Firewall migration to pfSense Plus — planned, tested, reversible
We move UK businesses off FortiGate, SonicWall, WatchGuard, DrayTek, Cisco ASA and Sophos onto Netgate hardware — with the new firewall built and tested in parallel before your live network is touched, a written rollback plan, and typically 15–30 minutes of downtime in a window you choose.
Get a fixed migration quote → From £399 inc. VAT · out-of-hours cutover includedHow the migration works
You send us a config export (or screenshots) from your current firewall plus your ISP details. We map every rule, NAT policy, VPN and VLAN — and flag anything redundant, risky or broken. Most firewalls we audit are carrying years of dead rules; we don't copy the mess across.
We configure your new Netgate appliance completely off-line: rules recreated and tidied, VPNs rebuilt and tested against a staging peer, VLANs and DHCP mapped one-for-one. Your live network is untouched during this phase — zero risk, zero downtime.
At an agreed window (evenings and weekends included at no extra charge), we swap the firewalls and work through a written test checklist with you: internet, every VPN, every port forward, every VLAN. Typical downtime is 15–30 minutes.
Your old firewall stays cabled up, configured and powered off beside the rack. If anything unexpected appears, rolling back is a two-minute cable swap — not a restore job. We have never had to leave a site rolled back, but the option is always there.
Every migration includes 30 days of post-migration support for anything related to the move. Combine it with a managed plan and we simply keep looking after the firewall from day one.
A typical deployment
Most of our migrations look something like this — a head office with VLAN separation, branch sites joined by IPsec, and remote staff on WireGuard. If yours is simpler, the process is the same but shorter; if it's bigger, we quote it site by site.
A typical 3-site deployment we migrate: two branches and roaming users, all previously on separate vendor boxes.
What we need from you
You don't need a network diagram (though it helps). For a fixed quote we ask for: the make, model and firmware version of your current firewall; a config export or backup file (we tell you exactly how to get one from your vendor); your internet connection details — static IPs, PPPoE credentials, or ISP router model; a list of VPNs — site-to-site peers and how many remote users; and any port forwards or special applications (VoIP, CCTV, card terminals, RDP). Can't get a config export? Screenshots of the rule and VPN pages are usually enough for us to scope it.
Downtime, honestly
The parallel-build approach means the only downtime is the physical swap and final testing: typically 15–30 minutes, in an evening or weekend window at no extra charge. Complex sites — many VPN peers, multiple WANs, VoIP re-registration — can take up to an hour. What we don't do is rebuild your firewall live on a Friday afternoon and hope: if a migration can't be made low-risk, we'll tell you before you book it.
What it costs
Single site: from £399 inc. VAT when bought alongside a Netgate appliance — audit, parallel build, out-of-hours cutover, rollback plan and 30 days of aftercare included. Multi-site, HA pairs and complex estates are quoted individually as a fixed price, not day rates. Add a managed plan and we keep running the firewall from the moment it goes live.