Replace firewalls

FrankIversen
FrankIversen Posts: 92  Ally Member
Ideas master First Comment Friend Collector Third Anniversary
edited April 2021 in Nebula

Which firewalls is inter-switchable?

f.ex if customer has NSG200, and we only have NSG100 avaiable, can we replace the NSG200 with the NSG100 as a solution until we get a new NSG200?

Which other scenarios with the different firewall is supported? Can f.ex a NSG50 replace a NSG100?

Any other issues we may expect in such a replacement which we should be aware of?

All Replies

  • Zyxel_Chris
    Zyxel_Chris Posts: 705  Zyxel Employee
    Zyxel Certified Network Administrator - WLAN Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate 50 Answers
    Is this user has any requirement on bandwidth, VLAN number or VPN tunnel number?
    Since NSG200 has the higher limitation than 100, like VLAN interface can reach to 32 on NSG200 but only 16 on NSG100.
    Concurrent VPN tunnel (include s2s and L2TP) can reach to 200 on NSG200, 40 on NSG100.
    You can refer to the datasheet.
    https://download.zyxel.com/NSG100/datasheet/NSG100_13.pdf

  • FrankIversen
    FrankIversen Posts: 92  Ally Member
    Ideas master First Comment Friend Collector Third Anniversary
    @Nebula_Chris No, there are very few settings on our clients firewall these days.
    Primary just a couple vlan, a new NAts and a few site to site tunnels.

    In that case, in "worst case", is a replacement from NSG200 to NSG50 a solution in a disaster recovery if we only have a NSG50 at our hands? 
    Anything else beside the limitations you are referring to which would cause this now to work?
  • Pook
    Pook Posts: 143  Ally Member
    First Comment First Answer Friend Collector Nebula Gratitude
    I have swapped out a few NSG's and it is quite easy, head to the site's security gateway and click configuration. Then click remove from site, scan new firewall via the app and and once it is online it will attach to that site.

    The old firewall can then be removed from inventory if required.
  • Zyxel_Chris
    Zyxel_Chris Posts: 705  Zyxel Employee
    Zyxel Certified Network Administrator - WLAN Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate 50 Answers
    If the usage is basic and all the requirement are under NSG50 datasheet specification then it should not have the issue.
    Don't worry. :)

  • mMontana
    mMontana Posts: 1,389  Guru Member
    50 Answers 1000 Comments Friend Collector Fifth Anniversary
    Another question...
    Which is the "closest" choice for USG20 (not 20-VPN) as replacement?
    I have a couple of sites that still rely on that kind of device...
  • Zyxel_Chris
    Zyxel_Chris Posts: 705  Zyxel Employee
    Zyxel Certified Network Administrator - WLAN Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate 50 Answers
    @mMontana
    Will suggest the USG Flex 100 for you. :)
  • mMontana
    mMontana Posts: 1,389  Guru Member
    50 Answers 1000 Comments Friend Collector Fifth Anniversary
    No chance for a future cheaper device with 20 VPN Tunnels instead of 40?
  • Pook
    Pook Posts: 143  Ally Member
    First Comment First Answer Friend Collector Nebula Gratitude
    This is a valid point, now the NSG50 is EOL the only entry level Nebula gateway is the Flex100. ZyXel need to release a Nebula USG-Flex50 to fill the gap.

Nebula Tips & Tricks