbakand have it including a migrate export directly into the backup archive. This way you can simply extract it whenever you need it.
Alternatively you could also create a second cron job that performs an migrate export one hour before your backup schedule. Just include the path and filename of the created archive within the INCLUDE_FILES section:
<INCLUDE_FILES>
BERNHARDS_MIGRATE_EXPORT.tgz
</INCLUDE_FILES>
Thanks Danny. That's great alternatives to repackage a migrate export format from the backup.
Any ideas regaring the conversion of the /config/initial to clish configuration commands?
I can only find /config/db/initial and /config/db/initial_db
You are right. The correct path is /config/db/initial.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 33 | |
| 10 | |
| 9 | |
| 9 | |
| 8 | |
| 7 | |
| 7 | |
| 6 | |
| 5 | |
| 5 |
Tue 12 May 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall delivered as a serviceWed 13 May 2026 @ 11:00 AM (EDT)
TechTalk: The State of Ransomware Q1 2026: Key Trends and Their ImpactThu 14 May 2026 @ 07:00 PM (EEST)
Under the Hood: Presentando Check Point Cloud Firewall como ServicioTue 12 May 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall delivered as a serviceTue 19 May 2026 @ 06:00 PM (IDT)
AI Security Masters E8 - Claude Myphos: New Era in Cyber SecurityAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY