Restore Policy, Then Rebuild the Rest
Cloud Restore brings back policy and SSL material bound to the activation key. It does not bring back the host — networking, OS configuration, and integration secrets stay missing, and a restore declared complete before those are checked leaves a proxy that looks configured and cannot pass traffic. Restore in two halves: what the backup covers, then what it does not.Validate prerequisites
Confirm:- SafeSquid is installed on the new or rebuilt appliance.
- The same activation key used for the backup is available. The backup is bound to it.
- The build record for the original host is at hand, for the settings the backup excludes.
- Cloud Restore was configured on the original appliance. See Configure Cloud Restore.
Restore the backed-up material
1
Activate with the original key
Activate the rebuilt appliance using the same activation key that produced the backup.Confirm activation succeeds and the licensed state is visible in the Configuration Portal.If activation fails, resolve it before attempting restore — the restore prompt only appears for an activated instance.
2
Trigger Cloud Restore
Select Cloud Restore in the Configuration Portal.Confirm the restore prompt appears. It is shown only when SafeSquid finds a cloud backup matching the activation key.If no prompt appears, the key does not match the backup. Check the key before assuming the backup is gone.
3
Restart to apply
Restart SafeSquid so the restored configuration takes effect.Confirm the service returns to a running state after the restart.If the service fails to start, inspect the service log before re-running the restore.
Restoring the original Root CA is what keeps already-deployed client trust valid. A rebuilt appliance with a newly generated CA forces a fresh trust rollout to every endpoint — which is usually discovered when users start seeing certificate warnings.
Verify what was restored
- Open the Configuration Portal.
- Navigate to Configure → Access Restriction, or any configured section.
- Confirm policies match the state from the original appliance.
- Check the SSL certificate under SSL Inspection, and confirm the certificate details match the original CA.
- Test a client connection through the rebuilt appliance.
Restore what the backup excluded
These are not in the cloud backup. Re-apply each from the build record:- Interface IP address, hostname, and routing.
- DNS and NTP configuration.
- Directory integration secrets and external connector settings.
- Operating system configuration and hardening.
- Log forwarding destinations and credentials.
Capture restore evidence
Store these artifacts with the incident or change record:- The date of the restore and the backup version it recovered.
- Confirmation that the restored Root CA matches the original, with issuer detail.
- The list of excluded items re-applied, and by whom.
- Client-side proof that traffic passes through the rebuilt appliance.
- Any policy difference found between the restore and the expected state.
Troubleshoot restore failures
Next steps
- Configure Cloud Restore - set up or repair the backup path.
- Backup Strategy - understand what the backup covers.
- Production-Readiness Checklist - re-validate before returning to production.

