Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Converting SG configuration for import in XG firewall

Hello,

I am currently preparing a XG310 as replacement for our ageing SG310. We have a quite extensive ruleset in the web protection with whitelist for hundreds of websites and seperated configurations for about 10 different LDAP-groups.

So I read about possibilites in exporting setting from SG to XG firewalls. My Sophos partner company told me, that there is no longer the Conversion Appliance Sophos offered to partners for a while but that they (our technical partner company) can sent a SG config file to Sophos and get back a converted XG config file. These XG config file should be inported to XG310 and would make it possible to get the web filter configuration transferred by using Import/Export function of the XG firewall.

My partner send the SG config to Sophos but only got the reply, that conversation would be possible "directly"?! We should import the abf file from the SG to the XG firewall. But the Sophos supporter did not explain, how this should be done, even after asking again. If I try an restore with the abf file on the XG, it only says that this is no valid config file for restoring (which I had expected, too).

Then I tried as another way the export function in SG. But this gives me a CSV-like output and XG likes XML-like files for Import. So this is no use either, as it appears.

What are the possibilities to get my web filter working as before without manuelly copy-pasting all of the whitelist-entrys from SG to XG? Configuring the whole web filter by hands could cost me a lot of time, I'm afraid. Any help is appreciated!



This thread was automatically locked due to age.
Parents
  • Hi Dennis,

    We recently migrated an SG to XG.  It was a very complicated setup, with 10 public IP aliases, 200 user VPNs, 2 S2S VPNs, 20 Wifi APs, email filtering, many port forwards, many firewall rules and web filtering rules.  We found ourselves in the same situation as yourself, ie no easy way to migrate.  I the end we divided the work between several people and just sat down and typed. 

    It was useful, though, to review all configurations - some were no longer needed, some could not be replicated on the XG; some XG features do not exist in the SG.  For example, the UTM was a proxy; the XG does not need to proxy to filter content.

    Good luck.

    Adrian

Reply
  • Hi Dennis,

    We recently migrated an SG to XG.  It was a very complicated setup, with 10 public IP aliases, 200 user VPNs, 2 S2S VPNs, 20 Wifi APs, email filtering, many port forwards, many firewall rules and web filtering rules.  We found ourselves in the same situation as yourself, ie no easy way to migrate.  I the end we divided the work between several people and just sat down and typed. 

    It was useful, though, to review all configurations - some were no longer needed, some could not be replicated on the XG; some XG features do not exist in the SG.  For example, the UTM was a proxy; the XG does not need to proxy to filter content.

    Good luck.

    Adrian

Children
No Data