Import Procedure Guide for Firewall

Electrical – Electronics – IT / Cybersecurity appliance

IMPORT PROCEDURE GUIDE FOR FIREWALL

A firewall appliance carries higher classification risk than ordinary network equipment. A small inconsistency between “router”, “security gateway”, “VPN appliance”, “UTM” and “firewall appliance” may result in an incorrect HS code, missing cyber information security or civil cryptography documents, incorrect labelling policy, or late handling after ETA. This guide provides an E2E (End-to-End) roadmap for reviewing HS code, duty, C/O, specialized management policy, customs documents, customs hold points and pre-ETA risk controls before shipment execution.

QUICK FACTS

ItemQuick review contentOperational note
Applicable productFirewall / hardware firewall appliance.Not automatically applicable to NAC, IPS/IDS, DDoS appliance, SIEM, UTM or network monitoring if the primary function differs.
Reference HS to review8517.62.49 / 8517.62.99; also compare 8471.30.90 / 8471.41.90 / 8471.49.90 if the configuration is essentially ADP equipment.VBHN 13/VBHN-BTTTT lists Network-based Firewall under the cyber-information-security import permit list with HS directions including 8471.30.90, 8471.41.90, 8471.49.90, 8517.62.43 and 8517.62.49; 8517.62.99 should only be used where the actual classification file supports it.
Reference dutiesOrdinary duty 5%; MFN 0%; VAT 10%; FTA usually 0% with valid C/O.Re-check the tariff at declaration date; do not use outdated rates.
Specialized policyImport permit for cyber security/civil cryptography, ICT quality inspection or conformity documents may arise depending on model/function.Never state “no permit required” before reviewing the actual features.
Minimum technical fileCatalogue, datasheet, user manual, model list, license/feature list, label photos, firmware information and VPN/encryption description if any.Product name, model and specifications must be consistent across documents, catalogue, labels and declaration.
LEGAL NOTE

The HS codes, duty rates and specialized policies in this article are for initial planning only. Enterprises must review the tariff, legal documents and actual dossier at the declaration date.

Illustration for Import Procedure Guide for Firewall
Illustration of the product group and document review before customs clearance.

SCOPE OF APPLICATION

This article applies only to Firewall as a hardware appliance used to control, filter, allow or block network traffic between network zones based on security policies. The related group includes Firewall, NAC, IPS/IDS, DDoS appliance, SIEM, UTM and Network Monitoring; however, each product has its own classification and compliance logic.

The conclusions here should not be automatically applied to UTM, dedicated IPS/IDS, DDoS mitigation appliance, SIEM collector, network monitoring appliance, secure router, encrypted gateway or VPN appliance. New, used, refurbished, sample, warranty-return and project cargo may trigger different requirements. The actual catalogue, datasheet, model and import purpose must be reviewed.

CLASSIFICATION & TECHNICAL IDENTIFICATION

A firewall should be identified by its primary function, hardware architecture and security feature set. A model may be marketed as “Next-Generation Firewall”, “Security Gateway”, “Threat Prevention Appliance”, “VPN Firewall” or “UTM”. The commercial name does not replace customs classification; the technical nature must be reviewed.

Technical criterionDocuments to compareRisk if described incorrectlySuggested description on commercial/customs documents
Primary functionCatalogue, datasheet, product brief, user manualDescribing it as an ordinary router/switch may lead to wrong cyber security/civil cryptography policy.“Network firewall appliance, model…, used for network traffic control/filtering”.
Ports and protocolsLAN/WAN/SFP/SFP+ ports, throughput and protocol listWrong classification as general network or ADP equipment.State port quantity/type and speed; avoid generic “network equipment”.
VPN/encryptionFeature list, license sheet, admin guide, IPsec/SSL VPN/encryption detailsCivil cryptography review or permit may be triggered; missing permit delays clearance.Clearly state whether VPN, encryption, IP flow/channel protection exists.
Cyber security functionsFirewall policy, IPS, anti-malware, URL filtering, threat prevention documentsMay fall under cyber information security import permit list.Describe as firewall appliance; do not hide security functions.
License/subscriptionInvoice, packing list, license certificate, order confirmationValue, description and product nature may be questioned when a security license is included.Separate hardware and license if shown separately in documents.
ConditionGoods photos, serials, condition statement, contractUsed/refurbished IT goods may be subject to separate control.State “brand new” or actual condition accurately.
LEGAL NOTE

