The NSM 3.2.0 uses the Command Line Interface (CLI) as compared to previous NSM versions using Management Console. CLI is a powerful tool that will enable you to configure networking and even perform backups and upgrades. Details on the CLI commands are present under Command Line Interface.
Capacity Requirements: The capacity requirements for an NSM On-Premises deployment have changed:
| Platform | Platform Details |
|---|---|
| VMware |
Supported versions: ESXi 7.0, 8.0 |
| Hyper-V | Windows 2019, 2022 |
| KVM | Linux Kernel 5.15 LTS |
| Azure |
Standard_D4_v2 Standard_D5_v2 Standard_D16as_v5 Standard_D8as_v5 |
| Number of Firewalls | CPU (Cores) |
|---|---|
| 100 | 4 |
| 150 | 4 |
| 250 | 8 |
| 500 | 8 |
| 750 | 8 |
| 1000 | 8 |
| 1000+ | 16 |
| Number of Firewalls | CPU (Cores) | RAM (GB) |
|---|---|---|
| 100 | 4 | 16 |
| 150 | 4 | 16 |
| 250 | 8 | 16 |
| 500 | 8 | 16 |
| 750 | 8 | 16 |
| 1000 | 8 | 16 |
| 1000+ | 16 | 32 |
| Number of Firewalls | CPU (Cores) | RAM (GB) |
|---|---|---|
| 100 | 4 | 24 |
| 150 | 4 | 24 |
| 250 | 8 | 24 |
| 500 | 8 | 32 |
| 750 | 8 | 32 |
| 1000 | 8 | 32 |
| 1000+ | 16 | 64 |
| Number of Firewalls | Data Retention 7 days | Data Retention 365 days |
|---|---|---|
| 50 | 600 GB | 750 GB |
| 100 | 1.2 TB | 1.5 TB |
| 150 | 1.7 TB | 2.3 TB |
| 250 | 2.8 TB | 4 TB |
| Number of Firewalls | NSM Nodes |
|---|---|
| ≤ 250 | NSM Controller Node / Single Node Deployment |
| > 250 | Controller Node + 1 Reporting Agent per 250 firewall |
| Reporting Agent resource requirements (CPU and RAM ) is the same as the controller node. | |
Upgrade Instructions:
| Current Build | Upgrade Path to 3.2.0 On-Prem |
|---|---|
| NSM 3.1.0 | NSM 3.1.0 > NSM 3.1.1 > NSM 3.1.1 HF1 > NSM 3.2.0 |
| MSM 3.1.1 | NSM 3.1.1 > NSM 3.1.1HF1 >NSM 3.2.0 |
| NSM 3.1.1HF1 | NSM 3.1.1HF1 >NSM 3.2.0 |
Please refer to the individual platform upgrade instructions:
ESXi upgrade guide - Upgrading to NSM 3.2.0 on ESXi
Hyper-V upgrade guide - Upgrading to NSM 3.2.0 on HyperV
Azure upgrade guide - Upgrading to NSM 3.2.0 on Azure
KVM upgrade guide - Upgrading to NSM 3.2.0 on KVM
NSM based on SonicCoreX - In this release, we have moved NSM to a new underlying operating system, which enhances the overall performance, security, and reliability of NSM.
New User Experience - NSM on-premises has a new modern user experience.
NSM CLIs - We have a new way to configure NSM using CLIs.
Proxy Configuration - NSM on-premises will support proxy configuration to make it suitable for environments where internet connectivity is provided through a proxy.
SonicOS support - This release enables support for SonicOS versions 7.3.1 and 8.1.0
Risk-Based Reporting: Introduces new report types that provide deeper insights into application usage, intrusion attempts, and malware risks, empowering security teams to prioritize threats and improve response times.
Schedule Web Activity Report - Get detailed insights into user web activity by the Web Activities schedule report
Schedule Attack Report - Admins can generate a schedule attack report on Gen 7 and Gen 8 devices. Attack reports provide visibility into potential security incidents, allow admins to investigate, respond, and enhance network security measures to prevent future breaches.
Upgrade workflow Improvements - Users can download and install upgrade with NSM user interface.
Tenant and Group Change logs - Enable tracking of configuration of firewall configuration changes for auditing and compliance requirements
User Management - Administrators have an option to enforce password change at first login for new users.
Alerts - Get alerted on local changes performed on firewall.
| Issue ID | Description |
|---|---|
| NSM-33628 | NSM 3.2.0 On-Prem VM creation failed with error "A required disk image was missing" |
| NSM-32563 | Secondary HA firewalls are getting added to Inventory when Secondary is active |
| NSM-32409 | When navigating to Firewall View>Device>Time an error is displayed stating "Cannot read properties of null (reading "startsWith")". |
| NSM-31946 | Aggregated scheduled reports fail to run on-demand. |
| NSM-31788 | NSM shows the errors "Error occured in saving CATP data in RAB for the device KAG-Quincy-Service-TZ370 (18C2415D9350): Put "http://127.0.0.1:3443/api/v1/captureatp/18C2415D9350": dial tcp 127.0.0.1:3443: connect: connection refused". |
| NSM-31100 | IP column sorting is not working in larger production environment. |
| NSM-30074 | IN Azure environment, all GEN6 units are offline after the upgrade to 3.0. |
| Issue ID | Description |
|---|---|
| NSM-33964 |
.Unable to upgrade firmware after restoring 3.1.1-HF backup in 3.2.0 Workaround- Either perform the firmware upgrades by grouping the firewalls in the inventory by firewall models or perform the firmware upgrades using the firewall user interface. |
NSM-33557, NSM-32022, NSM-31790, NSM-31254