<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Netscreen to ASA - Quick Look in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/netscreen-to-asa-quick-look/m-p/951624#M919320</link>
    <description>&lt;P&gt;Hey guys, I have attached a brief config from a NetScreen. This needs to be adapted to a new Cisco ASA. Wondering if one of you experts can take a quick look &amp;amp; provide guidance on any config converter tools and/or know if this can be simply translated. Thanks in advance for all responses! &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Matt&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 12:52:08 GMT</pubDate>
    <dc:creator>matthew.scala</dc:creator>
    <dc:date>2019-03-11T12:52:08Z</dc:date>
    <item>
      <title>Netscreen to ASA - Quick Look</title>
      <link>https://community.cisco.com/t5/network-security/netscreen-to-asa-quick-look/m-p/951624#M919320</link>
      <description>&lt;P&gt;Hey guys, I have attached a brief config from a NetScreen. This needs to be adapted to a new Cisco ASA. Wondering if one of you experts can take a quick look &amp;amp; provide guidance on any config converter tools and/or know if this can be simply translated. Thanks in advance for all responses! &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Matt&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 12:52:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/netscreen-to-asa-quick-look/m-p/951624#M919320</guid>
      <dc:creator>matthew.scala</dc:creator>
      <dc:date>2019-03-11T12:52:08Z</dc:date>
    </item>
    <item>
      <title>Re: Netscreen to ASA - Quick Look</title>
      <link>https://community.cisco.com/t5/network-security/netscreen-to-asa-quick-look/m-p/951625#M919321</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Looks pretty straight forward. I don't know of any tools (maybe I should write one) that converts the config. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;MIPS are equivalent to statics in an ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;B&gt;Netscreen&lt;/B&gt;&lt;/P&gt;&lt;P&gt;set interface "ethernet4" mip xxx.x.23.52 host 192.68.123.27 netmask 255.255.255.255 vr "trust-vr"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;B&gt;Cisco ASA&lt;/B&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) xxx.x.23.52 192.68.123.27 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ACLs &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;B&gt;Netscreen&lt;/B&gt;&lt;/P&gt;&lt;P&gt;set policy id 73 from "Untrust" to "Trust"  "Any" "MIP(xxx.x.23.35)" "WebServer Service Grp" permit log count &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;B&gt;Cisco ASA&lt;/B&gt;&lt;/P&gt;&lt;P&gt;access-list outside_in extended permit tcp any host xxx.x.23.35 object-group WebServer_ Service_Grp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Grouping ports &amp;amp; protocols &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;B&gt;Netscreen&lt;/B&gt;&lt;/P&gt;&lt;P&gt;set group service "WebServer Service Grp"&lt;/P&gt;&lt;P&gt;set group service "WebServer Service Grp" add "HTTP"&lt;/P&gt;&lt;P&gt;set group service "WebServer Service Grp" add "HTTPS"&lt;/P&gt;&lt;P&gt;set group service "WebServer Service Grp" add "PING"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;B&gt;Cisco ASA&lt;/B&gt;&lt;/P&gt;&lt;P&gt;object-group service WebServer_Service_Grp tcp&lt;/P&gt;&lt;P&gt; port-object eq www&lt;/P&gt;&lt;P&gt; port-object eq https&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note that with object groups, you can only have TCP or UDP in a group. I'm pretty sure you can nest groups though.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 May 2008 12:45:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/netscreen-to-asa-quick-look/m-p/951625#M919321</guid>
      <dc:creator>Collin Clark</dc:creator>
      <dc:date>2008-05-30T12:45:12Z</dc:date>
    </item>
  </channel>
</rss>

