Platform Module 03

Configuration Backup
& Change Governance

Every device configuration versioned, encrypted, diff-able, and rollback-ready — with compliance audit trails built in.


500+
Device Types
Cisco, Juniper, Fortinet, Palo Alto, F5, Arista & more
30s
Rollback Time
From finding a bad config to restoring previous version
100%
Encrypted Storage
AES-256 encryption at rest and in transit for every backup
7yr
Retention
Configurable retention policies aligned with compliance mandates

Network config governance
at enterprise scale

GlideHubAi's configuration backup module delivers multi-protocol credential management, flexible scheduling, and a Git-backed version store — extended with AI-powered change detection and compliance automation.

Multi-Protocol Backup Collection
  • SSH/Telnet pull — Connects to device, executes show commands (e.g. show running-config), stores full output. Supports SSH key and credential vault.
  • TFTP/FTP/SCP push — Instruct device to push its config to GlideHubAi's collector via TFTP or SCP — ideal for older devices that don't support modern SSH.
  • RESTCONF / NETCONF — Model-driven config retrieval from devices supporting RFC 8040 / RFC 6241 (Junos, IOS-XE 16.6+, Arista EOS).
  • Vendor APIs — Native API connectors for Fortinet FortiManager, Palo Alto Panorama, Cisco DNA Center, and F5 iControl REST.
  • Scheduled + event-triggered — Daily/hourly schedule OR trigger on syslog event (e.g. config change message received → backup immediately).
Intelligent Change Detection
  • Line-by-line diff engine — Git-style unified diff between any two config versions with syntax highlighting per vendor (Cisco IOS, Junos, FortiOS).
  • AI-classified changes — Each change line classified as: Security Policy, Routing Change, Interface Config, Access Control, or Other — automatically.
  • Unauthorized change alerts — Cross-reference config changes against approved change tickets; flag any change with no matching ITSM record.
  • Config compliance scoring — Score each device configuration against a security baseline (e.g. "password encryption enabled", "NTP configured", "unused interfaces shut").
  • Drift dashboard — Visual matrix showing which devices have drifted from their approved baseline — at a glance across thousands of devices.
One-Click Rollback
  • Select any version — Browse complete version history with timestamps, diff previews, and change author attribution.
  • Push via SSH/SCP — GlideHubAi connects to device and applies the selected configuration automatically. Supports Cisco configure replace for minimal disruption.
  • Staged rollback — Apply config to a staging device for verification before pushing to production (requires compatible hardware).
  • Approval-gated — Rollback can require change manager approval before execution — with full audit log of approval workflow.
  • Auto-verify — Post-rollback: re-poll device, confirm config hash matches expected, send success/failure notification.
Compliance & Audit
  • CIS Benchmarks — Built-in CIS Level 1/2 check library for Cisco IOS, Juniper JunOS, Palo Alto PAN-OS, and Fortinet FortiOS.
  • PCI-DSS controls — Automated checks for PCI DSS requirement 1 (firewall) and requirement 2 (secure defaults) with evidence export.
  • SOX / HIPAA templates — Pre-built compliance check sets aligned with SOX IT controls and HIPAA technical safeguards.
  • Evidence packages — One-click generation of audit evidence: config history, change log, compliance scores, approvals — packaged as a PDF/ZIP for auditors.
  • Immutable audit log — All access to configs, every download, every rollback — cryptographically signed and tamper-evident.
Config Diff Viewer
UNAUTHORIZED CHANGE
Device: core-router-01.dc1 Before: 2025-03-20 14:00 After: 2025-03-20 17:43 Changed by: UNKNOWN
interface GigabitEthernet0/0/0
ip address 10.0.0.1 255.255.255.0
- ip access-group SECURE_IN in
+ ip access-group OPEN_ACCESS in
duplex auto
speed auto
ip route 0.0.0.0 0.0.0.0 10.0.0.254
+ ip route 192.168.99.0 255.255.255.0 10.0.0.1
ntp server 10.0.1.5
- service password-encryption
⚠ AI ASSESSMENT: Security policy weakened · No matching change ticket · Rollback recommended
Device Profile Configuration Example
# Device credential profile device_profile: name: cisco-ios-ssh vendor: Cisco os: IOS 15.x / IOS-XE method: SSH2 credentials: vault: hashicorp-vault path: secret/network/cisco commands: backup: - terminal length 0 - show running-config schedule: cron: "0 2 * * *" on_change_syslog: true

Everything included in
GlideHubAi config backup

CapabilityFeature DetailIncluded
CollectionSSH/Telnet pull — show running-config
CollectionTFTP/FTP/SCP push from device
CollectionRESTCONF / NETCONF (RFC 8040 / 6241)
CollectionSyslog-triggered instant backup on change
VersioningGit-backed version history with UI diff viewer
Change DetectionAI-classified unauthorized change alerts
Change DetectionITSM ticket cross-reference (Jira/ServiceNow)
RollbackOne-click rollback with approval gate
ComplianceCIS Benchmark checks — 400+ built-in
ComplianceAudit evidence package — PDF/ZIP one-click
SecurityAES-256 encryption at rest for all backups
SecurityCredential vault integration (HashiCorp Vault)

Never lose control of a
config change again