SonicWall NSv 7.1.1+ Will Not Boot on VergeOS
SonicWall NSv firewalls on SonicOS 7.1.1+ fail to boot after import into VergeOS because the appliance requires SonicWall's signed OVMF firmware. Custom EFI firmware support is coming in Q3 2026.
SonicWall NSv virtual firewalls on SonicOS 7.1.1 and later do not currently boot after import into VergeOS. This article explains why the appliance fails to start and what your options are in the meantime.
Symptoms
You import a SonicWall NSv appliance into VergeOS and it fails to boot.
The console shows a firmware validation error such as
Invalid firmware detected.The failure is the same no matter which source format you import from — KVM/QCOW2, VMware OVA, or Hyper-V VHDX.
Overview
SonicWall ships the NSv image with its own custom OVMF firmware files — OVMF_CODE.sw.fd and OVMF_VARS.sw.fd — that carry SonicWall-specific Secure Boot certificates. At boot, SonicCoreX checks that it is running on exactly that firmware and aborts on anything else.
VergeOS builds and manages each VM's UEFI variable disk from standard OVMF templates. There is currently no supported way to swap the EFI disk's media source through the UI or API. The appliance cannot see SonicWall's custom firmware files, so its boot-time firmware check fails and the NSv does not start.
Options in the Meantime
Any virtual firewall that boots on standard UEFI firmware runs well on VergeOS, as a VM or inside a tenant. It can fill the role until NSv support arrives.
If you want to stay on SonicWall today, run the firewall on physical SonicWall hardware and connect it to your VergeOS environment over the network.
Last updated
Was this helpful?