Replacing a TZ-500 with a TZ-470 - Migration tool?
I have replaced a TZ-500 in the past and replaced it with a TZ-470, and we are doing it again now at another site. I do not remember if I had to use the Migration tool, or if I could simply export the config from the TX-500 and import it into the TZ-470. That is what I did this time, and when I went to swap the appliance out the newly configured appliance would not go online. No connectivity to the internet or to either of the VPN tunnels. Any thoughts? Should I go ahead and export the config again from the old device and use the migration tool and re-import and try again. I already have both devices loaded in NSM. As I brought the new unit online and added it to NSM. It's not currently online now as it contains the config from the old unit.
Answers
@AKAKilroy - the short answer is: NO! DO NOT import the Gen 6.x configuration into your Gen 7.x device. Period.
Yes, you can (some say should) use the Migration Tool.
Others say to rebuild the device manually.
Another alternative is to create a Template of your existing TZ470 in NSM and use that on the new device - and then customize per site requirements.
Irrespective of your approach, having already loaded a "bad" configuration, you are going to have to factory reset the Gen 7 device and upload the appropriate "good" configuration.