Generic descriptions such as “network device”, “router”, “computer appliance” or “security device” may result in wrong HS code, wrong specialized policy, permit risk, incorrect labelling and post-clearance explanation.

HS CODE – DUTY – C/O

For a firewall network appliance, HS classification must be reviewed carefully between heading 85.17 and heading 84.71. 8517.62.99 should not be treated as the absolute main direction. VBHN 13/VBHN-BTTTT on cyber information security products imported under permit lists Network-based Firewall with HS directions including 8471.30.90, 8471.41.90, 8471.49.90, 8517.62.43 and 8517.62.49. In practice, 8517.62.99 may still be considered only where the technical file supports the “other” data reception/conversion/transmission subheading. The final HS must be based on catalogue, datasheet, structure, primary function and actual goods description.

Detailed reference duty table

Reference HSDescription/application directionOrdinary dutyMFN dutyVATFTA/valid C/OControl note
8517.62.49Priority review direction for Network-based Firewall under the cyber-information-security import permit list; usually associated with network apparatus for wired/digital systems.5%0%10%Usually 0% with valid C/O and origin criteria met.Compare datasheet, ports, firewall/VPN functions, cyber-security criteria and goods description.
8517.62.99Fallback direction if the device belongs to “other” apparatus for data reception, conversion, transmission/regeneration and does not fit 8517.62.49.5%0%10%Usually 0% with valid C/O.Do not use as an absolute default; classification reasoning and technical evidence are required.
8471.30.90Review if the firewall is in the form of portable automatic data processing equipment matching the legal description.5%0%10%Usually 0% with valid C/O.Use only where structure and primary function fit heading 84.71.
8471.41.90Review if the device contains in the same housing at least a CPU, input unit and output unit, matching heading 84.71.5%0%10%Usually 0% with valid C/O.CPU/RAM or embedded OS alone is insufficient.
8471.49.90Review if the product is an ADP system rather than a specialized network appliance by primary function.5%0%10%Usually 0% with valid C/O.System description and independent data-processing function must be proven.

Reference HS review table

Reference HSApplication conditionRisk if incorrectDocuments to compare
8517.62.49Network-based Firewall or security network appliance with basis to be classified as wired/digital-system network apparatus.Wrong HS may affect cyber-security permit dossier, C/O and customs explanation.Catalogue, datasheet, user manual, feature list, label photos, model list.
8517.62.99Only where the classification file supports “other” data apparatus and not 8517.62.49.May be challenged if the cyber-security dossier or catalogue clearly identifies Network-based Firewall.HS classification note, ports, throughput, protocols, firewall/VPN functions.
8471.30.90 / 8471.41.90 / 8471.49.90Applicable where structure and primary function fit ADP equipment/system.May be seen as policy avoidance if based only on CPU/RAM without proving ADP nature.System description, CPU/RAM/storage, OS, operation diagram and independent data-processing proof.

C/O note: If MFN duty is already 0%, a C/O may not further reduce import duty, but it remains useful for origin control, contract requirements, post-clearance audit or specific FTA documentation. Wrong form, origin criterion, goods description or HS code may cause rejection of preferential treatment.

