2.4.1 Ensure 'System Backup' is set.

Information

List last-successful backup which is taken either locally or on a remote server. The backup can be taken locally on the device and also on a remote server via FTP, tftp or scp. The backup which is taken last is marked with (latest) in backup type.

Rationale:

The backup helps in restoring the configuration in the case of system failure or corruption or in the condition of device replacement.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Run the following command to Configure the backup.
CLI:

To take the backup local on the device.
Hostname> add backup local

To take the backup of FTP or SCP server.
Hostname>add backup [ftp|scp] ip [IP Address] path [Path to store backup] username [Username] password [Password]

To take the backup on tftp server.
Hostname>add backup tftp [IP address of tftp server]

GUI:

Navigate to Maintenance > System Backup > Backup > Select (This appliance | SCP Server | FTP Server | TFTP Server)

Default Value:

Not Configured

See Also

https://workbench.cisecurity.org/files/2828

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-2, 800-53|CM-6, CSCv7|5.2, CSCv7|5.5

Plugin: CheckPoint

Control ID: a3e9f9ee78131d9fdac4df8544eaed9849916d3775ae5e38c98f9426ecf3c268