About Backup and Restore
The ability to recover from a disaster is an essential part of any system maintenance plan. As part of your disaster recovery plan, we recommend that you perform periodic backups to a secure remote location.
On-Demand Backups
You can perform on-demand backups for multiple Secure Firewall Threat Defense devices in Security Cloud Control.
For more information, see Back Up Managed Devices.
Scheduled Backups
You can use the scheduler on Security Cloud Control to automate backups. You can also schedule remote device backups from Security Cloud Control.
The Security Cloud Control setup process schedules weekly configuration-only backups, to be stored locally. This is not a substitute for full off-site backups. After initial setup finishes, you must review your scheduled tasks and adjust them to fit your organization's needs.
For more information, see Back Up Managed Devices.
Store Backup Files
When you back up a device, the cloud-delivered Firewall Management Center stores the backup files in its secure cloud storage.
For more information, see Back Up Managed Devices.
Restore Managed Devices
You must use the threat defense CLI to restore the threat defense device.
For more information, see Restore Security Cloud Control-Managed Devices.
What Is Backed Up?
Device backups are always configuration-only.
What Is Restored?
Restoring configurations overwrites all backed-up configurations.
Make sure you understand and plan for the following:
-
You cannot restore what is not backed up.
-
The threat defense restore process removes VPN certificates and all VPN configurations from threat defense devices, including certificates added after the backup was taken. After you restore a threat defense device, you must re-add/re-enroll all VPN certificates, and redeploy the device.