Firewall migration to pfSense Plus — planned, tested, reversible

We move UK businesses off FortiGate, SonicWall, WatchGuard, DrayTek, Cisco ASA and Sophos onto Netgate hardware — with the new firewall built and tested in parallel before your live network is touched, a written rollback plan, and typically 15–30 minutes of downtime in a window you choose.

Get a fixed migration quote → From £399 inc. VAT · out-of-hours cutover included

How the migration works

1
Discovery & audit

You send us a config export (or screenshots) from your current firewall plus your ISP details. We map every rule, NAT policy, VPN and VLAN — and flag anything redundant, risky or broken. Most firewalls we audit are carrying years of dead rules; we don't copy the mess across.

2
Parallel build

We configure your new Netgate appliance completely off-line: rules recreated and tidied, VPNs rebuilt and tested against a staging peer, VLANs and DHCP mapped one-for-one. Your live network is untouched during this phase — zero risk, zero downtime.

3
Scheduled cutover

At an agreed window (evenings and weekends included at no extra charge), we swap the firewalls and work through a written test checklist with you: internet, every VPN, every port forward, every VLAN. Typical downtime is 15–30 minutes.

4
Rollback safety net

Your old firewall stays cabled up, configured and powered off beside the rack. If anything unexpected appears, rolling back is a two-minute cable swap — not a restore job. We have never had to leave a site rolled back, but the option is always there.

5
30 days of aftercare

Every migration includes 30 days of post-migration support for anything related to the move. Combine it with a managed plan and we simply keep looking after the firewall from day one.

A typical deployment

Most of our migrations look something like this — a head office with VLAN separation, branch sites joined by IPsec, and remote staff on WireGuard. If yours is simpler, the process is the same but shorter; if it's bigger, we quote it site by site.

Head officeNetgate 6100 MAXVLANs: staff · guest · CCTV Branch 1Netgate 2100 MAX Branch 2Netgate 2100 MAX Roaming staffWireGuard on laptops IPsec VPNIPsec VPNWireGuard

A typical 3-site deployment we migrate: two branches and roaming users, all previously on separate vendor boxes.

What we need from you

You don't need a network diagram (though it helps). For a fixed quote we ask for: the make, model and firmware version of your current firewall; a config export or backup file (we tell you exactly how to get one from your vendor); your internet connection details — static IPs, PPPoE credentials, or ISP router model; a list of VPNs — site-to-site peers and how many remote users; and any port forwards or special applications (VoIP, CCTV, card terminals, RDP). Can't get a config export? Screenshots of the rule and VPN pages are usually enough for us to scope it.

Downtime, honestly

The parallel-build approach means the only downtime is the physical swap and final testing: typically 15–30 minutes, in an evening or weekend window at no extra charge. Complex sites — many VPN peers, multiple WANs, VoIP re-registration — can take up to an hour. What we don't do is rebuild your firewall live on a Friday afternoon and hope: if a migration can't be made low-risk, we'll tell you before you book it.

What it costs

Single site: from £399 inc. VAT when bought alongside a Netgate appliance — audit, parallel build, out-of-hours cutover, rollback plan and 30 days of aftercare included. Multi-site, HA pairs and complex estates are quoted individually as a fixed price, not day rates. Add a managed plan and we keep running the firewall from the moment it goes live.

Not sure if your setup can be migrated? Send us the details — we'll tell you honestly what's involved before you spend a penny.