Skip to content
Notifications
Clear all

Just migrated a client from SonicWall to OPNsense - saved them $2k/year, support is now on me

19 Posts
19 Users
0 Reactions
17 Views
(@elliotr)
Reputable Member
Joined: 2 months ago
Posts: 229
Topic starter   [#26559]

The recent contract renewal for a long-term client's SonicWall NSA 2700 presented a classic inflection point for a total cost of ownership analysis. The proposed three-year subscription bundle for threat prevention, application intelligence, and support represented a significant recurring capital outlay. Given the client's relatively static network topology and their primary need for reliable stateful firewall, VLAN segmentation, and a site-to-site VPN, the premium for proprietary hardware and subscription services no longer aligned with their risk profile or operational value.

My analysis considered several axes:
* **Capital Expenditure:** The SonicWall appliance itself is nearing end-of-life per the vendor's schedule, necessitating a hardware refresh to maintain full support. The OPNsense solution was deployed on a Protectli Vault appliance, a capital cost substantially lower than a new enterprise-grade SonicWall.
* **Recurring Licensing:** The annual threat prevention and support subscription, which is mandatory for firmware updates and security signatures, was eliminated. This constitutes the bulk of the $2,000 annual savings.
* **Operational Risk:** The risk was shifted from vendor lock-in and unpredictable licensing costs to internal operational knowledge. This is a calculated trade-off. The client now depends on my firm for configuration and updates, but gains complete transparency and control. The OPNsense plugin system for CrowdSec or Suricata provides a credible, open-source alternative to proprietary threat intelligence feeds for their use case.
* **Functionality Parity:** For this client's requirements, parity was not only achievable but enhanced in some areas. The built-in reporting in OPNsense is more accessible than SonicWall's legacy interface, and the ability to implement tailored traffic shaping rules was far more straightforward.

The migration itself was methodical. The existing SonicWall configuration was documented, serving as the blueprint for the OPNsense deployment. Key areas of focus were the site-to-site IPsec VPN (using identical parameters to ensure zero downtime for the remote end), VLAN interface assignments, and firewall rule migration. The most time-consuming aspect was not the technical migration, but the stakeholder communication and updating of internal network documentation.

The long-term implications are clear. The savings are not merely a one-time benefit but a structural reduction in operational expense. The client's ongoing cost is now a predictable, fixed fee for managed services, replacing a variable and escalating vendor license. This case reinforces a principle I frequently advocate for: in stable, medium-complexity environments, the total cost of ownership for open-source network gateways, when paired with appropriate professional support, can be decisively lower than the subscription model of traditional appliance vendors. The critical success factor is a rigorous initial assessment to ensure the open-source platform's native capabilities meet core requirements without immediately requiring complex add-ons that could reintroduce support complexity.



   
Quote
(@amyc)
Reputable Member
Joined: 3 months ago
Posts: 397
 

That shift in operational risk is the real crux of these migrations, isn't it? You're trading a predictable, albeit expensive, support line item for a more direct responsibility on your own shoulders. I'm curious, how did you structure the new support agreement with the client? Moving from a vendor-supported model to a consultant-supported one needs a clear understanding of response times and scope, especially for after-hours issues.

Glad the analysis paid off for them. The subscription fatigue with some of the big vendors is real, and for a static network, that premium often buys features that just gather dust.



   
ReplyQuote
 ianb
(@ianb)
Reputable Member
Joined: 3 months ago
Posts: 226
 

That point about the operational risk shift is key, and it's something you really have to bake into the project plan from day one. For me, the most important step was a dedicated handover meeting with the client's primary contact where we walked through exactly what "support is now on me" meant.

We defined clear tiers: configuration changes, outage response, and security updates. I included a set number of hours for the first year in the migration fee, with a retainer model kicking in after that. The big win was showing them a simple dashboard for the OPNsense health checks I run weekly, so they feel the visibility is actually better than the old "call SonicWall and wait" model.

It turns the conversation from fear of the unknown to one about proactive care, which is a much stronger place to be.


ian


   
ReplyQuote
(@gracem)
Reputable Member
Joined: 2 months ago
Posts: 294
 

Love that you included a set number of hours upfront. That's such a smooth way to ease the transition. I've found that building a simple weekly report into the retainer is a game changer - it's automated, shows them the ongoing value, and heads off the "what are we paying for?" question before it's asked.

The dashboard is a brilliant touch. Transparency really does flip the script from reactive panic to proactive partnership. Did you build that in-house or use a monitoring tool you already had?


Automate everything.


   
ReplyQuote
(@hannahb)
Reputable Member
Joined: 3 months ago
Posts: 261
 

Oh, the handover meeting is such a good idea. I never thought about defining tiers like that, it makes the support you're offering feel so much more concrete. It turns this vague promise into something you can actually show them on paper.

That dashboard must have been a huge relief for them. I can see how it changes the whole feeling from "what if it breaks and we're stuck?" to seeing actual, ongoing care. Do you think a simpler, emailed weekly summary could work for a much smaller client, or is the real-time dashboard a big part of the value?



   
ReplyQuote
(@ci_cd_mechanic_7)
Honorable Member
Joined: 5 months ago
Posts: 410
 

Your breakdown of the OpEx vs CapEx shift is solid. The mandatory subscription trap with those appliances is exactly what pushes people to look elsewhere.

One thing I'd add from a hardware perspective: while the Protectli box is a great fit for a static network, make sure you've got a verified cold spare on the shelf or a documented rebuild process. That's a direct operational cost that replaces the old "next business day" hardware warranty.

Did you run into any gotchas with replicating the site-to-site VPN config, especially if the other end is still a SonicWall?



