Network Configuration Backup (NCB) is the process of saving your existing network configuration files. It enables quick recovery of devices from configuration failures, store configuration data centrally, and receive alerts. The most critical application to backup configuration is to restore network functions in times of a network disaster. Faulty configuration changes can cause network disasters like a data breach or even a network outage.
Configuration backup files
Configuration files are categorised into the following types:
Startup configuration
The startup configuration is the configuration your devices run on when they reboot or power up. Startup configuration files are used during system startup to configure the software.
Running configuration
Running configuration files contain the current configuration of the software. The running configuration file and startup configuration may not always be the same. There may be a case when you want to change the configuration for a short period of time, then you update the running configuration but you do not save the changes to the startup configuration file.
Permission-Based Access
For security reasons, a new permission-based access feature has been introduced for the Configuration Backup option for network devices:
- By default, the Configuration Backup option will not be visible unless the user has the necessary permissions.
- The Network Configuration tab under the resource will only be accessible to users with NCM View permissions or higher.
- The Set as Baseline option will only be available to users with NCM Manage permissions or higher.
Supported protocols
The gateway uses the following protocols to connect to end devices:
- SSH 2.x and higher
- Telnet
Prerequisites
Before running a Network Configuration Backup job:
- Network Configuration Backup is supported for network switches and routers.
- The device must be accessible from the gateway using either SSH or Telnet.
- Ensure that all required protocols are supported and enabled on the device.
- Create the job from Automation → Jobs v2 and select Network Configuration Backup as the job type.
- Apply a credential of type Network Configuration Backup to the device. Only one credential set of this type should be assigned per device.
Creating credentials
Follow these steps to create a credential:
- Click Setup → Account.
- From Account Details screen, click Credentials tile.
- Click +ADD. The ADD CREDENTIAL screen is displayed.
- From ADD CREDENTIAL, enter the name and description for credential.
- Select credential type as Network Configuration Backup.
- Enter username and configure the credential details:
| Field Name | Field Type | Description |
|---|---|---|
| Credential Type | Dropdown | Select credential type as NETWORK_BACKUP. |
| Name | String | Provide a name for the credential. |
| Description | String | Provide a brief description about the credential. |
| User Name | String | Enter the User Name. |
| Password Vault (Optional) | Checkbox | Select the checkbox to enable password vault options. The Integrations and Policy Mapping dropdowns are displayed. All installed Password Management integrations appear in the Integrations dropdown. Select an integration from the Integration dropdown. Select a vault policy from the Policy Mapping dropdown. |
| Password | String | Enter a strong password. |
| Confirm Password | String | Reenter the password. |
| Port | Integer | Enter the port number to establish an SSH or Telnet connection. |
| Transport Type | String | Determines the data transmission type: SSH or Telnet. |
| Auto Enable Mode | Checkbox | If enabled, an additional field appears to enter the enable password. |
| Enable Password | String | Enter the password required to execute the enable command after logging in. |
| Connection Timeout (ms) | Integer | Enter the connection timeout. Default is 10000 milliseconds. |
- Click Save.

Configuration backup job options
When creating a Network Configuration Backup job, the following options are available:
Startup Configuration: Enable this option to collect the device’s startup configuration.
Running Configuration: Enable this option to collect the device’s running configuration.
Version Saved
- All versions: Enable this option to save every configuration backup snapshot, regardless of whether changes have occurred.
- Save versions with changes only: Enable this option to save a configuration backup snapshot only when a change is detected in the device configuration.
Generate Alerts
These options are available only when their respective configuration backups are enabled:
- On changes to startup configuration: Enable this option to trigger an alert whenever a difference is detected between the newly collected startup configuration and the previously stored version.
- On changes to running configuration: Enable this option to trigger an alert whenever a difference is detected between the newly collected running configuration and the previously stored version.
Backup Trigger: Enable this option to automatically initiate a configuration backup when a configuration-change SNMP trap is received.
Retry Failed Devices: If enabled, the retry mechanism automatically retries configuration backups for devices that fail during the initial execution.
- Retry Count: The number of additional backup attempts.
- Retry Interval (mins): The time gap between each retry attempt.
For more information, see Network Configuration Backup Retry.
Resources: Add the resources from which configuration backup data needs to be collected.
Schedule
Choose how often the configuration backup job should run. The available scheduling options include:
- One Time: Executes the backup job only once at the specified date and time.
- Daily: Runs the backup job every day at the configured time.
- Weekly: Runs the backup job on the selected day(s) of the week at the specified time.
