15-Day Free Trial

Every Config.
Every Night.

Backup Manager takes the configuration off every switch, router, firewall and server you own, on a schedule, and tells you the moment one of them changes. When something is misconfigured at 3am, you already have last night's config — and the diff that shows what moved.

15-day free trial One-command install Ubuntu & CentOS SSH / Telnet / HTTP Runs on your server Encrypted client code
http://your-server:3000/
Backup Manager dashboard showing device count, successful and failed backups, storage used, server CPU, RAM and disk utilisation, and a table of recent backup jobs

The Config You Need Is the One Nobody Saved

A switch dies on a Sunday. Someone changed a firewall rule and nobody remembers which. An auditor asks to see what a device looked like in March. Backup Manager exists so none of those is a bad afternoon.

A Night in the Life of Your Network

Nobody is awake for this. At the scheduled minute the server opens a session to each device, pulls its configuration, compares it with last night’s and closes the session. Here is that, in miniature.

Waiting for the schedule
Next run 02:00 00:02
Backup Manager backup-01 0 of 6 collected CORE-SW-01 192.0.2.10 · Cisco IOS queued EDGE-RTR-01 192.0.2.17 · Juniper queued FW-HQ-01 192.0.2.24 · Sophos queued DIST-SW-02 192.0.2.31 · Aruba queued WLC-01 192.0.2.38 · Ruckus queued APP-SRV-01 192.0.2.45 · Ubuntu 24.04 queued

Swipe the diagram to follow each device →

Elapsed 00:00 Copied 0 B Changed 0

    Everything You Need to Keep Configs Safe

    Twelve modules, all included — no paywalled features, no per-device add-ons.

    Scheduled Backups

    Pick a time per device and the backups stagger themselves, so forty switches do not all wake the network at 2am. Failed jobs retry on their own with a growing gap between attempts.

    Change Detection

    Every capture is compared with the one before it. When a config differs you get a line-by-line diff, who changed what and when — and a full version history to walk back through.

    Compliance Rules

    Check stored configs against your own rules — telnet still enabled, no AAA, weak SNMP strings, missing logging. Run them across the estate or against one device, and look back at how a config stood on an earlier day.

    SSH, Telnet or HTTP

    Modern SSH, legacy kit that only speaks old ciphers, gear that only offers Telnet, and firewalls with a config-export API. Host keys are remembered so a swapped device is noticed rather than trusted.

    Device Profiles

    Built-in command sequences for Cisco, Juniper, Aruba, MikroTik, D-Link, Sophos, Cambium and Ruckus — or write your own step by step, with enable prompts and pager handling.

    Restore

    Push any stored version back to a device, with a dry run first that shows exactly which commands would be sent. Every restore is logged with its full transcript.

    PDF Reports

    Backup summaries, compliance status, change history and device health as charted PDFs. Download on demand, or have them emailed weekly or on a date and time you choose.

    Off-Site Copies

    Mirror archives to S3-compatible storage so a lost backup server is not a lost backup. Grandfather-father-son retention keeps daily, weekly and monthly copies without filling the disk.

    Fast on Big Servers

    Large file trees are pulled over several SSH sessions at once and big files split into ranges, which took one real 1.6 GB backup from fourteen minutes to under five. Pick exactly which directories to include first.

    Health & Alerts

    A page that answers "what is broken right now" — devices that have never backed up, ones that stopped, ones failing repeatedly. Alerts by email, webhook or Slack when a job fails or a config changes.

    Encrypted at Rest

    Device passwords are encrypted with a key held separately from the session secret, archives can be encrypted on disk, and SSH sessions are closed as soon as a copy finishes rather than left idle.

    API, Tokens & Audit

    A token-authenticated REST API, CSV export, Prometheus metrics and an audit log of every action, so this fits the monitoring and reporting you already run.

    Install in One Command

    On a fresh Ubuntu or CentOS server — Node.js, every dependency, a locked-down service account and a systemd service that survives a reboot, all done for you.

    root@server — install
    $ curl -fsSL https://opsec.co.in/opsec/backup-manager/get.sh | sudo bash

    Then open http://your-server:3000 and sign in. The installation licenses itself for 15 days on first run. Full steps in the user guide.

    See It In Action

    The real console. Device names and addresses below are examples, not a live network.

    .../devices
    Backup Manager devices page listing network devices with host, platform, backup mode, schedule and retention

    Every device in one list — search, filter, and run a backup on demand from the row menu.

    .../changes
    Backup Manager configuration changes page showing which devices changed and how many lines were added or removed

    What changed, on which device, and when — with a line-by-line diff a click away.

    .../compliance
    Backup Manager compliance page showing rule results per device with pass and fail status

    Compliance across the estate, or one device against one stored configuration.

    .../backups
    Backup Manager backup storage page listing stored archives with size, status and completion time

    Stored archives with size and status — view a switch configuration in place, or download the lot.

    .../health
    Backup Manager health page showing devices that have never backed up, stopped backing up or are failing

    The page that answers "what is broken right now", before anyone has to ask.

    .../reports
    Backup Manager reports page with scheduled PDF reports and recipients

    Charted PDF reports, downloaded on demand or emailed on the schedule you set.

    Licensing That Stays Out of Your Way

    Install it and it licenses itself for 15 days — no key to type, nothing to register. Extend the term with us and the installation picks it up on its own.

    15-Day Trial, Automatically

    The clock starts when the software is first activated, not when a key was issued, so a full trial is a full trial.

    Works Air-Gapped

    No route to the internet? Send us the machine fingerprint from the Licence page and import the signed licence file we send back. No network needed, ever.

    Your Data Is Never Held Hostage

    If a licence lapses, new backups pause — but viewing, downloading, comparing and restoring everything already collected keeps working. Your configuration history is yours.

    Built For

    Stop Hoping Someone Saved That Config

    Install it on your own server in one command and try it free for 15 days, or talk to us and we'll help you roll it out across your network.