Replacing a firewall without a bad Monday

By the NexusSec team · 4 min read · Published October 2026
Short version: Before the swap, export the old configuration and list everything the firewall does: rules, NAT, VPN tunnels, DHCP, DNS, routes, certificates and integrations. Remove unused rules instead of migrating them. Agree VPN changes with whoever runs the other end, cut over in a planned window with a written test list, and keep the old firewall ready to reconnect until the business has run on the new one for a while.

Replacing a firewall looks like a hardware job: unplug one box, plug in another. In practice the firewall is often doing a dozen jobs nobody wrote down, from handing out IP addresses to holding a VPN tunnel to a supplier that was set up years ago. A swap goes badly when one of those turns up on Monday morning.

Before: find everything the old firewall does

Clean up instead of copying

Vendors offer tools that convert one firewall's configuration into another's, and they save time. They also faithfully convert every rule nobody has used in years. Before converting, check rule hit counts on the old firewall: rules with no hits for months, duplicates, and rules hidden beneath broader ones can usually go. A replacement is the cheapest moment to fix the structure of the policy, because everything is being tested anyway. Zones first is the structure we move clients to.

Talk to the other end of every tunnel

A site-to-site VPN needs both ends to agree. If your public IP address or encryption settings change, the partner, branch or cloud provider at the other end must change their side at the same time. Contact them a week ahead, agree the settings in writing, and schedule their change in the same window. This is the item most easily forgotten.

The cutover plan

After: the first week

If the replacement was triggered by a renewal quote, read before you sign the firewall renewal first. Our firewall migration service is this checklist carried out for you.

Frequently asked questions

Can we keep the same rules when moving to a different vendor?

The intent of the rules can move, and conversion tools help. The structure usually should not move unchanged: a replacement is the best moment to remove unused rules and reorganise the policy into zones.

How long does a firewall replacement take?

The cutover itself is usually a few hours in a planned window. The preparation, meaning the inventory, the clean-up and coordinating VPN partners, takes longer and is where the effort should go.

Do we need downtime?

Usually a short window. A second internet link or a high-availability pair can reduce it, but plan for a window and tell the business anyway.

What is easiest to forget?

Site-to-site VPNs to partners, DHCP reservations and local DNS records the old firewall was serving, and port forwards for services nobody remembered were published.

Planning a firewall replacement?

We inventory the old firewall, clean up the policy, coordinate the VPN partners and run the cutover with a written rollback plan.

Book a free consultation