APPLICABLE SPECIALIZED POLICIES

Goods situationPotential policyDocuments to checkAuthority/portal if identifiableRecommended timingRisk note
Standard firewall, no wireless, no special VPN/encryptionCustoms, labelling, HS-duty-C/O; still review cyber security policy by product description.Catalogue, datasheet, invoice, packing list, original label.Customs; market surveillance authority for circulation.Before ETA.Do not conclude no permit without feature list.
Firewall with VPN, IPsec, SSL VPN, IP flow/channel protectionMay fall under civil cryptography and/or civil cryptography import permit.Encryption documents, VPN license, admin guide, datasheet.Government Cipher Committee / relevant public service portal.Before purchase or at least 10–15 working days before ETA.Missing permit may block clearance.
Firewall with anti-attack/intrusion, security gateway, threat preventionMay fall under cyber information security product import permit list.IPS/IDS, anti-malware, web filtering, sandbox and threat prevention documents.Authority responsible for cyber information security according to applicable regulations.Before ETA.Distinguish cyber security from civil cryptography; avoid overlapping if law excludes.
Firewall with Wi‑Fi/Bluetooth/4G/5G or radio moduleICT/telecom conformity and quality inspection may arise.RF specification, frequency band, test report, radio module datasheet.MST/CVT or relevant specialized portal depending on applicable period.Before arrival.Missing test report/conformity file may create pending obligations.
Firewall with adapter, PSU, battery or accessoriesLabelling and possible electrical safety/EMC review for accessories.Packing list, adapter datasheet, PSU label photos.Customs/specialized authority depending on goods.Before ETA.Accessories may change inspection or labelling requirements.
Used/refurbished goodsUsed IT goods restrictions or special import conditions.Condition statement, serial photos, contract, year of manufacture.MST/customs.Before signing contract.High risk if described only as “used equipment”.

LEGAL DOCUMENTS TO REVIEW

Document groupDocument name/numberIssuing bodyEffective/application timeRole in procedureKey article/annex to reviewReview note
LawCustoms Law 2014National AssemblyIn force; verify at time of clearance.Basis for customs dossier, declaration, inspection and clearance.Rules on customs dossier, physical inspection and clearance.Do not quote specific articles without checking the current text.
LawLaw on Export and Import Duties 2016National AssemblyIn force; check amendments if any.Basis for import duty obligations and preferential treatment.Taxable objects, tax calculation, exemption/reduction/refund if applicable.Check against the actual customs declaration.
LawLaw on Cyber Information Security No. 86/2015/QH13National AssemblyIn force; check amendments if any.Basis for cyber security products and civil cryptography management.Rules on business/import of cyber security and civil cryptography products.Security-feature firewall must be reviewed.
TariffDecree 26/2023/ND-CPGovernmentEffective from 15 July 2023.Preferential import tariff and taxable goods list.Import tariff annex.Re-check HS code and duty rate at declaration date.
CircularCircular 29/2025/TT-BKHCNMinistry of Science and TechnologyEffective from 31 December 2025.Group 2 ICT/telecom goods list.Annex I, II and corresponding QCVN if applicable.Applies when model has ICT/telecom features in scope.
Consolidated circularConsolidated document 13/VBHN-BTTTT on cyber information security import permitsMinistry of Information and CommunicationsCheck current validity and amendments.Review import permit for cyber information security products.List of cyber security products subject to import permit.Firewall with anti-attack/intrusion functions must be reviewed.
DecreeDecree 211/2025/ND-CPGovernmentEffective from 09 September 2025.Civil cryptography activities and import/export of civil cryptography products.Lists/conditions/permit dossier for civil cryptography.Applies if firewall has civil cryptography functions.
CircularCircular 26/2025/TT-BKHCNMinistry of Science and TechnologyEffective from 31 October 2025.Used IT goods import restriction/conditions.Used IT goods list.Important for used/refurbished goods.
DecreeDecree 43/2017/ND-CP amended by Decree 111/2021/ND-CPGovernmentVerify validity at circulation time.Goods labelling and Vietnamese supplementary label.Mandatory label contents, origin and responsible party.Compare original label and Vietnamese sub-label.

VIEW / DOWNLOAD ORIGINAL LEGAL DOCUMENTS

Enterprises may search legal documents by number on official legal document portals, the Government portal or the website of the issuing authority. Enterprises should also cross-check the document on official legal portals or the issuing authority’s website before application.

