IMPORT PROCEDURE GUIDE FOR FIREWALL
QUICK FACTS
| Item | Quick review content | Operational note |
|---|---|---|
| Applicable product | Firewall / hardware firewall appliance. | Not automatically applicable to NAC, IPS/IDS, DDoS appliance, SIEM, UTM or network monitoring if the primary function differs. |
| Reference HS to review | 8517.62.49 / 8517.62.99; also compare 8471.30.90 / 8471.41.90 / 8471.49.90 if the configuration is essentially ADP equipment. | VBHN 13/VBHN-BTTTT lists Network-based Firewall under the cyber-information-security import permit list with HS directions including 8471.30.90, 8471.41.90, 8471.49.90, 8517.62.43 and 8517.62.49; 8517.62.99 should only be used where the actual classification file supports it. |
| Reference duties | Ordinary duty 5%; MFN 0%; VAT 10%; FTA usually 0% with valid C/O. | Re-check the tariff at declaration date; do not use outdated rates. |
| Specialized policy | Import permit for cyber security/civil cryptography, ICT quality inspection or conformity documents may arise depending on model/function. | Never state “no permit required” before reviewing the actual features. |
| Minimum technical file | Catalogue, datasheet, user manual, model list, license/feature list, label photos, firmware information and VPN/encryption description if any. | Product name, model and specifications must be consistent across documents, catalogue, labels and declaration. |
The HS codes, duty rates and specialized policies in this article are for initial planning only. Enterprises must review the tariff, legal documents and actual dossier at the declaration date.
SCOPE OF APPLICATION
This article applies only to Firewall as a hardware appliance used to control, filter, allow or block network traffic between network zones based on security policies. The related group includes Firewall, NAC, IPS/IDS, DDoS appliance, SIEM, UTM and Network Monitoring; however, each product has its own classification and compliance logic.
The conclusions here should not be automatically applied to UTM, dedicated IPS/IDS, DDoS mitigation appliance, SIEM collector, network monitoring appliance, secure router, encrypted gateway or VPN appliance. New, used, refurbished, sample, warranty-return and project cargo may trigger different requirements. The actual catalogue, datasheet, model and import purpose must be reviewed.
CLASSIFICATION & TECHNICAL IDENTIFICATION
A firewall should be identified by its primary function, hardware architecture and security feature set. A model may be marketed as “Next-Generation Firewall”, “Security Gateway”, “Threat Prevention Appliance”, “VPN Firewall” or “UTM”. The commercial name does not replace customs classification; the technical nature must be reviewed.
| Technical criterion | Documents to compare | Risk if described incorrectly | Suggested description on commercial/customs documents |
|---|---|---|---|
| Primary function | Catalogue, datasheet, product brief, user manual | Describing it as an ordinary router/switch may lead to wrong cyber security/civil cryptography policy. | “Network firewall appliance, model…, used for network traffic control/filtering”. |
| Ports and protocols | LAN/WAN/SFP/SFP+ ports, throughput and protocol list | Wrong classification as general network or ADP equipment. | State port quantity/type and speed; avoid generic “network equipment”. |
| VPN/encryption | Feature list, license sheet, admin guide, IPsec/SSL VPN/encryption details | Civil cryptography review or permit may be triggered; missing permit delays clearance. | Clearly state whether VPN, encryption, IP flow/channel protection exists. |
| Cyber security functions | Firewall policy, IPS, anti-malware, URL filtering, threat prevention documents | May fall under cyber information security import permit list. | Describe as firewall appliance; do not hide security functions. |
| License/subscription | Invoice, packing list, license certificate, order confirmation | Value, description and product nature may be questioned when a security license is included. | Separate hardware and license if shown separately in documents. |
| Condition | Goods photos, serials, condition statement, contract | Used/refurbished IT goods may be subject to separate control. | State “brand new” or actual condition accurately. |
Generic descriptions such as “network device”, “router”, “computer appliance” or “security device” may result in wrong HS code, wrong specialized policy, permit risk, incorrect labelling and post-clearance explanation.
