02-14-2023 03:06 AM
Hi Team,
What is the best solution to Backup our firewalls? As we have standalone firewalls we need to make sure we have backup collected and stored. Please let me know the best way. Thanks.
Regards,
Sanjay S
02-14-2023 07:27 AM
Hi @Sanjay_Ramaiah ,
That is a great question. You can manually export the configuration periodically, or you can automate it with a script to grab it via the API. https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cm7yCAC
For those customers with Panorama, it automatically stores the configuration files for each NGFW. You can schedule a config export using SCP or FTP. https://docs.paloaltonetworks.com/panorama/10-1/panorama-admin/administer-panorama/manage-panorama-a...
Thanks,
Tom
02-14-2023 11:25 PM
Thank you very much Tom for this information.
Just wanted to know when i export it from the Panorama, will the managed devices backup will be separately copied to the FTP server as an XML file or how?
For Example:
> I have 10Firewalls managed by Panorama. I want backup.xml file for each device copied to the FTP server. Will it work with Scheduled Config Export? If yes. then that is all i needed 🙂
Regards,
Sanjay S
03-29-2023 11:56 PM
Hi Tom,
Schedule Config Export doesn't seem to be working 😞 I can confirm the communication is all there between the SCP server and the Panorama. I also tested it and can confirm to see the Fingerprint. But still seeing the issue :(.
Anything additinal to do?
Regards,
Sanjay S
04-03-2023 12:20 AM
Hi All,
Can anyone help on this please.
Regards,
Sanjay S
04-03-2023 02:54 AM
Hi @Sanjay_Ramaiah ,
I already gave you the answer. With regard to the follow up questions, those are answered in the URL I posted. With regard to troubleshooting, there is a test button in the GUI. What error do you get? You can also use the Panorama CLI "test" command to test the SCP connection.
Thanks,
Tom
04-10-2023 03:32 AM
Select the firewall which u want to backup and export the configuration, while choose the location where you want to save that and set the file format as .XML
You can specify the backup file like which part u want to backup like config backup ,network setting ,etc.
while scheduling the backup you can select when to get the backup done weekly or monthly, and save to initiate the process. and it is recommended to save your backups on-premises or cloud.
04-12-2023 01:49 AM
Hi Tom,
Looks like the certificate issue. checked few of the KBs to update the key of the server but still the same issue.
Failed exporting config bundle via ssh to x.x.x.x. No ECDSA host key is known for x.x.x.x ...Host key verification failed...lost connection |
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!