
Back Up and Restore SonicWall Settings and Firmware Safely
Before you run this
This guide covers two related jobs on a SonicWall firewall: taking a full backup of the running configuration (and creating a restore point), and upgrading or rolling back firmware. The purpose is simple — never touch firmware or a risky rule change without a known-good copy you can boot back to.
A few things to be clear about up front:
- You need full administrator credentials on the appliance — the built-in
adminaccount or an equivalent role. Exporting settings and flashing firmware are not available to read-only or limited admins. - Read each step before you click it. If you can, rehearse the whole flow on a spare or lab unit first (SonicWall's virtual NSv is fine for practising the menus). Do not learn the firmware page for the first time on the box that carries production traffic.
- A firmware upgrade reboots the firewall and drops all traffic for the duration of the reboot. Booting a firmware image "with factory default settings" wipes the running config — that is destructive and not reversible except by restoring a backup. Know which boot option you are choosing.
- Keep an out-of-band path open. Have the serial console cable (RJ45-to-DB9/USB) plugged into the console port, or at minimum a second browser session and the physical reset button documented, so a bad config or a hung upgrade doesn't leave you locked out with no way in.
- Back up before you change anything — that is literally step one below.
- Do this in a maintenance window. The rollback path is SonicWall's own SafeMode (reached with the reset button) plus booting a saved firmware/settings image; both are covered at the end.
What I'm assuming
- A Gen 7 SonicWall (TZ or NSa series) running SonicOS 7.x, managed through its web GUI.
- You have a MySonicWall account with the appliance registered to it, and a valid support/firmware entitlement so you can download firmware.
- You are working from a management workstation that can reach the firewall's LAN/management IP over HTTPS.
If you are on an older Gen 6 unit running SonicOS 6.5, the same concepts apply but the menu lives under MANAGE | Updates | Firmware & Settings instead of the Gen 7 path below. The exported settings file has the same .exp extension.
Step 1 — Export the running configuration
In SonicOS 7 the relevant page is:
DEVICE | Settings | Firmware and Settings
That page has two things you care about: a table of firmware/local-backup images, and a toolbar with actions to create a backup, import/export configuration, and upload firmware. (Exact button wording can shift slightly between 7.0 and 7.1 builds — if a label doesn't match, check the "Firmware and Settings" chapter of the SonicOS 7 Device Settings administration guide on the SonicWall documentation site.)
Do both of these:
- Export the settings file. Use the export action to download a settings file to your workstation. It saves with a
.expextension. This is your off-box copy — keep it somewhere backed up, not just on the firewall. - Create a local backup. Use Create Backup to store a restore point on the appliance itself. This gives you a one-click "boot this saved config" entry in the firmware table. If your unit and licence support Cloud Backup, create one of those too — it stores the snapshot in MySonicWall so it survives a hardware failure.
One honest caveat about the .exp file: it is tied to the firmware version it came from. A settings file exported on one SonicOS version is not guaranteed to import cleanly onto a different major version. So export before you upgrade, and keep that pre-upgrade file until the new firmware has proven stable.
Name your files so future-you understands them, e.g. TZ470-prod-7.0.1-2025-06-01.exp.
Step 2 — Verify the backup before you trust it
A backup you haven't checked is a guess. Confirm two things:
- The
.expfile actually downloaded and has a non-zero size on your workstation. - The local backup you created appears as a new row in the firmware/backup table on the Firmware and Settings page, with today's date/timestamp.
If you have a lab unit, the real test is to import the .exp onto it and confirm it boots with your settings. On production, at least confirm the file and the local-backup row exist before moving on.
Step 3 — Upgrade firmware
- Download the firmware from MySonicWall for your exact model. Read the release notes first — they list the supported upgrade path. SonicWall sometimes requires stepping through an intermediate version rather than jumping several releases at once; do not skip that.
- On DEVICE | Settings | Firmware and Settings, use Upload Firmware and select the downloaded image. Uploading does not activate it — it just adds the image to the table.
- Once uploaded, the new image appears as a row with its own boot control. Boot the new firmware "with current settings" — this keeps your configuration. Choosing "with factory default settings" instead is how you wipe the box, so only pick that deliberately.
- The firewall reboots. Wait for it to come fully back and re-establish traffic before doing anything else.
The previous firmware and your local backup stay in the table. That is your rollback, so don't delete them until the upgrade has run clean for a while.
Step 4 — Restore settings (or roll back firmware)
To restore a configuration onto a running, reachable firewall:
- From an on-box backup: on the Firmware and Settings page, boot the saved local-backup row. The firewall reboots into that saved config.
- From an
.expfile: use the import-configuration action, select your.exp, and the firewall imports and reboots. Remember the version-match caveat — import onto the same firmware family it came from.
To roll back firmware, boot the previous firmware image row (again, "with current settings" if you want to keep the config that image last ran).
If the firewall is unreachable — bad config, or an upgrade left it unresponsive — use SafeMode: hold the reset button per your model's instructions until it enters SafeMode, then browse to the SafeMode management IP and, from there, boot a known-good firmware/settings image or upload a fresh one. The exact reset-button timing and SafeMode IP are model-specific; get them from your model's Getting Started / SafeMode section in the SonicWall documentation before you need them, not during the outage.
Verify it worked
After any restore or upgrade, confirm the box is actually the way you expect:
- Firmware version: check the version shown on the dashboard / DEVICE | Settings matches what you intended.
- Config sanity: spot-check a few objects you know — a couple of access rules, your WAN interface addressing, VPN status (MONITOR dashboards) — rather than assuming the whole config came back.
- Traffic: confirm real production traffic (internet, VPN tunnels, published services) is flowing, not just that the GUI loads.
- Admin access: confirm you can still log in over your normal management path and that the console/OOB path still works.
Undo
The undo for everything here is the copy you made in Step 1: boot the previous firmware row, boot the local backup, or import the pre-change .exp. If those aren't reachable, SafeMode plus a re-upload is the last resort. Keep the pre-upgrade .exp and the previous firmware image until the change has proven itself — that is the whole point of doing Step 1 first.
Runs enterprise networks and security for a living, and writes Shore Up to turn two decades of hands-on Linux, Windows and mail-server work into guides you can actually use.
More about the author →Was this article helpful?
Tap a star — no sign-in needed.
Be the first to rate this article.
