Migration Tool 4.36.0 Release Notes
Version 4.34.0
June 2023
Important
Settings can be exported from one firewall to another, but not every SonicWall model is compatible with all others. Similarly, some firmware versions are not compatible with subsequent versions as new features get added or as changes are made to existing features. Understand the compatibility described in the following section to avoid possible corruption from importing unsupported settings.
Compatibility and Installation Notes
SonicOS 6.5.1.3 is the minimum version supported for importing settings to a firewall running SonicOS 7. If you try to migrate from an older version of SonicOS, it becomes a two-step process. Update the firewall to SonicOS 6.5.1.3 or higher. Then use the migration tool to create the settings file to import to the SonicOS 7 firewall.
Certain settings such as Global Bandwidth Management, Virtual Assist, Content Filter Client Enforcement, and others cannot be imported into SonicOS 7. A detailed matrix showing the compatible Source and Destination SonicWall firewalls is provided in the KB article, Can Settings be Exported/Imported from One SonicWall to Another? Refer to it for the most current information.
The Migration Tool does not support firewalls running SonicOS with Policy Mode. This includes any of the NSv Series devices that are running in Policy Mode and the NSsp 15700.
Using the Migration Tool to upgrade from a SonicOS 5.9.x firewall to a 6.1.x is not supported at this time. Speak to your reseller or SonicWall Partner about SonicWall Professional Services.
The SonicWall Migration Tool allows you to migrate some settings from third-party vendors. In the following table, the X indicates which settings can be migrated for each vendor and which are not supported at this time.
Feature | Checkpoint | Cisco | Fortinet | Palo Alto | Sophos | Watchguard |
---|---|---|---|---|---|---|
Zone | X | X | X | X | X | X |
Access Rule | X | X | X | X | X | X |
Network Object | X | X | X | X | X | X |
Status Route | Not supported | X | X | X | Not supported | X |
Service | X | X | X | X | X | X |
NAT | X | X | Not supported | X | Not supported | X |
VPN | Not supported | Not supported | Not supported | Not supported | Not supported | Not supported |
SonicWall does not fully test all features for all third-party devices. To minimize migration issues be sure to test the migrated setting in your test environment before deploying to production.
What's New
This release provides the fixes for previously reported issues and the following enhancements:
- Added an option to drop certificate-related settings.
- Added an alert message if there are custom management ports configured in the source settings.
Resolved Issues
Issue ID | Issue Description |
---|---|
DEVT-2763 |
Issue: Link aggregation configurations are not getting migrated from Gen6 to Gen7. Fix: Added support for migrating link aggregation - related settings. |
DEVT-2788 |
Issue: No option to remove certificate related configuration. Fix: Added an option to drop certificate-related settings. |
DEVT-2911 |
Issue: Syslog traffic sent in UTC time after migration. Fix: Fixed the issue with the syslog traffic time stamp being displayed in UTC. |
DEVT-2927 |
Issue: Finish button grayed out during migration attempt in MacOS. Fix: Fixed the finish button being grayed out on MacOS due to compatibility. |
DEVT-2936 |
Issue: Unable to migrate the settings for NSA devices using Migration Tool to remap to high speed interface. Fix: Allowed the translation of address objects containing zone names in the address object name. |
DEVT-2974 |
Issue: "For NSa 5700 - Unable to migrate setting for an interface containing VLAN to a different interface" Fix: Fixed parsing of advance routing settings while migrating from Gen7 to Gen7. |
DEVT-2980 |
Issue: Custom HTTPS Management port - Can the Migration Tool show an alert or message Fix: Added an alert message if there are custom management ports configured in the source settings. |
DEVT-2995 |
Issue: Settings from NSa 5600 to NSa 5700 via Migration tool are not being retained on NSa 5700. Fix: Fixed the migration of VLANs and WLAN-dependent settings. |
DEVT-3004 |
Issue: VLANs of WLAN tunnel interfaces are not getting migrated. Fix: Added the translation logic for migrating settings related to WLAN and VLANs. |
DEVT-3044 |
Issue: Uploading source exp as Gen6 NSv shows non-exiting models NSA E6600 and NSA E5600 in Select Target Product. Fix: Fixed the typo in the device name for NSa 5600 and NSa 6600. |
DEVT-3049 |
Issue: Migration Tool shows a blank message - migratetool.global.sonicwall.com. Fix: Fixed the migration failures caused by firmware version checks. |
DEVT-3050 |
Issue: Unable to import file from Migration Tool. Fix: Fixed the migration of VPN policies. |
DEVT-3059 |
Issue: Unable to migrate Fortinet platform settings into Sonicwall GEN7 TZ470. Fix: Fixed the file upload issue for Fortinet and Palo Alto platform configurations. |
Known Issues
Issue ID | Issue Description |
---|---|
DEVT-3024 |
Migrating from Gen7 physical devices to Gen7 NSv devices is failing with the error "Global mode firewall importing policy mode settings file". Contact support via web ticket with the source files to facilitate in the migration. |
DEVT-3078 |
Third party device (5.9 firmware ) to GEN7 migration is not working. Contact support via web ticket with the source files to facilitate in the migration. |
DEVT-3102 |
Unable to convert Fortinet and Sophos settings using migration tool. Contact support via web ticket with the source files to facilitate in the migration. |
Additional References
DEVT-3066
Was This Article Helpful?
Help us to improve our support portal