CUSTOMS CLEARANCE DOCUMENTS

Commercial documents

Specialized dossier if applicable

  • Cyber information security import permit if the product is in scope.
  • Civil cryptography import permit if the product is in scope.
  • Quality inspection/conformity certification/declaration if the model is Group 2 ICT/telecom.
  • Test report, technical file and self-assessment report if applicable.
  • Goods labelling file and Vietnamese supplementary label.

Control principle: Product name, quantity, model, serial, origin and specifications must be fully consistent across commercial documents, catalogue, labels, specialized dossier and customs declaration.

OPERATIONAL DOCUMENT CHECKLIST

Dossier groupRequired documentUsed for stepUsually prepared byCommon errorPre-ETA check
CommercialInvoice, Packing List, Contract/POValue, quantity, IncotermsProcurement/Docs/SupplierGeneric goods name; missing model; unclear license value.Compare each line with catalogue and PO.
TransportB/L or AWB, Arrival Notice, Pre-alertD/O, declaration, ETA monitoringForwarder/DocsWrong consignee, package/weight mismatch, missing pre-alert.Lock transport documents before ETA.
TechnicalCatalogue, datasheet, manual, feature/license listHS, policy and permit reviewSupplier/IT/ComplianceNo VPN/encryption/security feature details.Request supplier confirmation by model.
C/OPreferential C/O if anyPreferential duty and origin fileSupplier/ProcurementWrong form, HS, description or missing third-party invoice indication.Review draft C/O before issuance.
SpecializedCyber security/civil cryptography permit, conformity, test report if anyClearance/circulationLegal/Compliance/Service providerLate after ETA, missing technical file, wrong model.Finalize policy after receiving datasheet.
LabellingOriginal label photos and draft Vietnamese sub-labelClearance and local circulationImporter/ComplianceMissing origin, model or responsible party.Compare label with invoice, catalogue and labelling rules.

DECISION POINTS THAT MAY HOLD THE SHIPMENT

Decision pointQuestion to answerEvidenceConsequence if unclearRecommended handling
HS codeIs it a firewall appliance or another server/network device?Datasheet, product brief, user manualHS consultation, duty adjustment, delayed clearance.Prepare classification rationale before declaration.
Cyber security/civil cryptographyDoes it have VPN, encryption, anti-attack/intrusion or security gateway functions?Feature list, license, admin guideMissing permit or additional specialized dossier.Review by model and apply for permit/confirmation if needed.
Model and licenseDo documents, catalogue, label and license match?Invoice, PL, label, order confirmationDocument amendment or customs value explanation.Lock model list and license sheet before ETA.
C/OIs the C/O form, HS, description and origin criterion correct?C/O, invoice, packing listPreference denial or post-clearance recovery.Check draft C/O before official issuance.
New/used conditionIs it brand new, refurbished or used?Condition statement, serial photos, contractMay trigger used IT goods restriction.State accurate condition and review before purchase.
LabellingDo original and Vietnamese labels contain mandatory information?Label photos, sub-label draft, catalogueSupplement request or circulation risk.Prepare sub-label before domestic delivery.

PRACTICAL E2E PROCESS

Step 1: Pre-ETA review

Finalize reference HS, duty, C/O, labelling, cyber security/civil cryptography features, goods condition and potential permits or specialized inspection.

Step 2: Lock documents and technical file

Compare Invoice, Packing List, B/L/AWB, catalogue, datasheet, model list, serial/license list; ensure consistency of name, model, quantity and origin.

Step 3: Handle permit/specialized dossier if any

If firewall falls under cyber security, civil cryptography or Group 2 ICT/telecom, prepare permit, conformity and test report before arrival.

Step 4: Open customs declaration

Declare based on supported HS. Green channel may clear under conditions; Yellow checks documents; Red checks documents and physical goods.