HS CODE – DUTY – C/O
For a firewall network appliance, HS classification must be reviewed carefully between heading 85.17 and heading 84.71. 8517.62.99 should not be treated as the absolute main direction. VBHN 13/VBHN-BTTTT on cyber information security products imported under permit lists Network-based Firewall with HS directions including 8471.30.90, 8471.41.90, 8471.49.90, 8517.62.43 and 8517.62.49. In practice, 8517.62.99 may still be considered only where the technical file supports the “other” data reception/conversion/transmission subheading. The final HS must be based on catalogue, datasheet, structure, primary function and actual goods description.
Detailed reference duty table
| Reference HS | Description/application direction | Ordinary duty | MFN duty | VAT | FTA/valid C/O | Control note |
|---|---|---|---|---|---|---|
| 8517.62.49 | Priority review direction for Network-based Firewall under the cyber-information-security import permit list; usually associated with network apparatus for wired/digital systems. | 5% | 0% | 10% | Usually 0% with valid C/O and origin criteria met. | Compare datasheet, ports, firewall/VPN functions, cyber-security criteria and goods description. |
| 8517.62.99 | Fallback direction if the device belongs to “other” apparatus for data reception, conversion, transmission/regeneration and does not fit 8517.62.49. | 5% | 0% | 10% | Usually 0% with valid C/O. | Do not use as an absolute default; classification reasoning and technical evidence are required. |
| 8471.30.90 | Review if the firewall is in the form of portable automatic data processing equipment matching the legal description. | 5% | 0% | 10% | Usually 0% with valid C/O. | Use only where structure and primary function fit heading 84.71. |
| 8471.41.90 | Review if the device contains in the same housing at least a CPU, input unit and output unit, matching heading 84.71. | 5% | 0% | 10% | Usually 0% with valid C/O. | CPU/RAM or embedded OS alone is insufficient. |
| 8471.49.90 | Review if the product is an ADP system rather than a specialized network appliance by primary function. | 5% | 0% | 10% | Usually 0% with valid C/O. | System description and independent data-processing function must be proven. |
Reference HS review table
| Reference HS | Application condition | Risk if incorrect | Documents to compare |
|---|---|---|---|
| 8517.62.49 | Network-based Firewall or security network appliance with basis to be classified as wired/digital-system network apparatus. | Wrong HS may affect cyber-security permit dossier, C/O and customs explanation. | Catalogue, datasheet, user manual, feature list, label photos, model list. |
| 8517.62.99 | Only where the classification file supports “other” data apparatus and not 8517.62.49. | May be challenged if the cyber-security dossier or catalogue clearly identifies Network-based Firewall. | HS classification note, ports, throughput, protocols, firewall/VPN functions. |
| 8471.30.90 / 8471.41.90 / 8471.49.90 | Applicable where structure and primary function fit ADP equipment/system. | May be seen as policy avoidance if based only on CPU/RAM without proving ADP nature. | System description, CPU/RAM/storage, OS, operation diagram and independent data-processing proof. |
C/O note: If MFN duty is already 0%, a C/O may not further reduce import duty, but it remains useful for origin control, contract requirements, post-clearance audit or specific FTA documentation. Wrong form, origin criterion, goods description or HS code may cause rejection of preferential treatment.
