| Backup Strategy

Don't restore a whole org to fix one firewall rule

Meraki org clone copies everything or nothing. Granular feature-level restore lets you fix exactly what broke without touching anything else.

When something breaks in a Meraki network, the instinct is to restore the entire configuration to the last known-good state. This instinct is wrong for most incidents.

Most incidents affect one thing

A bad firewall rule. A misconfigured VLAN. An SSID that was changed during a maintenance window and never changed back. The vast majority of Meraki configuration incidents are localized to a single feature or a small set of related features.

Restoring the entire organization configuration to fix one firewall rule is like reformatting a hard drive to delete one file. It works, but the collateral damage is significant.

The problem with full-org restore

Meraki’s built-in org clone and most backup scripts operate at the organization level. They copy everything or nothing. When you restore a full org:

  • Every configuration change made since the backup point is lost. Not just the bad change. The good changes too.
  • SSIDs that were intentionally updated get rolled back.
  • Firewall rules that were added for new clients get removed.
  • VLAN assignments that were corrected get un-corrected.

For an MSP managing a client environment where multiple technicians make changes daily, a full-org restore can cause more damage than the original incident.

Feature-level restore

The alternative is granular, feature-level restore. Instead of restoring the entire organization, you restore only the specific feature that broke.

Someone pushed a bad L3 firewall rule? Restore just the L3 firewall rules. The VLANs, SSIDs, VPN tunnels, traffic shaping rules, and everything else stays exactly as it is.

This requires a backup system that understands Meraki configuration at the feature level, not just as a single blob. It needs to back up each configuration type independently, version them independently, and restore them independently.

What granular restore looks like in practice

  1. Identify the affected feature (e.g., L3 Firewall Rules on the Acme Corp MX250)
  2. View the version history for that specific feature
  3. Compare the current configuration with a previous version (visual diff)
  4. Select the version to restore
  5. Preview exactly what will change
  6. Restore with one click

The entire process takes under 2 minutes. No other configurations are affected. No collateral damage.

The safety net

Even with granular restore, things can go wrong. The API might fail mid-restore. The backup might have an integrity issue. The network conditions might have changed since the backup was taken.

This is why atomic rollback matters. Before any restore operation, NET Backup Vault snapshots the current live configuration. If the restore fails at any step, it automatically reverts to the pre-restore state. A failed restore never makes things worse.

When full-org restore makes sense

Full-org restore has its place. If a Meraki device fails completely and the RMA replacement arrives blank, restoring all 19 configuration types at once is the right approach. If someone accidentally factory-resets an appliance, full restore is what you want.

But these are the exception. The daily reality of network operations is small, targeted changes that occasionally go wrong. For those situations, granular restore is the right tool.

Ready to protect your Meraki configs?

See how NET Backup Vault handles backup and restore for your environment.

See Pricing →