SonicWall NSa2800 and NSa 3800 Settings Migration

Description

Introduction

The SonicWall NSa2800 and NSa3800 offer in-product migration, where you can import settings from select devices running a specific firmware. The settings import has some caveats, which are addressed in detail below.

Settings Import Feature:

  • Export/Import settings:
    Devices must be entirely configured from scratch in a typical greenfield deployment (new setup). Assuming you upgrade to the SonicWall NSa2800/NSa3800 from a select current generation or a previous generation firewall, you can leverage the in-product settings migration feature to import the settings (exp) file to the NSa2800/NSa3800.
  • Pre-Requisites: Supported Source Firewalls (Firewalls from which settings can be imported to NSa2800/NSa3800)

 

Source Firewall

Destination Firewall

GEN 7

NSa2800

NSa3800

TZ270

Y*

Y*

TZ270W

Y*

Y*

TZ370

Y*

Y*

TZ370W

Y*

Y*

TZ470

Y*

Y*

TZ470W

Y*

Y*

TZ570

Y*

Y*

TZ570P

Y*

Y*

TZ570W

Y*

Y*

TZ670

Y*

Y*

NSA2700

Y

Y*

NSA3700

Y*

Y

NSA4700

N

Y*

NSA5700

N

N

NSA6700

N

N

NSSP10700

N

N

NSSP11700

N

N

NSSP13700

N

N

NSSP15700

N

N

 

 

Source Firewalls

Destination Firewalls

GEN 6/6.5

NSa2800

NSa3800

SOHOW

Y*

Y*

SOHO250

Y*

Y*

SOHO250W

Y*

Y*

TZ300

Y*

Y*

TZ300P

Y*

Y*

TZ300W

Y*

Y*

TZ350

Y*

Y*

TZ350W

Y*

Y*

TZ400

Y*

Y*

TZ400W

Y*

Y*

TZ500

Y*

Y*

TZ500W

Y*

Y*

TZ600

Y*

Y*

TZ600P

Y*

Y*

NSA2600

Y*

Y*

NSA2650

Y#

Y*

NSA3600

Y*

Y*

NSA3650

N

Y*

NSA4600

N

Y*

NSA4650

N

Y*

NSA5600

N

N

NSA5650

N

N

NSA6600

N

N

NSA6650

N

N

SM9200

N

N

NSA9250

N

N

SM9400

N

N

NSA9450

N

N

SM9600

N

N

NSA9650

N

N

SM9800

N

N

NSSP12400

N

N

NSSP12800

N

N

 

Source Firewalls

Destination Firewalls

GEN 5

NSa2800

NSa3800

SOHO

Y*

Y*

 

Legend for the table above:

 

Y

Supported

N

Unsupported

Y*

Supported but import will fail if VLAN or Tunnel Interfaces are present in the settings file

Y#

In-Product Migration is Unsupported and Migration App accessible via NSM required to support settings Migration

 

 

Note: Due to an interface mismatch between NSa2650 and NSa2800, please use the Migration App on NSM to perform settings migration from NSa2650 to NSa2800.

Important: Importing settings from supported firewalls, except for NSa2700 to NSa2800 / NSa3700 to NSa3800, will fail if there are VLANs or tunnel interfaces. Please remove the VLAN or tunnel interface configuration for the settings import to succeed- Recommended. Alternatively, use the Existing Migration Tool to convert the settings to NSa2700/NSa3700 and import them to the firewalls.

 

  • Supported Source firewall firmware versions:

SonicOS 7

Firmware

Maintenance Release (MR)

7.1.2-x or newer

Maintenance Release (MR)

7.1.1-7051 or newer

Maintenance Release (MR)

7.0.1-5151 or newer 

General Release (GR)

7.0.1-5145 or newer 

 

SonicOS 6.5

Firmware

Maintenance Release (MR)

6.5.4.14 or newer

General Release (GR)

6.5.4.13-105n or newer

 

SonicOS 5

Firmware

Maintenance Release (MR)

5.9.1.8-10o or newer

Maintenance Release (MR)

5.9.2.14-12o or newer

General Release (GR)

5.9.1.7-2o

Maintenance Release (MR)

5.9.1.4-4o

 

  • Settings Migration Caveats:
    • Unsupported Settings that will need to be reconfigured
      • Certificates
      • If the target device does not support POE, POE-related configurations are dropped.
      • SNMP: if a SNMP view name contains a space or a quote, this name will be dropped
         
    • Unsupported Interfaces settings:
      • There will be a warning message displayed when importing settings from a source firewall that has W0/U1/MGMT interfaces, but the target does not. Any U1/W0/MGMT related default address objects and groups will be discarded upon import, and other configurations referencing these objects will be deleted or will need to be manually fixed after import.
      • Settings Import will be blocked if the source settings file contains the following interfaces:
        • VLAN Interfaces
        • Tunnel Interfaces
      • It is recommended that these interface settings be removed from the source firewall and then exported to the NSa2800/NSa3800, allowing the settings to be imported successfully.
      • As a workaround, users can utilize the Migration Tool to convert the export file containing the VLAN and Tunnel interfaces into settings for NSa2700/NSa3700 and use that file to import settings on NSa2800/NSa3800, respectively.
  • Settings Migration App on NSM:
    • NSM 3.0 introduces a new Migration App embedded into NSM. This migration app can be leveraged to support settings migration. At launch, it will support TZ80 and NSa2800. Support for NSa3800 will be added shortly.
      • SOHO/SOHO-W/SOHO250/SOHO250W → TZ80
      • NSa2600/NSa2650 → NSa2800

Related Articles

  • How to block ICMP (Ping ) using Application control
    Read More
  • SonicWall GEN8 TZ and NSa Firewalls FAQ
    Read More
  • How to configure Link Aggregation
    Read More
not finding your answers?