SonicWall GEN8 TZs and GEN8 NSas Settings Migration

Description

The SonicWall GEN8 TZ Series and GEN8 NSa Series firewalls introduce in-product migration capabilities that allow administrators to import configuration settings from supported legacy SonicWall firewalls. This greatly simplifies the upgrade process by eliminating the need for manual reconfiguration during hardware refresh or platform upgrade.

Settings Import Feature:

  • Export/Import settings
  • Devices must be entirely configured from scratch in a typical greenfield deployment (new setup). With GEN8 firewalls, you can import .exp configuration files from supported legacy devices, streamlining migration.
  • The GEN8 TZ and NSa firewalls support in-product migration from select current and previous generation SonicWall firewalls.
  • This feature is especially useful when upgrading from GEN6 or GEN7 models.

Key Benefits:

  • Reduces time spent on manual configuration
  • Maintains policy consistency across hardware generations
  • Simplifies deployments and rollback planning

Pre-Requisites: The following devices are supported as source firewalls from which settings can be exported and imported to GEN8 TZs and NSa models:

Source FirewallDestination Firewall
SonicOS 7 DeviceTZ80TZ280TZ380TZ380WTZ480TZ580TZ680NSa2800NSa3800NSa
4800
NSa
5800
TZ270NY*Y*Y*Y*Y*Y*Y*Y*Y*Y*
TZ270WNY*Y*Y*Y*Y*Y*Y*Y*Y*Y*
TZ370NY*Y*Y*Y*Y*Y*Y*Y*Y*Y*
TZ370WNY*Y*Y*Y*Y*Y*Y*Y*Y*Y*
TZ470NYYY*YYYY*Y*Y*Y*
TZ470WNY*Y*YY*Y*Y*Y*Y*Y*Y*
TZ570NYYY*YYYY*Y*Y*Y*
TZ570PNY*Y*Y*Y*Y*Y*Y*Y*Y*Y*
TZ570WNY*Y*YY*Y*Y*Y*Y*Y*Y*
TZ670NNNNYYYY*Y*Y*Y*
NSA2700NNNNNNNYY*Y*Y*
NSA3700NNNNNNNY*YY*Y*
NSA4700NNNNNNNNY*Y*Y*
NSA5700NNNNNNNNNYY
NSA6700NNNNNNNNNNY*
NSSP10700NNNNNNNNNNN
NSSP11700NNNNNNNNNNN
NSSP13700NNNNNNNNNNN
NSSP15700NNNNNNNNNNN

 

