cancel
Showing results for 
Search instead for 
Did you mean: 

Backing up Network and security appliances

gkman
Level 5

Hello,

I recently received a request to look into options of using netbackup to backup network and security appliances and servers (such as cisco switches, palo alto firewalls, symantec endpoint protection, symantec messaging gateway, and etc)

I have looked at the "Database and Application Agent Compatibility List"  and found no mention there, but was hoping there was an option nonetheless (or maybe plans to enable this soon)

If netbackup is incapable to backup appliances, what would you recommend doing?

thanks in advance

4 REPLIES 4

vtas_chas
Level 6
Employee

Most appliances have a mechanism of backing themselves up built into their interface.  By design, they are closed environments and you can't perform things like backups directly against them. 

Are you just looking for a way to backup the configurations so you could import them into a new device if something failed?  Some devices allow you to run a backup of the running firmare and then copy the backup file to a network location.  You could use NBU to back up that network location.  I believe Cisco devices still allow you to FTP/TFTP the running configuration via their cron implementation, so if this is a high change environment you could automate that somewhat.  Your process will vary by device, though.

I'm not aware of any Enterprise backup solution that has an agent or policy type associated with appliance-type devices, because they aren't designed as Enterprise servers intended to have regular backups taken by a 3rd party.  As specific purpose systems they're walled gardens not open to agents or other external process connections like a server is.

Charles
VCS, NBU & Appliances

Thanks for the reply.
there is actually a product that claims to be able to backup appliances: http://www.backbox.co/

at my previous firm we had a scheduled script that used to connect via ssh to the appliance and back it up. I suppose I can write something like that myself, but it seems simple enough to have a product that already has the solution implemented.

If the appliances are virtual, it might be possible to backup them through the hypervisor.

Switches are probably another matter as they usually aren't virtual.

Wonder if this backbox is just fancy a way of doing the ssh scripts, their web page is not that informative about how the product actually works.

The standard questions: Have you checked: 1) What has changed. 2) The manual 3) If there are any tech notes or VOX posts regarding the issue

sdo
Moderator
Moderator
Partner    VIP    Certified

I'm with Charles on this one.  We use features within these appliances to FTP/SFTP their config and/or meta-data off-host and then backup those configs.  Because you'll find that the vendors of these black boxes usually state this as the only way to protect them.  And the vendors do not usually like to have third party software installed within their black boxes.  Same way we're not allowed to install thord party software inside NetBackup Appliances.