Import Configuration Settings from a Firebox Configuration File

Applies To: Cloud-managed Fireboxes, Locally-managed Fireboxes

Some of the features described in this topic are available only to participants in the WatchGuard Cloud Beta program. If a feature described in this topic is not available in your version of WatchGuard Cloud, it is a beta-only feature.

If you want a cloud-managed Firebox to use the same settings as an existing Firebox configuration, the Import Configuration wizard saves you time and reduces the risk of errors. For example, you can use the wizard to help you migrate from locally-managed Fireboxes to cloud-managed Fireboxes.

Alternatively, when you add a Firebox to WatchGuard Cloud as a cloud-managed device, you can copy configuration settings from another cloud-managed Firebox. For more information, go to Copy Configuration Settings from a Cloud-Managed Firebox.

If you want to import configuration settings to multiple cloud-managed Fireboxes, you can add or edit a Firebox template. The Import Configuration wizard is available from a Firebox template. For more information, go to About Firebox Templates.

With the Import Configuration wizard, you can import these settings from an existing Firebox configuration file to a cloud-managed Firebox:

  • Aliases
  • Exceptions
  • Routes
  • Blocked Ports
  • Blocked Sites
  • Dimension Servers
  • Syslog Servers
  • Technology Integrations
  • Networks
  • Branch office virtual private networks (BOVPNs)

You can import only these settings from a Firebox configuration file to WatchGuard Cloud. The import process does not import any other settings from the configuration file. For information about how to import BOVPNs, go to Import BOVPN Configuration Settings from a Firebox Configuration File.

When you import configuration settings, the Import Configuration wizard compares the settings you want to import with the settings that are already configured on the cloud-managed Firebox. If the settings you want to import are duplicates of the settings that are configured on the cloud-managed Firebox, you can select an action to take, such as merge, replace, keep, or skip settings.

You can use the Import Configuration wizard when you want to:

  • Add a device to WatchGuard Cloud
  • Import configuration settings to an existing cloud-managed Firebox
  • Import configuration settings to a Firebox template

Before You Begin

Before you import configuration settings to a cloud-managed Firebox, review the information in these sections:

Configuration File Requirements

Before you can import configuration settings to a cloud-managed Firebox, you must first export and save the .XML configuration file from the Firebox with the settings you want to import.

To save a configuration file from a Firebox, follow the steps in these topics:

The configuration file must:

  • Be in .XML format
    If you save a configuration file from Fireware Web UI, you must unzip the .XML file from the .GZ file before you can import it.
  • Be a valid Firebox configuration file
  • Contain fewer than 5000 total exceptions to import
    A cloud-managed Firebox supports up to 5000 exceptions. There is no maximum limit for aliases.

Duplicate Configuration Data

When you import configuration settings from a Firebox configuration file, the Import Configuration wizard might detect duplicate settings that exist in both the imported .XML configuration file and the cloud-managed Firebox configuration in WatchGuard Cloud. When this occurs, you must specify what action to take for each type of duplicate setting in the Duplicate Settings section of the wizard.

Duplicate setting detection is not applicable to Dimension servers, syslog servers, technology integrations, or networks.

Screenshot of the Import Configuration UI

Not Importable Settings

When you use the Import Configuration wizard to import configuration settings from a Firebox configuration file, the Not Importable tab shows any settings that you cannot import because they are not supported.

Screenshot of the Import Configuration wizard, Not Importable tab

Import Configuration Settings

With the Import Configuration wizard, you can import some configuration settings from an existing Firebox configuration file to a cloud-managed Firebox configuration.

To import configuration settings to a cloud-managed Firebox:

  1. Export and save the .XML configuration file from the Firebox with the settings you want to import. For more information, go to Configuration File Requirements.
  2. From WatchGuard Cloud, select Configure > Devices.
  3. Select a cloud-managed Firebox.
  4. Select Device Configuration.
    The Device Configuration page opens.

Screenshot of the Device Configuration page

  1. Click Import Configuration.
    The Import Configuration wizard opens.

Screenshot of the Import Configuration wizard selection page

  1. Select Import Configuration Settings from a Firebox. For information about how to import BOVPN configuration settings, go to Import BOVPN Configuration Settings from a Firebox Configuration File.
    The Import Configuration page opens.

Screenshot of the Import Configuration wizard

  1. Drag the configuration file (.XML format) that you want to import to the file upload box. Alternatively, click the box to browse and select the configuration file.
  2. Click Next.
  3. If the wizard finds duplicate settings, on the Duplicate Settings page, from the drop-down lists, select the action to take for each duplicate item. For more information, go to Duplicate Configuration Data.