- Monthly: Runs the backup job on the selected date(s) each month at the specified time.

Comparing Configuration Versions in the New UI
You can compare the changes or differences between two versions of a configuration.
- Go to Infrastructure > Search > Others > Network Device, select the resource for which a network configuration backup job is configured.
- Click the resource and then click on Related info and then go to the Configuration Backup tab.
- Select the type of configuration Startup Config or Running Config.
- Select any two dates to compare the configuration between the dates and click Compare. You can view the difference between the two configurations between the selected dates.
Scenarios
A user wants to save every snapshot of configurations
Every snapshot of configuration can be saved by selecting the option All Versions for the job type Network Backup Configuration while creating a job.
A user wants to save snapshot only when configurations change
Snapshot of configuration change can be saved by selecting the option Save Versions with changes only for the job type Network Backup Configuration while creating a job.
A user wants to get alerts on configuration changes
User gets alerts when there is a change in configuration. Select Generate Alerts while creating a job to get the alerts on changes to the Startup configuration or on changes to the Running configuration.
A user wants to take a backup of a device
In this case, there is a configuration change trap (SNMP) generated on the device
A resource backup is done when you create the job. During job creation:
- Select the Network Backup Configuration job type.
- Select the Backup Trigger option.
Network Configuration Backup Retry
If enabled, the retry mechanism automatically retries configuration backups for devices that fail during the initial execution. You can configure the following.
- Retry count: The number of additional backup attempts.
- Retry interval: The time gap between each retry attempt.
- If a device backup fails, the system will retry based on the configured count and interval.
- Alerts are generated only after all retry attempts are exhausted. If any devices still fail after the final retry, an alert is triggered for those devices.
- If the retry mechanism is not configured, alerts are triggered immediately after the initial job attempt, following the standard alerting process.
Example 1:
If the retry count is set to 1 and the retry interval to 30 minutes, and the original job is scheduled for 10:00 AM, then:
- Initial backup runs at 10:00 AM.
- Retry for failed devices runs at 10:30 AM.
- If devices still fail after the retry, an alert is generated for those devices.
Example 2:
If the retry count is set to 2, the system will make two additional backup attempts after the initial failure, with each attempt spaced according to the configured interval at the time of job creation. Alerts will be sent only for the devices that are failed to collect the backup, in the final retry.
Retention policy
Rolling history of network configuration backup for each resource will be retained for 365 days.
From the first release of 2025, a copy of the latest network configuration for each resource is retained, if there are no recent backups from the last one year.
Supporting OS and Model Devices
Click here to view the supporting OS and Model devices
| OS | Model | Match case |
|---|---|---|
| WL-IOS Note: Added support from 16.1.0 version gateway | AIR-CT2504-K9 / 2500 WLC | contains |
| WL-IOS | equals | |
| FORTIOS | equals | |
| SB-IOS (or) SBIOS | equals | |
| XR-IOS | equals | |
| XE-IOS | FIREPOWER 3140 / FPR-3140-K9 | equals |
| XE-IOS Note: Added support from 19.1.0 GW version. | ISR4ISR 4 | equals equals |
| IOS | CSS11503 | equals |
| IOS | SG500 | contains |
| IOS | equals | |
| ASA | ASAV | equals |
| ASA | IPS | contains |
| ASA | ASA (or) Adaptive Security Appliance | equals |
| MLNX-OS | equals | |
| NXOS (or) NX-OS | UCS | contains |
| NXOS (or) NX-OS | equals | |
| CISCO UCS FIRMWARE (or) CISCO UCS | UCS | contains |
| NOS | equals | |
