How to restore DFW with backup file
search cancel

How to restore DFW with backup file

book

Article ID: 378110

calendar_today

Updated On:

Products

VMware vDefend Firewall

Issue/Introduction

This KB explains how to take DFW backup and restore

Environment

NSX-T 4.x

Resolution

To backup and restore DFW ,you have to export DFW configuration to take the backup and import the same configuration while restoring it.

Below are the steps involved.

1.Export or Import a Firewall Configuration

2.Save or View a Firewall Draft

3.Load and publish DFW config from draft.

 

1.Export or Import a Firewall Configuration

For DFW backup you have to export the DFW configurations , for restore you can import the same config.

Note 

When importing rules with groups, the groups must be created on the destination environment without typos. If not, you will get a Deleted_Object error message instead of the group name when importing the rules.

Editing the name of the Group to fix the typo does not fix the issue, because the UUID stays with the the original name.

https://docs.vmware.com/en/VMware-NSX/4.1/administration/GUID-FCE6567E-1174-49CC-90F1-BA7B695B28F0.html

2.Save or View a Firewall Draft

The imported configuration does not directly restore the backup but it is saved as a manual draft in NSX. You can view the draft to see what kind of configuration will restore.

https://docs.vmware.com/en/VMware-NSX/4.1/administration/GUID-F44F5876-A6CB-4030-B372-F3D6866BB147.html

3.Load and publish DFW config from draft.

Now you can select the configuration which has been imported and load the draft and publish it. This will restore the DFW configuration

https://docs.vmware.com/en/VMware-NSX/4.1/administration/GUID-C3AC5910-37AE-48AC-8FDD-7AED17274670.html

Note: Only DFW rule definition is restored not group definition. User need to ensure all the group/inventory definition are are created before they restored DFW configuration. Group/inventory definition are included as a part of NSX manager backup not in DFW export.