APPLICABLE SPECIALIZED POLICIES
| Goods situation | Potential policy | Documents to check | Authority/portal if identifiable | Recommended timing | Risk note |
|---|---|---|---|---|---|
| Standard firewall, no wireless, no special VPN/encryption | Customs, labelling, HS-duty-C/O; still review cyber security policy by product description. | Catalogue, datasheet, invoice, packing list, original label. | Customs; market surveillance authority for circulation. | Before ETA. | Do not conclude no permit without feature list. |
| Firewall with VPN, IPsec, SSL VPN, IP flow/channel protection | May fall under civil cryptography and/or civil cryptography import permit. | Encryption documents, VPN license, admin guide, datasheet. | Government Cipher Committee / relevant public service portal. | Before purchase or at least 10–15 working days before ETA. | Missing permit may block clearance. |
| Firewall with anti-attack/intrusion, security gateway, threat prevention | May fall under cyber information security product import permit list. | IPS/IDS, anti-malware, web filtering, sandbox and threat prevention documents. | Authority responsible for cyber information security according to applicable regulations. | Before ETA. | Distinguish cyber security from civil cryptography; avoid overlapping if law excludes. |
| Firewall with Wi‑Fi/Bluetooth/4G/5G or radio module | ICT/telecom conformity and quality inspection may arise. | RF specification, frequency band, test report, radio module datasheet. | MST/CVT or relevant specialized portal depending on applicable period. | Before arrival. | Missing test report/conformity file may create pending obligations. |
| Firewall with adapter, PSU, battery or accessories | Labelling and possible electrical safety/EMC review for accessories. | Packing list, adapter datasheet, PSU label photos. | Customs/specialized authority depending on goods. | Before ETA. | Accessories may change inspection or labelling requirements. |
| Used/refurbished goods | Used IT goods restrictions or special import conditions. | Condition statement, serial photos, contract, year of manufacture. | MST/customs. | Before signing contract. | High risk if described only as “used equipment”. |
LEGAL DOCUMENTS TO REVIEW
| Document group | Document name/number | Issuing body | Effective/application time | Role in procedure | Key article/annex to review | Review note |
|---|---|---|---|---|---|---|
| Law | Customs Law 2014 | National Assembly | In force; verify at time of clearance. | Basis for customs dossier, declaration, inspection and clearance. | Rules on customs dossier, physical inspection and clearance. | Do not quote specific articles without checking the current text. |
| Law | Law on Export and Import Duties 2016 | National Assembly | In force; check amendments if any. | Basis for import duty obligations and preferential treatment. | Taxable objects, tax calculation, exemption/reduction/refund if applicable. | Check against the actual customs declaration. |
| Law | Law on Cyber Information Security No. 86/2015/QH13 | National Assembly | In force; check amendments if any. | Basis for cyber security products and civil cryptography management. | Rules on business/import of cyber security and civil cryptography products. | Security-feature firewall must be reviewed. |
| Tariff | Decree 26/2023/ND-CP | Government | Effective from 15 July 2023. | Preferential import tariff and taxable goods list. | Import tariff annex. | Re-check HS code and duty rate at declaration date. |
| Circular | Circular 29/2025/TT-BKHCN | Ministry of Science and Technology | Effective from 31 December 2025. | Group 2 ICT/telecom goods list. | Annex I, II and corresponding QCVN if applicable. | Applies when model has ICT/telecom features in scope. |
| Consolidated circular | Consolidated document 13/VBHN-BTTTT on cyber information security import permits | Ministry of Information and Communications | Check current validity and amendments. | Review import permit for cyber information security products. | List of cyber security products subject to import permit. | Firewall with anti-attack/intrusion functions must be reviewed. |
| Decree | Decree 211/2025/ND-CP | Government | Effective from 09 September 2025. | Civil cryptography activities and import/export of civil cryptography products. | Lists/conditions/permit dossier for civil cryptography. | Applies if firewall has civil cryptography functions. |
| Circular | Circular 26/2025/TT-BKHCN | Ministry of Science and Technology | Effective from 31 October 2025. | Used IT goods import restriction/conditions. | Used IT goods list. | Important for used/refurbished goods. |
| Decree | Decree 43/2017/ND-CP amended by Decree 111/2021/ND-CP | Government | Verify validity at circulation time. | Goods labelling and Vietnamese supplementary label. | Mandatory label contents, origin and responsible party. | Compare original label and Vietnamese sub-label. |
VIEW / DOWNLOAD ORIGINAL LEGAL DOCUMENTS
Enterprises may search legal documents by number on official legal document portals, the Government portal or the website of the issuing authority. Enterprises should also cross-check the document on official legal portals or the issuing authority’s website before application.
