USG Flex 50H - questions regarding migration to the new series

Options
mlik
mlik Posts: 26 image  Freshman Member
First Comment Fifth Anniversary

Hello, I'm planning to implement a firewall. I've been using USG FLEX 100 models so far, but it's becoming increasingly difficult to find this model in wholesale. I have a question about the USG Flex 50H model. I see there's a way to convert configuration files between these firewalls. Has anyone used the config converter and does it work correctly for this model? Has the GEO IP service, which was available for free in the previous series, been retained in the new H models? I have configured policy control based on GEO IP and would like to maintain it. Is it difficult to switch to the new interface? I've primarily used IPsec VPN configurations. Are there any limitations, such as whether this series requires valid subscriptions to operate, or can it operate as a standalone device without them? I also have a question about the older USG FLEX 100 / 100AX / USG20W-VPN models. Are they already on the EoL list and how long will they be supported?

All Replies

  • Zyxel_Barry
    Zyxel_Barry Posts: 120 image  Zyxel Community Virtual Assistant
    5 Answers First Comment Friend Collector

    Hi @mlik,

    Thank you for reaching out to the Zyxel Community. I understand you're looking into migrating from USG FLEX 100 models to the USG FLEX 50H and have several questions regarding the new series and your existing devices.

    Here's some information to address your concerns:

    Initial Solution

    • Configuration Migration Tool: Zyxel offers a Configuration Migration Tool to help transfer settings from older Zyxel firewalls (including USG FLEX) to the USG FLEX H-Series. You can access this tool at convert.cloud.zyxel.com. This tool automates the process, aiming to reduce manual reconfiguration.

      • Limitations: While the tool simplifies migration, not all features map 1:1 between old and new firewalls. If a feature isn't supported on the target model, the tool will log it as failed. Some settings may be adjusted or removed, and you can review a detailed log file to check what was successfully migrated.
      • Partial Configuration Import: Zyxel devices generally require a complete configuration file to be imported; partial configurations are not supported for direct import. However, you can edit the converted configuration file to include specific sections, such as IPsec VPN tunnel configurations, by downloading the new firewall's configuration, copying the relevant sections from the converted file, and then importing the modified file.
      • IPsec VPN Conversion: If you are using IKEv1 VPN configurations, direct conversion to IKEv2 on the H-series is not supported, and manual reconfiguration will be required.
    • GEO IP Service: The USG FLEX H series supports the GeoIP feature, and you can update the Geo-IP DB manually via the Web GUI by navigating to Object > Address > GeoIP and clicking "Update Now".

    • Interface: The USG FLEX H series introduces a new interface (uOS). Several GUI enhancements have been made to improve usability, functionality, and overall user experience, including changes to the menu tree layout, frozen headers for viewing large datasets, and enhanced port details.
    • Subscription Requirements:

      • The USG FLEX H series can operate as a standalone device. However, to utilize advanced security features like Reputation Filter and to gain access to Priority Support, an active subscription such as the Entry Defense Pack or Gold Security Pack is required.
      • When you register your device on the Nebula Control Center (NCC), you receive a 30-day trial of the Gold Security Pack and a 366-day Entry Defense Pack.
    • End-of-Life (EoL) for Older Models: Information regarding the EoL status for specific older models like USG FLEX 100, 100AX, and USG20W-VPN is not immediately available in the provided search results.

    Information Collection Guide

    To help us provide more specific guidance, please provide the following:

    • Exact models and current firmware versions of your existing USG FLEX 100 devices.
    • Screenshots of any error messages you encounter during the configuration migration process.

    If you plan to manage your USG FLEX 50H via Zyxel Nebula, please enable Zyxel Support Access via Help > Support Request in the Nebula console and provide your Organization and Site name. This allows the Zyxel support team to directly view your cloud environment configuration, significantly shortening troubleshooting time.

    This AI response aims to provide initial troubleshooting steps and identify information needed for further diagnosis. Feel free to share additional details based on the suggestions above — this will help community members offer more targeted assistance.
    If you have feedback or idea about this AI assistant, share them in Community Feedback.

  • Zyxel_Tina
    Zyxel_Tina Posts: 642 image  Zyxel Employee
    Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Switch 100 Answers 500 Comments

    Hi @mlik,

    1) Config migration (USG FLEX 100 → USG FLEX 50H)

    Yes, you can migrate firewalls from the USG FLEX 100 to the USG FLEX 50H by using the converter tool. Many users have used it successfully for common settings such as interfaces, security policies, NAT, and IPsec VPN. After conversion, we still recommend reviewing the config, as some features or object mappings may need minor adjustments.

    uOS – Configuration Migration Tool — Zyxel Community

    2) GEO IP service on H series (uOS)

    The GEO IP feature is still available on USG FLEX H models without requiring a license, same as the USG FLEX (ZLD) generation.

    3) Interface / management on H series

    The H series uses hybrid management due to the firmware design. You can manage the device via local GUI or Nebula Cloud.

    Once the device is registered to Nebula and has connectivity to NCC, any configuration done in Nebula will synchronize to the device, while local configuration is still supported.

    4) Subscription requirement

    Subscriptions are required for advanced security services, as Zyxel_Barry mentioned above. If you can share your usage scenario, we can better advise on whether (and which) license is actually needed.

    5) EoL status of USG FLEX 100 / 100AX / USG20W-VPN

    At this moment, USG FLEX 100 / 100AX / USG20W-VPN have not yet been announced as EoL, so no official end-of-support timeline has been published.

    Zyxel Tina