SonicWall TZ80 In-Product settings migration

Description

The SonicWall TZ80 offers in-product migration where you can import settings from a SOHO/SOHOW device running a specific firmware. There are some caveats on the settings import, which are addressed in detail below.

 

Settings Import Feature:

  • Export/Import settings from SOHO/SOHOW to TZ80:
    • In a typical greenfield deployment (new setup), the device must be configured completely from sc. Assuming you upgrade to the SonicWall TZ80 from a SonicWall SOHO/SOHOW, you can leverage the in-product settings migration feature to import the settings (exp) file to the TZ80.
  • Pre-Requisites:
    • Supported Source Firewalls (Firewalls from which settings can be imported to TZ80)
      • SOHO
      • SOHOW
    • Supported Source firewall firmware versions:

SOHO Firewall

Firmware

Maintenance Release (MR)

5.9.1.8-10o or newer

Maintenance Release (MR)

5.9.2.14-12o or newer

General Release (GR)

5.9.1.7-2o

Maintenance Release (MR)

5.9.1.4-4o

 

SOHOW Firewall

Firmware

Maintenance Release (MR)

6.5.4.14 or newer

General Release (GR)

6.5.4.13-105n or newer

 

  • Settings Migration Caveats:
    • Settings that are not available on the SOHO platform that will not be supported on TZ80:
      • Advanced Switching (Not supported on TZ80)
      • Capture Client Enforcement and Integration (Not supported on TZ80)
      • Active/Active Clustering (Not supported on TZ80)
      • Active/Active DPI (Not supported on TZ80)
    • Unsupported Settings that will need to be reconfigured
      • CFS 3.0 (Replaced by CFS 5.0)
      • HA(Note: Only the HA control Interfaces need to be reconfigured)
      • Syslog Server (Note: Only applicable for SOHO to TZ80 settings migration)
      • VPN Policy Bound to Interfaces (Note: Only applicable for SOHO to TZ80 settings migration)
      • IP-Helper Policy (Note: Only applicable for SOHO to TZ80 settings migration)
      • Certificates
    • Unsupported Features in SonicWall TZ80:
      • Internal Wireless Configuration (Hardware Limitation)
      • Advanced Switching support
      • Capture Client Enforcement and Integration
      • PoE configuration (Hardware Limitation)
      • Port Redundancy
      • Active/Active Clustering
      • Active/Active DPI
      • L3 Link Aggregation
      • Dell Switch Integration
      • GMS Configurations
      • Capture Client Enforcement
      • Advanced BWM 
    • Unsupported Interfaces settings:
      Settings Import will be blocked if the source settings file contains the following interfaces:
      • Tunnel Interfaces
      • WLAN Tunnel Interfaces
      • VLAN Interfaces
      • Wiremode (Note: TZ80 does not support this mode)
      • TapMode (Note: TZ80 does not support this mode)
      • It is recommended that these interface settings be removed from the source firewall and then exported to the TZ80, allowing the settings to be imported successfully.

 

Key Points

  • The TZ80 supports in-product settings migration from SOHO/SOHOW.
  • There are prerequisites to supporting the settings migration, but not all features are supported.

Conclusion

Understanding the SonicWall TZ80's settings migration support helps save time when upgrading from a SOHO/SOHOW firewall by reusing the existing device configuration.

Related Articles

  • How to block ICMP (Ping ) using Application control
    Read More
  • SonicWall GEN8 TZ and NSa Firewalls FAQ
    Read More
  • How to configure Link Aggregation
    Read More
not finding your answers?