CUSTOMS CLEARANCE DOCUMENTS
Commercial documents
- Commercial Invoice.
- Packing List.
- Bill of Lading/Air Waybill.
- Sales Contract/Purchase Order if any.
- Certificate of Origin – C/O if duty preference is claimed.
- Catalogue/Datasheet/User Manual.
- Original label photos, model list, serial list and license sheet if any.
Specialized dossier if applicable
- Cyber information security import permit if the product is in scope.
- Civil cryptography import permit if the product is in scope.
- Quality inspection/conformity certification/declaration if the model is Group 2 ICT/telecom.
- Test report, technical file and self-assessment report if applicable.
- Goods labelling file and Vietnamese supplementary label.
Control principle: Product name, quantity, model, serial, origin and specifications must be fully consistent across commercial documents, catalogue, labels, specialized dossier and customs declaration.
OPERATIONAL DOCUMENT CHECKLIST
| Dossier group | Required document | Used for step | Usually prepared by | Common error | Pre-ETA check |
|---|---|---|---|---|---|
| Commercial | Invoice, Packing List, Contract/PO | Value, quantity, Incoterms | Procurement/Docs/Supplier | Generic goods name; missing model; unclear license value. | Compare each line with catalogue and PO. |
| Transport | B/L or AWB, Arrival Notice, Pre-alert | D/O, declaration, ETA monitoring | Forwarder/Docs | Wrong consignee, package/weight mismatch, missing pre-alert. | Lock transport documents before ETA. |
| Technical | Catalogue, datasheet, manual, feature/license list | HS, policy and permit review | Supplier/IT/Compliance | No VPN/encryption/security feature details. | Request supplier confirmation by model. |
| C/O | Preferential C/O if any | Preferential duty and origin file | Supplier/Procurement | Wrong form, HS, description or missing third-party invoice indication. | Review draft C/O before issuance. |
| Specialized | Cyber security/civil cryptography permit, conformity, test report if any | Clearance/circulation | Legal/Compliance/Service provider | Late after ETA, missing technical file, wrong model. | Finalize policy after receiving datasheet. |
| Labelling | Original label photos and draft Vietnamese sub-label | Clearance and local circulation | Importer/Compliance | Missing origin, model or responsible party. | Compare label with invoice, catalogue and labelling rules. |
DECISION POINTS THAT MAY HOLD THE SHIPMENT
| Decision point | Question to answer | Evidence | Consequence if unclear | Recommended handling |
|---|---|---|---|---|
| HS code | Is it a firewall appliance or another server/network device? | Datasheet, product brief, user manual | HS consultation, duty adjustment, delayed clearance. | Prepare classification rationale before declaration. |
| Cyber security/civil cryptography | Does it have VPN, encryption, anti-attack/intrusion or security gateway functions? | Feature list, license, admin guide | Missing permit or additional specialized dossier. | Review by model and apply for permit/confirmation if needed. |
| Model and license | Do documents, catalogue, label and license match? | Invoice, PL, label, order confirmation | Document amendment or customs value explanation. | Lock model list and license sheet before ETA. |
| C/O | Is the C/O form, HS, description and origin criterion correct? | C/O, invoice, packing list | Preference denial or post-clearance recovery. | Check draft C/O before official issuance. |
| New/used condition | Is it brand new, refurbished or used? | Condition statement, serial photos, contract | May trigger used IT goods restriction. | State accurate condition and review before purchase. |
| Labelling | Do original and Vietnamese labels contain mandatory information? | Label photos, sub-label draft, catalogue | Supplement request or circulation risk. | Prepare sub-label before domestic delivery. |
PRACTICAL E2E PROCESS
Finalize reference HS, duty, C/O, labelling, cyber security/civil cryptography features, goods condition and potential permits or specialized inspection.