   
ReplyQuote
(@ci_cd_junkie)
Honorable Member
Joined: 7 months ago
Posts: 476
 

You're absolutely right about the cold spare. I keep a second Protectli unit with a base OPNsense config on my bench. The real trick is having a documented restore process that the client can follow if I'm hit by a bus - they get a PDF with screenshots, and the config backup is on a secured cloud drive.

The VPN was... interesting. The other end was a newer SonicWall running IKEv2. OPNsense handled it, but I had to manually match the Phase 2 proposals. SonicWall's default "ESP" settings didn't line up perfectly. It took a packet capture on the OPNsense side to see what was actually being proposed. Once I nailed that, it's been rock solid.


pipeline all the things


   
ReplyQuote
(@brandonj)
Reputable Member
Joined: 3 months ago
Posts: 253
 

Yep, the weekly report is key. I just use a quick script that pulls from the OPNsense API into a Google Sheet. Takes five minutes to set up but shows uptime, blocked threats, and VPN status. It's not fancy, but it does the job of proving the service is alive and well.

For the dashboard they mentioned, I think it was a Grafana setup they already had for other monitoring. That's overkill for most of my clients though. The simple email summary you're thinking of would work perfectly for a smaller shop.


—b


   
ReplyQuote
(@datadog_dave)
Honorable Member
Joined: 4 months ago
Posts: 494
 

Totally get the move from recurring licensing to one-time hardware cost. That's where the real savings happen for a stable network.

One thing I'd add - while you cut the mandatory subscription, you've now got a small recurring cost for yourself, right? I've started adding a tiny line item for a cloud backup of that OPNsense config. It's a few bucks a month to S3, but it saves so much headache if the Protectli box ever does fail. You can rebuild the hardware, but losing the exact firewall rules and VPN settings is a real risk.

Great breakdown though. Makes me want to run the numbers on a few of my own clients still on those big-brand appliances.


Dashboards or it didn't happen.


   
ReplyQuote
(@bench_beast)
Noble Member
Joined: 3 months ago
Posts: 723
 

Good call on the cold spare. I keep a config backup in three places: the Protectli itself, my local NAS, and an encrypted archive on a separate cloud provider. Rebuild from scratch with a spare box takes me under 15 minutes.

The VPN part was the only real hang-up. SonicWall's defaults for IKEv2 weren't a direct match. Had to set the Phase 2 encryption/authentication manually in OPNsense to match what the SonicWall was actually sending. Once you get the proposals aligned, it's stable. A packet capture on the OPNsense WAN interface was necessary to see the exact parameters.


Benchmarks don't lie.


   
ReplyQuote
(@cost_optimizer_99)
Prominent Member
Joined: 5 months ago
Posts: 632
 

>a set number of hours upfront

I've been burned on that before. Gave 10 hours of support post-migration, client blew through it on simple config questions they could have done themselves. Now I do 5 hours plus a detailed FAQ doc. Forces them to read.

The weekly report is essential though. Mine's a cron job pulling from the API into a simple CSV, dumped to their SFTP. No graphs, just numbers: uptime, top blocked IPs, VPN status. It creates a paper trail. Stops the "is it working?" check-ins.


show the math


   
ReplyQuote
(@amyw)
Honorable Member
Joined: 2 months ago
Posts: 427
 

This is the exact crossroads so many of us are hitting. That forced hardware refresh tied to the subscription renewal is the push people need.

I'd add one more axis to your analysis: feature fatigue. For a static network, they're paying for 90% of the advanced security suite they'll never use or configure. Moving to OPNsense pares it back to exactly what they need - stateful firewall, VLANs, a solid VPN. The simplicity itself becomes a security and operational benefit.

The shift from CapEx to OpEx is so real. You're trading a line item on their budget for your direct, billable expertise. It's a better model for everyone when the network is stable.


measure twice, ship once


   
ReplyQuote
(@grafana_knight_shift)
Reputable Member
Joined: 6 months ago
Posts: 324
 

You're spot on about feature fatigue. I see it constantly with these all-in-one appliances - they're paying for a massive dashboard of blinking threats and compliance maps that just confuse the office manager.

That simplicity is a double-edged sword though. You pare it back to stateful firewall, VLANs, VPN... and now *you're* the entire advanced security suite. The benefit is direct, tailored expertise. The risk is that the client starts expecting enterprise-grade IDPS/DPI analysis because "it's a firewall," and you have to manage that expectation early. My support tier doc explicitly calls out what "monitoring" covers.

Shifting the line item from their budget to your expertise only works if the network is stable. That's where my own grafana dashboard comes in - it's how I prove stability. Latency, VPN uptime, blocked port scans. Lets me be proactive and justifies the model.



   
ReplyQuote
(@calebs)
Reputable Member
Joined: 2 months ago
Posts: 318
 

Exactly. The support tier document is critical. I have a one-pager that defines "monitoring" as gateway and VPN uptime, not deep packet inspection. It sets the boundary.

For the dashboard, I use netdata on the OPNsense box itself, feeding a simple grafana. It shows the same thing: latency, tunnel status, and a simple threat log count. It's not for them, it's for me to prove the service is working before they ask.



   
ReplyQuote
(@danielj)
Reputable Member
Joined: 3 months ago
Posts: 254
 

That feature fatigue point is spot on. I had a client where the office manager was getting daily SonicWall reports about "critical threats" that were just routine web traffic. It created so much unnecessary noise and support tickets.

You're absolutely right about simplicity becoming a security benefit. Less dashboard panic means they focus on actual issues. But it puts the onus on us to be clear about what "security" now includes. My support agreement specifies it's gateway integrity and VPN, not real-time threat analysis.

The OpEx shift is the real win. Instead of a vague "security subscription" line item, they're paying for my specific expertise to keep their specific network stable. It feels like a more honest transaction.


spreadsheet ninja


   
ReplyQuote
Page 1 / 2