Replace firewalls

FrankIversen
FrankIversen Posts: 92  Ally Member
First Anniversary Friend Collector First Comment Ideas master
edited April 2021 in Nebula

Which firewalls is inter-switchable?

f.ex if customer has NSG200, and we only have NSG100 avaiable, can we replace the NSG200 with the NSG100 as a solution until we get a new NSG200?

Which other scenarios with the different firewall is supported? Can f.ex a NSG50 replace a NSG100?

Any other issues we may expect in such a replacement which we should be aware of?

All Replies

  • Zyxel_Chris
    Zyxel_Chris Posts: 653  Zyxel Employee
    First Anniversary 10 Comments Friend Collector First Answer
    Is this user has any requirement on bandwidth, VLAN number or VPN tunnel number?
    Since NSG200 has the higher limitation than 100, like VLAN interface can reach to 32 on NSG200 but only 16 on NSG100.
    Concurrent VPN tunnel (include s2s and L2TP) can reach to 200 on NSG200, 40 on NSG100.
    You can refer to the datasheet.
    https://download.zyxel.com/NSG100/datasheet/NSG100_13.pdf

    Chris
  • FrankIversen
    FrankIversen Posts: 92  Ally Member
    First Anniversary Friend Collector First Comment Ideas master
    @Nebula_Chris No, there are very few settings on our clients firewall these days.
    Primary just a couple vlan, a new NAts and a few site to site tunnels.

    In that case, in "worst case", is a replacement from NSG200 to NSG50 a solution in a disaster recovery if we only have a NSG50 at our hands? 
    Anything else beside the limitations you are referring to which would cause this now to work?
  • Pook
    Pook Posts: 136  Ally Member
    First Anniversary 10 Comments Nebula Gratitude Friend Collector
    I have swapped out a few NSG's and it is quite easy, head to the site's security gateway and click configuration. Then click remove from site, scan new firewall via the app and and once it is online it will attach to that site.

    The old firewall can then be removed from inventory if required.
  • Zyxel_Chris
    Zyxel_Chris Posts: 653  Zyxel Employee
    First Anniversary 10 Comments Friend Collector First Answer
    If the usage is basic and all the requirement are under NSG50 datasheet specification then it should not have the issue.
    Don't worry. :)

    Chris
  • mMontana
    mMontana Posts: 1,298  Guru Member
    First Anniversary 10 Comments Friend Collector First Answer
    Another question...
    Which is the "closest" choice for USG20 (not 20-VPN) as replacement?
    I have a couple of sites that still rely on that kind of device...
  • Zyxel_Chris
    Zyxel_Chris Posts: 653  Zyxel Employee
    First Anniversary 10 Comments Friend Collector First Answer
    @mMontana
    Will suggest the USG Flex 100 for you. :)
    Chris
  • mMontana
    mMontana Posts: 1,298  Guru Member
    First Anniversary 10 Comments Friend Collector First Answer
    No chance for a future cheaper device with 20 VPN Tunnels instead of 40?
  • Pook
    Pook Posts: 136  Ally Member
    First Anniversary 10 Comments Nebula Gratitude Friend Collector
    This is a valid point, now the NSG50 is EOL the only entry level Nebula gateway is the Flex100. ZyXel need to release a Nebula USG-Flex50 to fill the gap.

Nebula Tips & Tricks