Compare Invoice, Packing List, B/L/AWB, catalogue, datasheet, model list, serial/license list; ensure consistency of name, model, quantity and origin.
If firewall falls under cyber security, civil cryptography or Group 2 ICT/telecom, prepare permit, conformity and test report before arrival.
Declare based on supported HS. Green channel may clear under conditions; Yellow checks documents; Red checks documents and physical goods.
Release goods, deliver to warehouse, affix supplementary/conformity labels if applicable, retain shipment dossier and prepare post-clearance explanation file.
PRE-ETA RISK CHECKLIST
| Risk | Consequence | Pre-ETA control | Documents to check |
|---|---|---|---|
| Over-generic goods name | Wrong HS/policy and explanation request. | Describe as firewall appliance with model and function. | Catalogue, datasheet, invoice. |
| VPN/encryption not reviewed | Civil cryptography permit may be missing. | Ask supplier to confirm IPsec/SSL VPN/encryption. | Feature list, admin guide. |
| Cyber security not reviewed | Cyber security import permit may be missing. | Compare model/function with relevant list. | Catalogue, product matrix. |
| Wrong C/O HS/description | Preference denial or recovery. | Check draft C/O before issuance. | Draft C/O, invoice, PL. |
| Model mismatch | Channel change or document amendment request. | Lock model/serial list before ETA. | Invoice, PL, label photos. |
| Refurbished/used condition unclear | Used IT goods restriction risk. | Confirm condition before contract. | Contract, serial photos, condition statement. |
FAQ – COMMON BUSINESS QUESTIONS
It may, if the model falls under cyber information security or civil cryptography lists. Review catalogue, datasheet, feature list and import purpose first.
It may require civil cryptography review if it has IP flow/channel protection, VPN or encryption. The current technical specifications and lists must be checked.
8517.62.49 is the priority review direction under the cyber-security list for Network-based Firewall; 8517.62.99 is only a fallback where the classification file supports it. Final HS depends on actual function, structure and technical documents.
It may not reduce duty further, but it remains useful for origin file, contract requirements or post-clearance audit.
Yes, for circulation in Viet Nam, goods labelling and Vietnamese sub-label requirements should be reviewed.
Not automatically. Review condition, import purpose, value, specialized policy and re-export obligations if any.
Standardize the product description and prepare technical explanation of primary function to avoid being treated as another product group.
Tiếng Việt
中文 (中国)
NEED TO REVIEW IMPORT PROCEDURES OR A SHIPPING PLAN?
Send us the product name, shipping route, current dossier, or implementation request in advance so we can suggest a suitable approach that is practical, focused, and aligned with your shipment.
Vietnam Import Procedure for Fruit Wine: HS, Food Safety, Alcohol Stamps and 2026 Taxes
Import procedure guide for herbal alcoholic drinks
Sparkling wine import procedures into Vietnam 2026: licensing, food safety, e-stamps, taxes and origin
Import procedure guide for whisky
Import Procedures for Sake / Soju into Vietnam: HS, Food Safety, E-stamps, SCT and C/O 2026
Brandy / Cognac Import Procedures into Vietnam: HS, Alcohol Licence, Food Safety, Stamps and 2026 Taxes
Import procedure guide for energy drinks
Herbal Drink Import Procedures in Vietnam: HS, Food Safety, Self-Declaration and Labelling 2026
Bottled / Canned Coffee Import Procedure in Vietnam: HS, Food Safety, VAT and Labeling 2026
Beer Import Procedures into Vietnam: HS, Food Safety, SCT, VAT, Origin and Labelling 2026
Baijiu and distilled spirits import procedures into Vietnam 2026: HS, licensing, food safety, stamps and taxes
Guide to Vietnam import procedure for bottled/canned milk tea
Import procedures for carbonated soft drinks into Vietnam: HS, food safety, VAT, excise tax, C/O and labels
Import Procedures for Fruit Juice into Vietnam 2026
Vietnam bottled tea import procedures: HS, food safety, labeling, VAT and sugar tax