Cisco Meraki Firewall MX67

thoufeek
New here

Cisco Meraki Firewall MX67

How to take the backup of Cisco Meraki MX67 firewall

14 Replies 14
MarcP
Kind of a big deal

You could export the config through API... (?)

thoufeek
New here

Not tried yet. Still looks to be complicated. Either direct download or API. Need steps to do it.

 

MarcP
Kind of a big deal

Don´t see a point to do so anyways, haha

Whats the use-case?

 

Think about cloning the network if API is too much.

alemabrahao
Kind of a big deal
Kind of a big deal

To be honest, I think it's unnecessary, unless you want to move to a new organization.

Another thing you can do is simply clone a network, or even use templates for most things.

 

https://documentation.meraki.com/General_Administration/Organizations_and_Networks/Cloning_Networks_...

 

https://documentation.meraki.com/General_Administration/Templates_and_Config_Sync/Managing_Multiple_...

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
KarstenI
Kind of a big deal
Kind of a big deal

The Meraki Marketplace has a couple of toole to do this backup:

https://marketplace.cisco.com/en-US/home

If you found this post helpful, please give it Kudos. If my answer solves your problem, please click Accept as Solution so others can benefit from it.
RWelch
Kind of a big deal
Kind of a big deal

If you are worried or concerned about your current MXs longevity, you can always use the Replacing an Existing MX with a Different MX which walks through the process of removing the old MX and replacing it with a different MX - not sure exactly the reason for wanting or needing a backup config.

If you found this post helpful, please give it Kudos. If my answer solves your problem please click Accept as Solution so others can benefit from it.
jimmyt234
Head in the Cloud

We've had several customers explore this subject from the viewpoint of "what if someone malicious deletes all my dashboard config, how do we restore"

alemabrahao
Kind of a big deal
Kind of a big deal

Even if you make a backup, not all settings will be restorable via API.
There are other ways to prevent someone from improperly accessing your dashboard, one of which is to enable multi-factor authentication and use strong passwords.

It may not guarantee that no one who shouldn't have access will be able to access it, but it certainly makes it much more difficult.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
jimmyt234
Head in the Cloud

Agreed entirely, but you know how these tabletop exercises go, already assume "post breach/incident" etc 🙂

alemabrahao
Kind of a big deal
Kind of a big deal

I understand, but something that would worry me more than the settings in this case would be losing access to the dashboard and not being able to unclaim the devices to add them to a new organization if necessary.

 

Don't you think?

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
jimmyt234
Head in the Cloud

Great idea - rogue admin holds serial numbers hostage by transferring to their own Org... new exercise to discuss 🤣

RWelch
Kind of a big deal
Kind of a big deal

Makes sense from that perspective @jimmyt234.  Legal action and restart from scratch (unfortunately)....and be very selective to who has full organization admin permissions.

If you found this post helpful, please give it Kudos. If my answer solves your problem please click Accept as Solution so others can benefit from it.
jimmyt234
Head in the Cloud

Indeed, got to love "what if" scenarios!

RaphaelL
Kind of a big deal
Kind of a big deal

We have the exact same use case.  Ransomware , malicious employee and whatever. We built scripts to restore the org from scratch from daily config exports and obviously , APIs are the way to go

Get notified when there are additional replies to this discussion.