BackUp Firewalls

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
Palo Alto Networks Approved
Palo Alto Networks Approved
Community Expert Verified
Community Expert Verified

BackUp Firewalls

L4 Transporter

Hi Team,

What is the best solution to Backup our firewalls? As we have standalone firewalls we need to make sure we have backup collected and stored. Please let me know the best way. Thanks.

Regards,

Sanjay S

7 REPLIES 7

Cyber Elite
Cyber Elite

Hi @Sanjay_Ramaiah ,

 

That is a great question.  You can manually export the configuration periodically, or you can automate it with a script to grab it via the API.  https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cm7yCAC

 

For those customers with Panorama, it automatically stores the configuration files for each NGFW.  You can schedule a config export using SCP or FTP.  https://docs.paloaltonetworks.com/panorama/10-1/panorama-admin/administer-panorama/manage-panorama-a...

 

Thanks,

 

Tom

Help the community: Like helpful comments and mark solutions.

Thank you very much Tom for this information.

Just wanted to know when i export it from the Panorama, will the managed devices backup will be separately copied to the FTP server as an XML file or how?

For Example:

> I have 10Firewalls managed by Panorama. I want backup.xml file for each device copied to the FTP server. Will it work with Scheduled Config Export? If yes. then that is all i needed 🙂

Regards,

Sanjay S

Hi Tom,

Schedule Config Export doesn't seem to be working 😞 I can confirm the communication is all there between the SCP server and the Panorama. I also tested it and can confirm to see the Fingerprint. But still seeing the issue :(.

Anything additinal to do?

Regards,

Sanjay S

Hi All,

 

Can anyone help on this please.

Regards,

Sanjay S

Cyber Elite
Cyber Elite

Hi @Sanjay_Ramaiah ,

 

I already gave you the answer.  With regard to the follow up questions, those are answered in the URL I posted.  With regard to troubleshooting, there is a test button in the GUI.  What error do you get?  You can also use the Panorama CLI "test" command to test the SCP connection.

 

Thanks,

 

Tom

Help the community: Like helpful comments and mark solutions.

Hi @Sanjay_Ramaiah 

Select the firewall  which u want to backup and export the configuration, while choose the location where you want to save that and set the file format as .XML 

You can specify the backup file like which part u want to backup like config backup ,network setting ,etc.

while scheduling the backup you can select when to get the backup done weekly or monthly, and save to initiate the process. and it is recommended to save your backups on-premises or cloud.

AbbasAli.S

Hi Tom,

Looks like the certificate issue. checked few of the KBs to update the key of the server but still the same issue.

Failed exporting config bundle via ssh to x.x.x.x. No ECDSA host key is known for x.x.x.x ...Host key verification failed...lost connection
  • 1781 Views
  • 7 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!