Replace firewalls

FrankIversen
FrankIversen Posts: 92  Ally Member
Third Anniversary Ideas master Friend Collector First Comment
edited April 2021 in Nebula

Which firewalls is inter-switchable?

f.ex if customer has NSG200, and we only have NSG100 avaiable, can we replace the NSG200 with the NSG100 as a solution until we get a new NSG200?

Which other scenarios with the different firewall is supported? Can f.ex a NSG50 replace a NSG100?

Any other issues we may expect in such a replacement which we should be aware of?

All Replies

  • Zyxel_Chris
    Zyxel_Chris Posts: 705  Zyxel Employee
    Zyxel Certified Network Administrator - WLAN Sixth Anniversary 500 Comments 50 Answers
    Is this user has any requirement on bandwidth, VLAN number or VPN tunnel number?
    Since NSG200 has the higher limitation than 100, like VLAN interface can reach to 32 on NSG200 but only 16 on NSG100.
    Concurrent VPN tunnel (include s2s and L2TP) can reach to 200 on NSG200, 40 on NSG100.
    You can refer to the datasheet.
    https://download.zyxel.com/NSG100/datasheet/NSG100_13.pdf

  • FrankIversen
    FrankIversen Posts: 92  Ally Member
    Third Anniversary Ideas master Friend Collector First Comment
    @Nebula_Chris No, there are very few settings on our clients firewall these days.
    Primary just a couple vlan, a new NAts and a few site to site tunnels.

    In that case, in "worst case", is a replacement from NSG200 to NSG50 a solution in a disaster recovery if we only have a NSG50 at our hands? 
    Anything else beside the limitations you are referring to which would cause this now to work?
  • Pook
    Pook Posts: 143  Ally Member
    Fourth Anniversary 100 Comments First Answer Nebula Gratitude
    I have swapped out a few NSG's and it is quite easy, head to the site's security gateway and click configuration. Then click remove from site, scan new firewall via the app and and once it is online it will attach to that site.

    The old firewall can then be removed from inventory if required.
  • Zyxel_Chris
    Zyxel_Chris Posts: 705  Zyxel Employee
    Zyxel Certified Network Administrator - WLAN Sixth Anniversary 500 Comments 50 Answers
    If the usage is basic and all the requirement are under NSG50 datasheet specification then it should not have the issue.
    Don't worry. :)

  • mMontana
    mMontana Posts: 1,353  Guru Member
    Fifth Anniversary Community MVP 50 Answers 1000 Comments
    Another question...
    Which is the "closest" choice for USG20 (not 20-VPN) as replacement?
    I have a couple of sites that still rely on that kind of device...
  • Zyxel_Chris
    Zyxel_Chris Posts: 705  Zyxel Employee
    Zyxel Certified Network Administrator - WLAN Sixth Anniversary 500 Comments 50 Answers
    @mMontana
    Will suggest the USG Flex 100 for you. :)
  • mMontana
    mMontana Posts: 1,353  Guru Member
    Fifth Anniversary Community MVP 50 Answers 1000 Comments
    No chance for a future cheaper device with 20 VPN Tunnels instead of 40?
  • Pook
    Pook Posts: 143  Ally Member
    Fourth Anniversary 100 Comments First Answer Nebula Gratitude
    This is a valid point, now the NSG50 is EOL the only entry level Nebula gateway is the Flex100. ZyXel need to release a Nebula USG-Flex50 to fill the gap.

Nebula Tips & Tricks