Step 5: Clearance, delivery and post-clearance file

Release goods, deliver to warehouse, affix supplementary/conformity labels if applicable, retain shipment dossier and prepare post-clearance explanation file.

PRE-ETA RISK CHECKLIST

RiskConsequencePre-ETA controlDocuments to check
Over-generic goods nameWrong HS/policy and explanation request.Describe as firewall appliance with model and function.Catalogue, datasheet, invoice.
VPN/encryption not reviewedCivil cryptography permit may be missing.Ask supplier to confirm IPsec/SSL VPN/encryption.Feature list, admin guide.
Cyber security not reviewedCyber security import permit may be missing.Compare model/function with relevant list.Catalogue, product matrix.
Wrong C/O HS/descriptionPreference denial or recovery.Check draft C/O before issuance.Draft C/O, invoice, PL.
Model mismatchChannel change or document amendment request.Lock model/serial list before ETA.Invoice, PL, label photos.
Refurbished/used condition unclearUsed IT goods restriction risk.Confirm condition before contract.Contract, serial photos, condition statement.

FAQ – COMMON BUSINESS QUESTIONS

Does importing a firewall require a permit?

It may, if the model falls under cyber information security or civil cryptography lists. Review catalogue, datasheet, feature list and import purpose first.

Does a firewall with VPN fall under civil cryptography?

It may require civil cryptography review if it has IP flow/channel protection, VPN or encryption. The current technical specifications and lists must be checked.

What is the main HS code for firewall?

8517.62.49 is the priority review direction under the cyber-security list for Network-based Firewall; 8517.62.99 is only a fallback where the classification file supports it. Final HS depends on actual function, structure and technical documents.

Is C/O still needed if MFN is 0%?

It may not reduce duty further, but it remains useful for origin file, contract requirements or post-clearance audit.

Is Vietnamese supplementary labelling required?

Yes, for circulation in Viet Nam, goods labelling and Vietnamese sub-label requirements should be reviewed.

Are sample or warranty goods handled the same as commercial goods?

Not automatically. Review condition, import purpose, value, specialized policy and re-export obligations if any.

What if invoice says “security gateway” but catalogue says firewall?

Standardize the product description and prepare technical explanation of primary function to avoid being treated as another product group.

EXECUTION SUPPORT FROM TGIMEX

This guide provides a roadmap on HS code, duty, dossier and specialized policy for Firewall. In real shipment execution, however, enterprises still need to review the actual catalogue, datasheet, model, firmware, license, documents, origin and import purpose.

Pre-ETA review
  • HS, duty, C/O and goods labelling.
  • Cyber security, civil cryptography and ICT conformity if applicable.
  • Model, feature, license and datasheet comparison.
E2E execution
  • Coordination with overseas agents, carriers/airlines and pre-alert.
  • Customs declaration and Green/Yellow/Red channel handling.
  • Domestic delivery and post-clearance dossier retention.

For shipments that may trigger specialized inspection, permits, C/O or labelling requirements, enterprises should not wait until arrival to start the compliance review. Any mismatch among Invoice, Packing List, catalogue, datasheet, C/O or labels may lead to additional document requests, delayed clearance or unplanned storage costs.

TGIMEX supports enterprises in building an E2E import execution plan: pre-ETA policy review, document checking, international freight coordination, customs declaration, clearance handling, domestic delivery and post-clearance dossier retention.

QUICK CONSULTATION

NEED TO REVIEW IMPORT PROCEDURES OR A SHIPPING PLAN?

Send us the product name, shipping route, current dossier, or implementation request in advance so we can suggest a suitable approach that is practical, focused, and aligned with your shipment.

CALL NOW
Zalo
HOTLINE 0963 856 664 / 0982 135 393
EMAIL info@tgimex.com
SUITABLE FOR International shipping · Customs procedures · Import licenses · B2B logistics

Leave a Reply

Discover more from TGIMEX VIETNAM JSC

Subscribe now to keep reading and get access to the full archive.

Continue reading