Transcript
to convert configurations from other firewalls and easily migrate them into Sophos Firewall. Let's dive in. In this TechVid, you'll learn how to convert configurations from Sophos UTM Firewalls, SonicWall Firewalls, and FortiGate Firewalls. For steps on converting from Palo Alto networks, check the documentation linked in the description. Then, I'll show you how to import those configurations into Sophos Firewall. Before starting, ensure you have access to the firewall configurations you're importing, Sophos Firewall, and Sophos Firewall Config Studio. Let's get started. First, navigate to Config Studio. You can access this page by using the link in the description. Click Migrate to Sophos Firewall. You can migrate configurations from the following supported vendors. Note, use the video chapters provided to navigate to a specific vendor's migration process. I'll demonstrate the process with Sophos UTM first. To start, you need to run the migration script first, hosted on the open-source GitHub project. You can follow the documented steps here. The script generates an entities.xml file and a summary table of supported configurations. Review the table, then click Continue. Upload the entities.xml file. Two options appear after uploading. When migrating to different firewalls, it's best practice to choose Keep All Configurations. Next, select your target firewall model. You can review the port layout, map each interface manually, or use Auto-Assign to map interfaces sequentially. Once finished, click Apply Mapping, then click Migration Report. Here, you can manually fix flagged items. In this example, the following items are missing zones and IP addresses. Please note that the Preview and Download buttons stay unavailable until the required fixes are complete. After fixing all flagged items, the Migration Report button will disappear, and the Preview and Download buttons are enabled. You can now download the configuration as a tar file and import it into Sophos Firewall, which is the last chapter of this tech fit. Next, I'll demonstrate the migration process for SonicWall. Review the table of supported configurations, then click Continue. Upload the .exp configuration file. As a note, ensure to use the unencrypted, plain-text version of the backup. A list of imported configurations and their counts appears. Click Import Converted Entities. Then, select your target firewall model and review the port layout and interface mapping. You can also delete ports that aren't going to be used. Take note that removing an interface doesn't automatically remove its references. Ensure to delete those before importing to Sophos Firewall. Once finished, click Apply Mapping. Now, use the Migration Report to spot anything that needs a manual fix. A useful feature to highlight is the ability to review items that have been auto-resolved by Config Studio. After reviewing, click Action Required to continue manually fixing flagged items. Common issues in this case include missing zones, IP addresses, services, or references left behind after an interface or VLAN is removed. You can also find and filter affected rules. Go to Firewall Rule, then click Config Analysis. Unsupported. This filter shows rules that need attention. Click the Edit button, and you can see what needs to be fixed inside the rule. In this case, there's a missing reference. You can fix this by updating or removing that reference, or creating a new one. Once finished, click Update. If the rules that are marked Unsupported aren't needed anymore, you can select and delete them all. As a reminder, the Preview and Download buttons stay unavailable until the required fixes are complete. Once the report is clean, you can download the configuration file and import it into Sophos Firewall, which is the last chapter of this tech vid. Now, I'll show you how to migrate from FortiGate. Review the table of supported configurations, then click Continue. Upload the .conf configuration file. A list of imported configurations and their counts appears. Then, select your target firewall model and review the port layout and interface mapping. Once finished, click Apply Mapping. A pop-up appears to notify that FortiGate uses interface-based rules, while Sophos Firewall uses zone-based rules. Config Studio maps interfaces to zones based on the interface rule, then uses those zones to build firewall rules. For more information on how these interfaces are converted, check the relevant documentation linked in the description. After importing, use the Migration Report to spot anything that needs a manual fix. When importing configurations from FortiGate, verify that the rules have been set to their correct zones. Go to Firewall Rule and check if any rules need a zone change. If several rules need the same update, use Bulk Update to change multiple rules at once. In this case, I'll change the selected rules to a DMZ zone. Please note that the Preview and Download buttons stay unavailable until the required fixes are complete. Once everything is fixed, you can preview the configuration. Download the configuration as a TAR file and import it into Sophos Firewall, which is the last chapter of this tech vid. Lastly, I'll quickly show you how to import these configurations into Sophos Firewall. From the Sophos Firewall dashboard, under System, click Backup & Firmware. Then, select Import-Export and choose the configuration you want to import. Finally, click Import. As a best practice, verify connectivity, recreate any missing configurations, and test traffic flow. For more information on importing and exporting configurations in Sophos Firewall, check the relevant documentation linked in the description. And that's how you migrate firewall configurations into Sophos Firewall. I hope you found this useful. The relevant documentation and other comprehensive resources for this tech vid are linked in the video description. Join the Sophos community to stay up to date with our products, ask questions, and get answers from Sophos experts. And go to Sophos TechVids for more expert tutorials to help you maximize your products and stay secure. See you next time!