Convert Firewalls to Master NGFW Engines and Virtual Firewall elements

You can use a conversion tool to change a Single Firewall or Firewall Cluster element to a Master NGFW Engine and Virtual Firewall elements.

The Master NGFW Engine must always be based on a Firewall. The Virtual NGFW Engines can only be in the Virtual Firewall role. Only Single Firewalls or Firewall Clusters that are running on 64-bit hardware can be converted to Master NGFW Engines and Virtual Firewalls.

Single Firewalls and Firewall Clusters with the following configurations cannot be converted to Master NGFW Engines and Virtual Firewalls:
  • Firewall Clusters that use a CVI as the Control IP address
  • Firewall Clusters that have only a CVI on the Heartbeat Interface
  • Single Firewalls that have ADSL Interfaces
  • Single Firewalls that have Wireless Interfaces
  • Single Firewalls that have a dynamic IP address
  • Single Firewalls or Firewall Clusters that have a dynamic Contact Address
  • Single Firewalls or Firewall Clusters that have DHCP settings on the interface for communication with the Management Server