About Backup and Restore

The ability to recover from a disaster is an essential part of any system maintenance plan. As part of your disaster recovery plan, we recommend that you perform periodic backups to a secure remote location.

On-Demand Backups

You can perform on-demand backups for multiple Secure Firewall Threat Defense devices in CDO.

For more information, see Back Up Managed Devices.

Scheduled Backups

You can use the scheduler on CDO to automate backups. You can also schedule remote device backups from CDO.

The CDO setup process schedules weekly configuration-only backups, to be stored locally. This is not a substitute for full off-site backups. After initial setup finishes, you must review your scheduled tasks and adjust them to fit your organization's needs.

For more information, see Back Up Managed Devices.

Store Backup Files

When you back up a device, the cloud-delivered Firewall Management Center stores the backup files in its secure cloud storage.

For more information, see Back Up Managed Devices.

Restore Managed Devices

You must use the threat defense CLI to restore the threat defense device.

For more information, see Restore CDO-Managed Devices.

What Is Backed Up?

Device backups are always configuration-only.

What Is Restored?

Restoring configurations overwrites all backed-up configurations.

Make sure you understand and plan for the following:

  • You cannot restore what is not backed up.

  • The threat defense restore process removes VPN certificates and all VPN configurations from threat defense devices, including certificates added after the backup was taken. After you restore a threat defense device, you must re-add/re-enroll all VPN certificates, and redeploy the device.