Checkpoint: Snapshot vs Backup

AllCheck PointFirewall
I apologize if you find some of this article to be redundant. I found most of the information under sk108902 of checkpoints Secure Knowledge Support center found here: Snapshot vs Backup

This is the verbiage used from the Checkpoint article above.
Snapshot Management 
The snapshot creates a binary image of the entire root (lv_current) disk partition. This includes Check Point products, configuration, and operating system. Starting in R77.10, exporting an image from one machine and importing that image on another machine of the same type is supported. The log partition is not included in the snapshot. Therefore, any locally stored FireWall logs will not be saved.


System Backup (and System Restore) 
System Backup can be used to backup current system configuration. A backup creates a compressed file that contains the Check Point configuration including the networking and operating system parameters, such as routing and interface configuration etc., but unlike a snapshot, it does not include the operating system, product binaries, and hotfixes.

I've been doing a lot of studying and have been trying to clearly call out the differences between Snapshot and Backup.

Snapshot is better when:
  • Backing up, when needing to include Hotfixes.
  • Backing up, when needing to restore from a different version.

Backup is better when:
  • Trying to get it done in the least amount of time.
  • Supporting automatic scheduling.




I've also highlighted in Green where each command is preferable.


Snapshot Management
snapshot

System Backup
backup
How much time does it take ?
30 - 60 minutes
5 - 30 minutes
Size of output file on Security Gateway
5-100 GB
Depends on configuration
Size of output file on Management Server
5-100 GB
5-100 GB
Does it back up Gaia OS configuration ?
Yes
Yes
Does it back up Products configuration ?
Yes
Yes
Does it back up Hotfixes ?
Yes
No (*)
Does it back up Check Point logs?
No
No
Does it support automatic scheduling ?
No
Yes
Can you restore from different version ?
Yes
No
Does it require to close SmartConsole GUI clients ?
No
R7x - No
R80 - Yes
Does it require to stop Check Point services?
No
No
Does it require reboot ?
No
No


Categories: All, Check Point, Firewall