sk180259 - How to create AWS snapshot for CloudGuard Network Security Gateway
How to create AWS snapshot for CloudGuard Network Security Gateway
Product
- CloudGuard Network for AWS
Version
- R80.40 (EOS)
- R81 (EOS)
- R81.10 (EOS)
- R81.20
- R82
OS
- Gaia
Platform
- AWS
Last Modified
- 2025-10-20
Solution
Instructions to create AWS snapshot for CloudGuard Network Security Gateway:
Navigate to AWS console > EC2 > Instances and select CloudGuard EC2 instance.
Click on Storage tab.
Click on the Volume ID of the selected instance.
Select the volume and on the right bar select Actions > Create snapshot and wait until snapshot creation is completed.
Instructions to restore from AWS snapshot for CloudGuard Network Security Gateway:
Navigate to AWS console > EC2 > Snapshots.
Select your snapshot and on the right bar select Actions > Create volume from snapshot.
Change the Volume settings (Volume type, Size, IOPS, Throughput and Availability Zone) as your original volume then click on Create volume.
Navigate to AWS console > EC2 > Instances, select your target CloudGuard EC2 instance and stop it.
Click on Storage tab of the EC2 instance.
Copy the Volume ID of the CloudGuard EC2 instance’s original volume.
Navigate to AWS console > EC2 > Volumes, search and select the copied volume id Volume ID and then detach it from the CloudGuard EC2 instance.
Select the newly created volume and click Attach volume.
Select:
- CloudGuard Network Gateway server as the target EC2 instance.
- Device name: /dev/xvda and click Attach volume.
Start the CloudGuard Network Gateway.
Reference: Create Amazon EBS snapshots
Notes:
- Snapshot of a Management solution is supported from version R81.10 and higher. The machine must be turned off when you take the snapshot.
- For Management HA environments (Security Management HA, Multi-Domain Security Management server, Multi-Log Management servers, Global Smart Event), you must take snapshots from all the machines in the environment at the same time, and under no circumstances when changes are done in the Domains’ structure or in global/IPS/APPI policies.
Risks
There is a risk of trying to restore from an "unclean" source. If you try to that a snapshot when some process is writing to the volume, write requests in the instance's kernel cache may not be written to disk or may only be partially written. These files would look corrupted on a volume made from the snapshot.
AWS recommends unmounting all volumes before taking a snapshot for this reason. See Create Amazon EBS snapshots.
If you cannot unmount / on a running instance, you can stop the instance from making the snapshot and we recommend to backup the volume.