How to use the NSM Firewall Migration App

Description

NSM’s configuration migration feature streamlines firewall hardware upgrades by eliminating the need to manually recreate policies. Security rules, interfaces, VPNs, and other firewall configurations can be migrated in just a few clicks. This article explains how to migrate firewall configurations from supported legacy SonicWall firewalls to latest hardware




Resolution

  • Log in to MySonicWall.com
    Tip: To enable cloud Management on your firewall, please click here
  • Navigate to Service | Available Services, then click Capture Security Center to launch it.
  • Select Network Security Manager (NSM) and ensure that the correct and appropriate tenant where the firewall is registered is selected from the drop-down list.
    Tip: You can also access NSM directly by logging in to cloud.sonicwall.com.
  • Navigate to Firewalls | Config Migration.
    Note: Using this Migration app eliminates the need to manually remove VLANs, WLAN tunnels, or other tunnel interfaces before import.

  • From the Source Device drop-down list, select the source firewall and verify that it is running a supported firmware version. Supported Firmware Version illustrates the supported SonicOS versions for the source firewall, on which the source device should be running.Example: NSa 4700 selected as the source device.
    Note: Currently, only like-to-like device migrations are supported. The target device is automatically selected by the tool (for example, TZ570 → TZ580 or NSa 4700 → NSa 4800).


  • From the drop-down list, select the Target Device Firmware Version.
  • Upload the source settings file by either: Clicking Browse your computer, or Selecting Browse NSM backup. Once the file is uploaded, click Next.

  • Review the Migration Notice by clicking Click here, then click OK to proceed.
    Note: Migration Notice is presented to check for unsupported configurations that won’t be migrated. It is intended as guidance and does not prevent the migration from proceeding


  • Under Interface Mapping, click Auto Map, scroll down, and click Next.
  • A pop-up window will appear showing the file generation process.
  • Once the process completes, a confirmation message will appear stating: The target file is generated successfully. Click Download and import the generated file on the target device.

    Tip: Ensure that the target GEN8 firewall is running the appropriate and supported firmware version. For example, settings intended for SonicOS 8.1.0 are not supported and will not work on SonicOS 8.0.4.

FAQs

  • Can we migrate settings between GEN8 firewalls?
    Yes. Settings can be migrated between like GEN8 models, as well as from lower-end models to higher-end models.
  • Does the NSM Migration App migrate HA settings?
    Yes. High Availability (HA) settings are migrated. However, HA functionality is not automatically restored because the new firewall has a unique serial number. After migration, HA must be reconfigured using the new secondary device’s serial number. 
  • Will there be an upgrade to the NSM Migration App to support multiple target GEN8 devices instead of a 1-to-1 mapping?
    Yes. Support for migrating to multiple target GEN8 devices is planned for future SonicWall NSM releases. 
  • Does a GEN8 firewall require a migration tool when migrating from GEN6/GEN7 to GEN8?
    For fully supported devices, there is no requirement to use the NSM Migration App, as GEN8 firewalls include a built-in migration feature.However, if VLANs and tunnel interfaces are present, we recommend using the NSM Migration App to ensure a smoother and more comprehensive migration. 

Related Articles

  • Gen 6 NSv to Gen 7 NSv Upgrades
    Read More
  • How to Collect Debug CSE Logs on a SonicWall Firewall.
    Read More
  • How to Block Google QUIC Protocol on SonicOS 7?
    Read More
not finding your answers?