SonicOS 6/6.5 Device

TZ80

TZ280

TZ380

TZ380W

TZ480

TZ580

TZ680

NSa2800

NSa3800

NSa 4800

NSa 5800

SOHOW

Y*

Y*

Y*

Y*

Y*

Y*

Y*

Y*

Y*

Y*

Y*

SOHO250

N

Y*

Y*

Y*

Y*

Y*

Y*

Y*

Y*

Y*

Y*

SOHO250W

N

Y*

Y*

Y*

Y*

Y*

Y*

Y*

Y*

Y*

Y*

TZ300

N

Y*

Y*

Y*

Y*

Y*

Y*

Y*

Y*

Y*

Y*

TZ300P

N

Y*

Y*

Y*

Y*

Y*

Y*

Y*

Y*

Y*

Y*

TZ300W

N

Y*

Y*

Y*

Y*

Y*

Y*

Y*

Y*

Y*

Y*

TZ350

N

Y*

Y*

Y*

Y*

Y*

Y*

Y*

Y*

Y*

Y*

TZ350W

N

Y*

Y*

Y*

Y*

Y*

Y*

Y*

Y*

Y*

Y*

TZ400

N

Y*

Y*

Y*

Y*

Y*

Y*

Y*

Y*

Y*

Y*

TZ400W

N

Y*

Y*

Y*

Y*

Y*

Y*

Y*

Y*

Y*

Y*

TZ500

N

N

Y*

Y*

Y*

Y*

Y*

Y*

Y*

Y*

Y*

TZ500W

N

N

Y*

Y*

Y*

Y*

Y*

Y*

Y*

Y*

Y*

TZ600

N

N

Y*

Y*

Y*

Y*

Y*

Y*

Y*

Y*

Y*

TZ600P

N

N

Y*

Y*

Y*

Y*

Y*

Y*

Y*

Y*

Y*

NSA2600

N

N

N

N

N

N

N

Y*

Y*

Y*

Y*

NSA2650

N

N

N

N

N

N

N

Y#

Y*

Y*

Y*

NSA3600

N

N

N

N

N

N

N

Y*

Y*

Y*

Y*

NSA3650

N

N

N

N

N

N

N

N

Y*

Y*

Y*

NSA4600

N

N

N

N

N

N

N

N

Y*

Y*

Y*

NSA4650

N

N

N

N

N

N

N

N

Y*

Y*

Y*

NSA5600

N

N

N

N

N

N

N

N

N

Y*

Y*

NSA5650

N

N

N

N

N

N

N

N

N

Y*

Y*

NSA6600

N

N

N

N

N

N

N

N

N

N

Y*

NSA6650

N

N

N

N

N

N

N

N

N

N

Y*

SM9200

N

N

N

N

N

N

N

N

N

N

N

NSA9250

N

N

N

N

N

N

N

N

N

N

N

SM9400

N

N

N

N

N

N

N

N

N

N

N

NSa9450

N

N

N

N

N

N

N

N

N

N

N

SM9600

N

N

N

N

N

N

N

N

N

N

N

NSa9650

N

N

N

N

N

N

N

N

N

N

N

SM9800

N

N

N

N

N

N

N

N

N

N

N

NSSP12400

N

N

N

N

N

N

N

N

N

N

N

NSSP12800

N

N

N

N

N

N

N

N

N

N

N

 

SonicOS 5 Device

 TZ80

TZ280

TZ380

TZ380W

TZ480

TZ580

TZ680

NSa2800

NSa3800

NSa 4800

NSa 5800

SOHO

 Y

Y*

Y*

Y*

Y*

Y*

Y*

Y*

Y*

Y*

Y*

Legend for the table above:

Y

Supported

N

Unsupported

Y*

Supported but import will fail if VLAN or Tunnel Interfaces are present in the settings file.

Important: Please remove the VLAN or tunnel interface configuration for the settings import to succeed- Recommended. Alternatively, use the Existing Migration Tool to convert the settings and import them to the GEN8 firewalls.

Y#

In-Product Migration is Unsupported. Use Migration App via NSM to support settings Migration

TIP: Due to an interface mismatch between NSa2650 and NSa2800, please use the Migration App on NSM to perform settings migration from NSa2650 to NSa2800.  

NOTE: Settings imported from a firewall running 7.3.x and above with TOTP configured to SonicOS 8.0.0/8.0.1/8.0.2 will not be supported. Please upgrade to SonicOS 8.0.3 before importing settings from a firewall running SonicOS 7.3.0 with TOTP function enabled. 

Supported Source firewall firmware versions:

SonicOS 7

Firmware

Maintenance Release (MR)

7.1.2-x or newer

Maintenance Release (MR)

7.1.1-7051 or newer

Maintenance Release (MR)

7.0.1-5151 or newer

General Release (GR)

7.0.1-5145 or newer

 

SonicOS 6.5

Firmware

Maintenance Release (MR)

6.5.4.14 or newer

General Release (GR)

6.5.4.13-105n or newer

 

SonicOS 5

Firmware

Maintenance Release (MR)

5.9.1.8-10o or newer

Maintenance Release (MR)

5.9.2.14-12o or newer

General Release (GR)

5.9.1.7-2o

Maintenance Release (MR)

5.9.1.4-4o

Settings Migration Caveats:

Unsupported Settings that will need to be reconfigured

  • CFS3: If migrating from a GEN5 device, the CFS policies will be dropped.
  • VPN policy: If migrating from a GEN5 device, the interface it is bound to may be lost.
  • Ip-helper:  If migrating from a GEN5 device, some ip-helper policies configuration may be lost.
  • The contents of the certificates will not be migrated to the new device.
  • If the target device does not support POE, POE-related configurations are dropped.
  • On TZ80, L3 LAG and Port Redundancy related configurations are dropped.
  • BWM(Bandwidth Management) advanced configuration will be dropped.
  • Syslog server: If migrating from a GEN5 device, some configuration may be lost.
  • Log Automation: If migrating from a GEN5 device, the username and password of mail server settings will be dropped.
  • HA: If migrating from a GEN5 device, the HA control interface needs to be reconfigured.
  • SNMP: if a SNMP user name contains space, this user will be dropped. 

