- Products
- Learn
- Local User Groups
- Partners
- More
Introduction to Lakera:
Securing the AI Frontier!
Quantum Spark Management Unleashed!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
For those running MDS management solution. What's your take on backup after R80.10? In our case in R77.30 backup was approx 3GB in size and it took less than half an hour to restore MDS and have it up and running. With R80.10 backup has grown to 18GB(!) within a year and actual process takes well over an hour if not closer to two. As an engineer I might accept the argument that R80.10 brought in so many new features thus increasing backup size but from business and disaster recovery point of of view it is complete shumbles.
Ironically it makes even support process painfully slow as I was asked to upload MDS backup yesterday and considering that CP FTP servers are over 50ms away from us, it will take couple of hours to complete that.
I have been raising SRs trying to point out inefficiency of MDS backup process for years - same MDS TGZ being archived and compressed 4 times... Seriously. In order to restore backup now (offcial MDS GAIA backup) we would need nearly 100GB free disk-space. Not that it costs too much money but it makes it so slow.
I'm not expecting many votes as probably not that many run MDS but still would be good to hear opinions about the matter
Great news Kaspars Zibarts
Hi Kaspars,
My name is Ran, I’m a TL in the Management R&D responsible for the repository of the Management server, including the PostgreSQL database.
We have identified the major issues causing the DB growth. We created a fix to prevent it from happening and a tool to clear up the historic growth which is not cleared with purge at the moment.
We are working to add them both to one of the next JHFs.
The good news is that you don’t have to wait. You can get them both privately now. All you need to do is open a support ticket with the relevant details: ‘MDS backup is too big’ and the current JHF you are using (latest is always recommended), you can mention my name as well so I can handle it faster.
Once we get your ticket we will create a private HF with the relevant content for you to deploy. We will also share the instructions for how to run the tool to clear up the historic growth.
Thanks,
Ran
Hello Ran,
Good to hear that there could be a solution for it. I had a long case regarding the sync between multiple domain servers caused by the big postgresql database. There was a lot of (old) data in it regarding compliancy. Does the fix also helps with the sync between MDS servers? if the postgresql database is smaller.
Kind Regards,
Sander Zumbrink
Hi Sander,
I'm sorry but I don't see the connection between sync issues and a big database. The only impact related I can think of is the time it takes for Full-Sync operation to complete.
Maybe in your case the database was so big and as a result the disc was completely full ?
If you have an SR number I can check.
Thanks,
Ran
Hello Ran,
At that moment the issues were disk full and time.
But now the issue has been resolved.
But the sync is still "slow" due to the large postgresql database.
So i was querious if the hotfix is also speeding up the sync between MDS servers.
Sander
Sanders,
What do you mean by 'slow sync' ?
The time takes for changes appear on the second machine ?
The time takes for Full-Sync to complete ?
Thanks,
Ran
Sander-
What JHF version are you running? There were Sync improvements and JHF154 should help with that...
Hi Brian,
How are you ?
I'm personally familiar with your environment, therefore we are already working with Support since Monday to prepare this fix for you
Thanks, Ran!
Interesting.. my case have been open for months and the last update was on 9th November saying part #1 is done.
I know it's 3 years later and 3 versions on... I thought a 7GB MDS backup was large, is this now the standard for an R80 MDS?
I don't recall my NG-AI MDS backups being more than a gig, for hundreds of customers/policies/revisions, yet I have a 4-CMA R80.40 MDS with about 80 policies (VSX mind you) and can't get the backup any smaller than 7GB. I'm sure I have seen odd things like binaries in backups too.
I agree with the UI improvements in R80 but I just don't think the whole layers of databases thing works for firewall management with all the problems I've had with them since. In contrast I manage another multi-tenanted environment with hundreds of devices and can export the entire configuration (including that of the devices) to a flat file of about 50MB - most of which are certificates and images used in response pages. I can also restore these environments with confidence in minutes and don't burn hours with "take forever, get to 99% and fail" type situations.
</rant> but I don't see this improving without a complete re-think and simplification of management (sorry Dorit) including things like gateway interaction, SIC (especially in VSX), configuration management, unification (1 UI for everything) instead of wrapping it all up in another database 🙂
@cosmos, there is always more room to improve and we welcome the feedback. I'd like to point out a few things that we have already done in the Check Point Management product:
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
24 | |
16 | |
4 | |
3 | |
3 | |
3 | |
3 | |
3 | |
2 | |
2 |
Tue 30 Sep 2025 @ 08:00 AM (EDT)
Tips and Tricks 2025 #13: Strategic Cyber Assessments: How to Strengthen Your Security PostureTue 07 Oct 2025 @ 10:00 AM (CEST)
Cloud Architect Series: AI-Powered API Security with CloudGuard WAFTue 30 Sep 2025 @ 08:00 AM (EDT)
Tips and Tricks 2025 #13: Strategic Cyber Assessments: How to Strengthen Your Security PostureThu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Wed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY