How to replace the existing firewall with a new USG FLEX H Series firewall?

Zyxel_Cooldia
Zyxel_Cooldia Posts: 1,538  Zyxel Employee
Zyxel Certified Network Administrator - Security Zyxel Certified Sales Associate 100 Answers 1000 Comments

Scope:

A Nebula site currently operating with access points (AP), switches, and a USGFLEX, ATP, or NSG firewall. The customer intends to replace the existing firewall with a new USG FLEX H Series firewall.

Objectives:

  • Minimize downtime during the replacement process
  • Reserve site-wide AP and switch monitoring historical data
  • Backup the existing ZLD firewall settings prior to replacement

Steps to Replace the Existing ZLD Firewall with a New USG FLEX H Series Firewall

Create a Backup Site on NCC
On the Nebula Control Center (NCC), create a new site and clone the settings from the existing ZLD site. This serves as a backup of the site configuration.

Select “Create Site” from the site list.

圖片1.jpg

Type the site name, select “Replicate from”, choose the existing site “FLEX500”, and then click “Create Site.”

圖片2.jpg

Unbox and Power on the H Series Firewall:
Internet access is required. Connect the WAN uplink of the H Series firewall toa LAN port of the existing firewall to provide temporary Internet connectivity.

Upgrade Firmware:
Use the initial setup wizard to upgrade the firmware to the latest version (uOSv1.35 or above).

Connect Locally:
Disconnect the WAN cable, then connect a PC to a LAN port of the H Series firewall. Open a web browser and log in to the device. You will see the initial setup wizard again.

Enter Web Configurator Mode:
In the wizard, select “Web Configurator”, then click “Next” to continue.

圖片3.jpg

Configure the Internet settings and system time settings, then click “Exit” to skip device Registration in Step 3.

圖片4.jpg

Configure the Firewall Locally:
Complete the wizard, then configure the firewall settings through the local GUI.

Backup Configuration:
Once the configuration is complete, back up the configuration file.

Go to the Maintenance page, select “startup-config.conf”, and click the “Download” button to save the file to your PC.

圖片5.jpg

Replace the Old Firewall:
Disconnect all cables from the old firewall and reconnect them to the corresponding ports on the H Series firewall. Verify that the network is functioning properly.

Note: If there are network issues, switch back to the old firewall to restore connectivity.

Remove existing firewall from Org, and Register the New Firewall in Nebula:
In the Nebula portal, remove the old firewall (USG FLEX, ATP, or NSG) from the existing site. Then register the H Series firewall to the same site.

Navigate to Organization-wide > License & Inventory, go to the Devices tab, click the Action button, and select “Remove from the organization.”

圖片6.jpg

Click “Yes” to continue.

圖片7.jpg

After completing the steps above, the FLEX/ATP firewall has been removed from the organization. Now we will need to register H series firewall to Nebula.

Click the “Add” button to register the H Series firewall

圖片8.jpg

Fill in the serial number and MAC address, then click “Next” to continue.

圖片9.jpg

Click the “Finish” button to complete device registration.

圖片10.jpg

Now, you will be able to see the firewall listed in the device list.
Click the “Actions” button and select “Change Site Assignment.”

圖片11.jpg

Select the original site and click “Save.”

圖片12.jpg

A warning message will pop up. Tick “Acknowledge”, and click “OK” to continue.

圖片14.jpg

Allow Cloud Synchronization:
When the H Series firewall connects to the Internet and reaches Nebula, it will automatically initiate a full configuration sync to the Nebula cloud.

Verify Status in Nebula:
Go to the device detail page in Nebula and ensure the device is online. Wait until the "Configuration Status" shows “Up to date.”

圖片15.jpg