Unsupported Interfaces settings:

  • There will be a warning message displayed when importing settings from a source firewall that has W0/U1/MGMT interfaces, but the target does not. Any U1/W0/MGMT related default address objects and groups will be discarded upon import, and other configurations referencing these objects will be deleted or will need to be manually fixed after import.
  • Settings Import will be blocked if the source settings file contains the following interfaces:
    • VLAN Interfaces
    • Tunnel Interfaces
  • It is recommended that these interface settings be removed from the source firewall and then exported to the GEN8 TZ and NSa models, allowing the settings to be imported successfully.
  • As a workaround, users can utilize the Migration Tool to convert the export file containing the VLAN and Tunnel interfaces into settings for equivalent GEN7 models and use that file to import settings on same GEN8 models, respectively.
  • SonicWall TZ380W – Wireless specific caveats
    • SonicWall TZ380W will support simultaneous dual-band operation. To support this, we will use VAPs or Virtual Access Points settings for wireless configuration as the default setting.
    • Our goal is to retain the imported wireless setting after on-box import.

      source GEN5/GEN6/Gen7 TZW

      target Gen8 TZW expected behavior

      Radio Role: Access Point/station/AP&station/Mesh
      Radio Mode: 2.4G
      VAP mode

      Radio Role: retain from source
      2.4G radio config:
       retain from source
      5G radio config: default settings
      VAP mode with
       source VAP group

      Radio Role: Access Point/station/AP&station/Mesh
      Radio Mode: 5G
      VAP mode

      Radio Role: retain from source
      2.4G radio config: default settings
      5G radio config:
       retain from source
      VAP mode with
       source VAP group

      Radio Role: Access Point/station/AP&station/Mesh
      Radio Mode: 2.4G
      non VAP mode
      SSID and radio schedule, security, advanced and MAC filter list pages settings 


      Radio Role: retain from source
      2.4G radio config:
       retain from source
      5G radio config: default settings
      VAP mode with
       default VAP group contains default VAP object
      Source SSID and radio schedule, security, advanced and MAC filter list pages settings will apply to default VAP object

      Radio Role: Access Point/station/AP&station/Mesh
      Radio Mode: 5G
      non VAP mode 
      SSID and radio schedule, security, advanced and MAC filter list pages settings

      Radio Role: retain from source
      2.4G radio config: default settings
      5G radio config:
       retain from source
      VAP mode with
       default VAP group contains default VAP object
      Source SSID and radio schedule, security, advanced and MAC filter list pages settings will apply to default VAP object

    • TZ380W wireless with SonicOS 8.0.3 does not support DFS(will support in future release). So import source firewall with DFS enabled to Gen8 wireless will disable DFS and reset radio mode/band/channels to default value.
    • TZ380W wireless do not support WEP. So import the source firewall with WEP settings to Gen8 wireless will be reset to default auth settings, which is WPA2-AUTO-PSK with the serial number as the password.
    • TZ380W wireless does not support WPA. So, when you import a source firewall with WPA settings to Gen8 wireless, it will be reset to the default auth settings, which are WPA2-AUTO-PSK with the serial number as the password.
    • TZ380W wireless with SonicOS 8.0.3 does not support SonicOS 7.2.1 features (they will be supported in a future release). For example, station EAP and W0 MAC override-related settings from the source firewall (SonicOS 7.2.1+) will be lost after import to SonicOS 8.0.3.
    • TZ380W wireless does not support mesh gateway mode. Importing settings from a source firewall with mesh gateway to TZ380W wireless will be set to AP mode.
      Importing settings from TZW in a different country/domain - When we import from a different domain, FCC/US or ETSI/Canada or JAPAN will keep unchanged, ETSI non-CA will set as default GB. And radio mode/band/channels will be reset to default value.

Settings Migration App on NSM:

The new Migration App, introduced in NSM 3.1, is embedded within the platform and enables seamless settings migration. Initial support includes GEN8 TZ and NSa models as listed below.

Source Firewalls

Target Firewalls

SOHO/SOHO-W/SOHO250/SOHO250W

TZ80

NSa2600/NSa2650

NSa2800

NSa3600, 3650

NSa3800

TZ300, TZ300W, TZ300P, TZ350, TZ350W

TZ380

TZ400, TZ400W

TZ480

TZ600, TZ600P

TZ680

 

Related Articles

  • SonicOS 8.1.0 FAQ
    Read More
  • Getting started with SonicWall firewalls
    Read More
  • LDAP Connectivity Fails After Upgrading to SonicOS 7.3.1
    Read More
not finding your answers?