This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SG to XG Migration

Hello, 

We have 2xSG 230 appliances in HA and with the licence (FullGuard) expiration date approaching, we're thinking of upgrading to the XG operating system while keeping the same hardware. That said, here are some of my concerns:

- Can the present hardwawre support XG? If yes, Will it consume more ressources compared to UTM9 (we have about 150 - 200 Users) ? 

- Can the actual UTM9 config be imported into XG after setup?

- Is it really worth the upgrade? I mean what are the major improvements/setbacks compared to UTM9. 

Thanks,

Zak.



This thread was automatically locked due to age.
Parents
  • You can use your SG230 Hardware going forward and migrate your valid license. You can also migrate only the base license, which has more features compared to UTM9. (UTM: Firewall, NAT   // XG: Firewall, NAT, IPsec (Remote access, Site to Site), SSLVPN (Remote Access), RED (Site to Site) Wireless.). Those features are there "forever", as long as the appliance is running. The resource consumption depends on the configuration. As you can configure the Hardware based on your needs in XG, you can do things like fine tuning IPS etc., which is not possible on UTM. 

    There is a Migration Tool to move some features to XG. But likely you want to re evaluate your setup. XG is another approach to the network scheme. For example you have Zones in XG, which allows to build firewall rules based on Interfaces (compared to UTM, which uses IP Networks /hosts etc.). Much of the handling is different, so the WAF, Web proxy, DPI, IPS is completely different. Also XG can use Layer 8 authenticated firewalling (Allow User A to use SSH, as he is a Admin). The answer to import backup is No. To use such features, you need to rethink your firewall rule set anyways. 

    The question on is the upgrade worth it, depends on your current situation and free time. There are benefits in using XG. There are some blockers in handling things different. For example, if you worked with UTM for the past X years, it could be challenging in finding certain configuration and do your tasks. There are certain things for free on the XG platform. For example Central management is completely free. 

    Hope this clears some points. If you move forward, you can also use different system, called Heartbeat and Synchronized Security with XG. 

    Most customers break their UTM9 HA, migrate one appliance and do a "step by step" migration inline. They move certain things to XG, test it and move the next module. This is possible with your Hardware.  

    __________________________________________________________________________________________________________________

Reply
  • You can use your SG230 Hardware going forward and migrate your valid license. You can also migrate only the base license, which has more features compared to UTM9. (UTM: Firewall, NAT   // XG: Firewall, NAT, IPsec (Remote access, Site to Site), SSLVPN (Remote Access), RED (Site to Site) Wireless.). Those features are there "forever", as long as the appliance is running. The resource consumption depends on the configuration. As you can configure the Hardware based on your needs in XG, you can do things like fine tuning IPS etc., which is not possible on UTM. 

    There is a Migration Tool to move some features to XG. But likely you want to re evaluate your setup. XG is another approach to the network scheme. For example you have Zones in XG, which allows to build firewall rules based on Interfaces (compared to UTM, which uses IP Networks /hosts etc.). Much of the handling is different, so the WAF, Web proxy, DPI, IPS is completely different. Also XG can use Layer 8 authenticated firewalling (Allow User A to use SSH, as he is a Admin). The answer to import backup is No. To use such features, you need to rethink your firewall rule set anyways. 

    The question on is the upgrade worth it, depends on your current situation and free time. There are benefits in using XG. There are some blockers in handling things different. For example, if you worked with UTM for the past X years, it could be challenging in finding certain configuration and do your tasks. There are certain things for free on the XG platform. For example Central management is completely free. 

    Hope this clears some points. If you move forward, you can also use different system, called Heartbeat and Synchronized Security with XG. 

    Most customers break their UTM9 HA, migrate one appliance and do a "step by step" migration inline. They move certain things to XG, test it and move the next module. This is possible with your Hardware.  

    __________________________________________________________________________________________________________________

Children
No Data