| FOS | SILKWORM SERIES OF FC SWITCH | contains |
| FOS | ACCESS GATEWAY (or) CONVERGE SWITCH | contains |
| FOS | equals | |
| MSS | equals | |
| JUNOS (or) JUNIPER OS | equals | |
| CATOS | equals | |
| PIXOS | equals | |
| PROCURVE | GBE2C | equals |
| PROCURVE | OFFICECONNECT SWITCH 1920S 24G 2SFP PPOE+ (185W) JL384A | contains |
| PROCURVE | equals | |
| SCREENOS | equals | |
| EOS (or) | equals | |
| ADEOS (or) ADE-OS | equals | |
| FORCE10 (or) FORCE 10 | equals | |
| VYATTA | equals | |
| NETSCALER | equals | |
| IRONWARE | ICX7150-24-POE (or) ICX7150-C12-POE (or) ICX7150-48-POEF | equals |
| IRONWARE Note: Added support from 17.1.0 version gateway. | ICX 6430 (or) ICX 6610-48 | equals |
| IRONWARE | equals | |
| PAN-OS (or) PANOS | equals | |
| VXWORKS | 10/100/1000 GIGABIT SWITCH | contains |
| VXWORKS | equals | |
| WAAS | equals | |
| ARUBAOS | R0X25A 6410 | equals |
| AOS-CXNote: Added support from 17.2.0 GW version. | equals | |
| ARUBAOS | IAP-VC | equals |
| ARUBAOS | JL076A (or) JL322A (or) JL320A (or) JL357A (or) JL558A (or) JL356A | equals |
| ARUBAOS | equals | |
| ACOS | equals | |
| AEROZOS | equals | |
| EXTREMEXOS | B5 (or) C2 (or) C3 (or) C5 (or) D2 | equals |
| EXTREMEXOS | BONDED SSA-T1068-0652A | equals |
| EXTREMEXOS | 1440 (or) 1480 | equals |
| EXTREMEXOS | equals | |
| SONICOS | equals | |
| COS | equals | |
| CISCOACSW | equals | |
| DELLPC | equals | |
| F5TMOS | equals | |
| MERUOS | equals | |
| ADTRANOS | equals | |
| COMWARE | 1910 | equals |
| COMWARE | 1920 | equals |
| COMWARE | 1950 | equals |
| COMWARE | JG937A (or) FLEXNETWORK 5130-48G-POE+-4SFP+ (370W) EI | equals |
| COMWARE | equals | |
| VIPTELAOS Note: Added support from 20.1.0 GW version. | VEDGE | equals |
| VIPTELAOS | equals | |
| BCF CONTROLLER OS | equals | |
| FXOS | FPR-2110, FIRE POWER 1140TD, FIREPOWER 2130 SECURITY APPLIANCE, FIREPOWER 4110 SECURITY MODULE 12, FIREPOWER 2120, FIRE POWER 1120TD, FPR4K-SM-36, FIREPOWER 9000 SECURITY MODULE 44, FIREPOWER 4120 SECURITY MODULE 24, FPR-1140-TD, FPR-1150TD, FPR-3120 | equals |
| FXOS | equals | |
| NGOS | equals | |
| LINUX | CBS350-48FP-4G | equals |
| LINUX | MEDIANT 2600 E-SBC | equals |
| LINUX | STEELHEAD CX7055 (CX7055M) | equals |
| FIREWARE (or) FIREWARE XTM | equals | |
| MRV-OD | equals | |
| LINUX | IM7200 and make = OpenGear | equals |
| OS10 | equals | |
| YAMAHA OS | equals | |
| AUDIOCODES (LINUX) | M800B | equals |
| VOSS | equals | |
| CUMULUS LINUX | equals | |
| ONYX-OS | equals | |
| DNOS | equals |
Version History
Click here to view the Integration Version History
| Application Version | Bug fixes / Enhancements |
|---|---|
| 20.1.0 |
|
| 20.0.0 | Network configuration backup support added for Cisco FPR-3120 (FX-OS). Earlier, these devices were not supported by OpsRamp Gateway. With this update, OpsRamp collects configuration backup for FPR-3120 firewall devices. |
| 19.2.0 |
|
| 19.1.0 | Enabled support to display SD-WAN configuration as startup configuration for devices with OS type XE-IOS and models starting with ISR4 or the ISR 4 series. Note: If the startup configuration retrieval fails, an alert will be shown. In cases where SD-WAN is not configured on these devices, users should disable the "startup configuration" option in the Network Configuration Backup job to retrieve the running configuration instead. |
| 19.0.0 | Added support to remove header and footer data from Palo Alto configuration backups. |
| 18.3.0 | Fixed an issue with Palo Alto configuration backups where certain configurations were not being correctly saved or restored. This has been fixed to ensure that all backup files capture the complete and accurate configuration data. |
| 18.2.0 | Added XML-based configuration backup support for Palo Alto. |
| 18.0.0 |
|
| 17.2.0 |
|
| 17.1.0 | Added configuration backup support for IRONWARE OS ICX 6610-48 model devices. |
| 17.0.0 |
|
| 16.1.0 | Added Network backup support for "WL-IOS" OS "AIR-CT2504-K9/ 2500 WLC" model switches. |
| 15.1.0 | Added fix to configuration backup connection issues. |
| 15.0.0 |
|
| 14.0.0 |
|