> Source: [sk180259](https://support.checkpoint.com/results/sk/sk180259)

# sk180259 - How to create AWS snapshot for CloudGuard Network Security Gateway 

| Property | Value |
|----------|-------|
| Solution ID | sk180259 |
| Date Created | 2022-11-10 |
| Last Modified | 2025-10-20 |
| Technical Level | General |
| Products | Cloud Firewall |
| Versions | R81 (EOS), R81.10 (EOS), R81.20, R82 |
| OS | Gaia |
| Platform | AWS |

## Solution

### **Instructions to create AWS snapshot for CloudGuard Network Security Gateway:**

1. Navigate to **AWS console** \> **EC2** \> **Instances** and select **CloudGuard EC2 instance** .  

2. Click on **Storage** tab.  

3. Click on the Volume ID of the selected instance.  

   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1668011984260/Snapshot-1202211091850191.png)  

4. Select the volume and on the right bar select **Actions** \> **Create snapshot** and wait until snapshot creation is completed.  

   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1668011984260/Snapshot-2202211091853112.png)  

### **Instructions to restore from AWS snapshot for CloudGuard Network Security Gateway:**

1. Navigate to **AWS console** \> **EC2** \> **Snapshots** .  

2. Select your snapshot and on the right bar select **Actions** \> **Create volume from snapshot**   

   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1668011984260/Snapshot-3202211091853413.png)  

3. Change the **Volume settings** (Volume type, Size, IOPS, Throughput and Availability Zone) as your original volume then click on **Create volume** .  

   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk180259/Snapshot-4202211101251571.png)  

4. Navigate to **AWS console** \> **EC2** \> **Instances** , select your target CloudGuard EC2 instance and stop it.  

   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk180259/Snapshot-5202211101255392.png)  

5. Click on **Storage** tab of the EC2 instance.  

6. Copy the **Volume ID** of the CloudGuard EC2 instance's original volume.  

   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk180259/Snapshot-6202211101258543.png)  

7. Navigate to **AWS console** \> **EC2** \> **Volumes** , search and select the copied volume id **Volume ID** and then detach it from the CloudGuard EC2 instance.  

   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk180259/Snapshot-8202211101301255.png)  

8. Select the newly created volume and click **Attach volume** .  

   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk180259/Snapshot-9202211101302286.png)  

9. Select:
   1. CloudGuard Network Gateway server as the target EC2 instance.
   2. Device name: /dev/xvda and click **Attach volume** .  

      ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk180259/Snapshot-10202211101317167.png)  

10. Start the CloudGuard Network Gateway.

**Reference** : [Create Amazon EBS snapshots](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ebs-creating-snapshot.html)

**Notes:**

* Snapshot of a Management solution is supported from version R81.10 and higher. The machine must be turned off when you take the snapshot.
* For Management HA environments (Security Management HA, Multi-Domain Security Management server, Multi-Log Management servers, Global Smart Event), you must take snapshots from all the machines in the environment at the same time, and under no circumstances when changes are done in the Domains' structure or in global/IPS/APPI policies.

### Risks

There is a risk of trying to restore from an "unclean" source. If you try to that a snapshot when some process is writing to the volume, write requests in the instance's kernel cache may not be written to disk or may only be partially written. These files would look corrupted on a volume made from the snapshot.

AWS recommends unmounting all volumes before taking a snapshot for this reason. See [Create Amazon EBS snapshots](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ebs-creating-snapshot.html).

If you cannot unmount / on a running instance, you can stop the instance from making the snapshot and we recommend to backup the volume.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