Screenshot of the Import Configuration Wizard, Duplicate Settings page

  1. Click Next.
    The Aliases page opens.

Screenshot of the Import Configuration wizard, Aliases page

  1. Select the check box next to each alias to import. The page shows the number of aliases available for import and the number of aliases found in the configuration file.

Some data is not available for import because it is reserved for use by the Firebox, such as a default alias. The Not Importable tab shows items that WatchGuard Cloud cannot import. For more information, go to the Not Importable Settings section of this topic.

  1. Click Next.
    The Exceptions page opens.

Screenshot of the Import Configuration wizard, Exceptions page

  1. Select the check box next to each exception to import. The page shows the number of exceptions available for import and the number of exceptions found in the configuration file.
  2. Click Next.
    The Routes page opens.

Screenshot of the Import Configuration wizard, Routes page

  1. Select the check box next to each route to import. The page shows the number of routes available for import and the routing distance found in the configuration file.

    You cannot import routes into a template.

  2. Click Next.
    The Blocked Ports page opens.

Screenshot of the Import Configuration wizard, Blocked Ports page

  1. Select the check box next to each blocked port to import. The page shows the number of blocked ports available for import in the configuration file.
  2. Click Next.
    The Blocked Sites page opens.

Screenshot of the Import Configuration wizard, Blocked Sites page

  1. Select the check box next to each blocked site to import. The page shows the number of blocked sites available for import and their description in the configuration file.
  2. Click Next.
    The Dimension Servers page opens and shows the Dimension Servers on the cloud-managed Firebox.

Screenshot of the Import Configuration wizard, Dimension Servers page

  1. (Optional) To change the list of Dimension servers, click Select Server.
    A dialog box opens and shows the list of available Dimension servers. The list shows servers from both the import file and the cloud-managed configuration.

    Screenshot of the Import Configuration wizard, Dimension Servers dialog box
    1. Select the check box next to the Dimension servers that you want to use with WatchGuard Cloud. You can select up to two Dimension servers from the list.
    2. Click OK.
  1. To prioritize Dimension servers, click and drag them to new positions in the list.

Screenshot of the Import Configuration wizard, Dimension Servers page

  1. Click Next.
    The Syslog Servers page opens. The list of servers includes syslog servers from both the import file and the cloud-managed configuration.

Screenshot of the Import Configuration wizard, Syslog Servers page

  1. Select the check box next to each syslog server that you want to use with WatchGuard Cloud. You can select up to three syslog servers.
  2. Click Next.
    The Technology Integrations page opens.

Screenshot of the Import Configuration wizard, Technology Integrations page

  1. Select the check box next to each technology integration to import.

    When you import a technology integration, it replaces an existing technology integration of the same type. For more information, go to About Firebox Technology Integrations.

  1. Click Next.
    The Networks page opens.

Screenshot of the Import Configuration wizard, Networks page

The Import Configuration wizard does not support the ability to import networks to Firebox Cloud or FireCluster devices. It also does not support the ability to import networks to templates.

  1. Select the check box next to each external or internal network you want to import. The page shows the number of networks available for import and the number of networks found in the configuration file.
  2. (Optional) If you import an Optional or Custom network from a locally-managed Firebox configuration, the Import Configuration wizard prompts you to select a different network type.

To select a different network type, from the Optional or Custom drop-down list, select Internal or Guest.

Screenshot of the Import Configuration Wizard, Networks page with unsupported Optional and Custom networks

  1. Click Next.
    The Finish page opens.

Screenshot of the Import Configuration wizard, Finish page

  1. Review the settings to import. Click Finish.
    The Upload in Progress bar indicates the status of the import process.

Screenshot of the Import Configuration wizard, Upload in Progress bar

  1. Deploy the changes to WatchGuard Cloud.

Screenshot of the Device Configuration page with Undeployed Saved Changes banner

After you deploy any changes, imported settings show in WatchGuard Cloud on the Device Configuration page. From this page, you can click the relevant widgets to edit or delete the settings that you imported.

If you use a template to import settings, you must also use the template to edit or delete the settings after import.

Related Topics

Add a Cloud-Managed Firebox to WatchGuard Cloud

Import BOVPN Configuration Settings from a Firebox Configuration File

Add Exceptions on a Cloud-Managed Firebox

Configure Firebox Aliases