<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: checkpoint to FWSM conversion in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/checkpoint-to-fwsm-conversion/m-p/1016614#M940449</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Are you using secondary IP addresses on the Nokia?  In other words,&lt;/P&gt;&lt;P&gt;do you have multiple ip addresses on the Nokia interfaces?  If you&lt;/P&gt;&lt;P&gt;do, it will not work on the FWSM and you have create new VLAN for &lt;/P&gt;&lt;P&gt;this.  Secondary IP addresses on the Nokia works the same way as&lt;/P&gt;&lt;P&gt;Cisco IOS routers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Negate rules can be written, yes, but it is not a simple things.&lt;/P&gt;&lt;P&gt;SCT tool couldn't do it either.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Be careful with the FWSM.  If I am not mistaken, it can have &lt;/P&gt;&lt;P&gt;a maximum of 65k lines in the configuration in single-context &lt;/P&gt;&lt;P&gt;mode and 128k lines in the configuration in multiple-context mode.&lt;/P&gt;&lt;P&gt;That is NOT a whole lot when you convert from Checkpoint to FWSM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- When I mentioned 10%, I meant to say I did about 10 checkpoint&lt;/P&gt;&lt;P&gt;to Pix/ASA conversions and 1 out of 10 actually work.  The other &lt;/P&gt;&lt;P&gt;9 was a mess.  Customers were not very happy.  The Cisco Engineers&lt;/P&gt;&lt;P&gt;helping with the  project was a triple-CCIE and he could not&lt;/P&gt;&lt;P&gt;do it either.  At the end, customer decided to stay with Nokia &lt;/P&gt;&lt;P&gt;and upgraded the Nokia to the IP2260.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Last but not least, if you have a lot of interfaces on the Nokia&lt;/P&gt;&lt;P&gt;and complex rules, the harder it will get.  FWSM does NOT support&lt;/P&gt;&lt;P&gt;VPN either. You have to get a spa module for this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Good luck to you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CCIE security&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 25 Mar 2008 20:17:12 GMT</pubDate>
    <dc:creator>cisco24x7</dc:creator>
    <dc:date>2008-03-25T20:17:12Z</dc:date>
    <item>
      <title>checkpoint to FWSM conversion</title>
      <link>https://community.cisco.com/t5/network-security/checkpoint-to-fwsm-conversion/m-p/1016608#M940443</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Has anyone any experience converting from their checkpoint firewall to a brand new FWSM blade.&lt;/P&gt;&lt;P&gt;Any advice or tips would be much appreciated.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 12:21:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/checkpoint-to-fwsm-conversion/m-p/1016608#M940443</guid>
      <dc:creator>770801tvdhaar</dc:creator>
      <dc:date>2019-03-11T12:21:40Z</dc:date>
    </item>
    <item>
      <title>Re: checkpoint to FWSM conversion</title>
      <link>https://community.cisco.com/t5/network-security/checkpoint-to-fwsm-conversion/m-p/1016609#M940444</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What do you need to know?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1- Checkpoint configuration in traditional &lt;/P&gt;&lt;P&gt;or simplified mode?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2- NG, NG with AI R55 or NGx R60/R61/R62 or R65?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3- What level of HFA?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please be more specific.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CCIE Security&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Mar 2008 11:36:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/checkpoint-to-fwsm-conversion/m-p/1016609#M940444</guid>
      <dc:creator>cisco24x7</dc:creator>
      <dc:date>2008-03-25T11:36:38Z</dc:date>
    </item>
    <item>
      <title>Re: checkpoint to FWSM conversion</title>
      <link>https://community.cisco.com/t5/network-security/checkpoint-to-fwsm-conversion/m-p/1016610#M940445</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;One tip would be to get the SCT tool from Cisco that can convert your FW-1 rulebase/routing and such to a FWSM/ASA syntax, this can get you quite a bit of the way with the actual tedious work of converting between the two.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Mar 2008 12:14:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/checkpoint-to-fwsm-conversion/m-p/1016610#M940445</guid>
      <dc:creator>jan.nielsen</dc:creator>
      <dc:date>2008-03-25T12:14:51Z</dc:date>
    </item>
    <item>
      <title>Re: checkpoint to FWSM conversion</title>
      <link>https://community.cisco.com/t5/network-security/checkpoint-to-fwsm-conversion/m-p/1016611#M940446</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;1. Simplified mode&lt;/P&gt;&lt;P&gt;2.NGX R60 HFA_04, hotfix 604&lt;/P&gt;&lt;P&gt;3.Either 04 hotfix 604 if not then I'm unsure&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've started using SCT to convert the rules.&lt;/P&gt;&lt;P&gt;any other documents you can point me to before I test the conversion?&lt;/P&gt;&lt;P&gt;I will probably have more specific questions later on in the test.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Mar 2008 12:18:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/checkpoint-to-fwsm-conversion/m-p/1016611#M940446</guid>
      <dc:creator>770801tvdhaar</dc:creator>
      <dc:date>2008-03-25T12:18:38Z</dc:date>
    </item>
    <item>
      <title>Re: checkpoint to FWSM conversion</title>
      <link>https://community.cisco.com/t5/network-security/checkpoint-to-fwsm-conversion/m-p/1016612#M940447</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've done checkpoint to Pix and FWSM firewall&lt;/P&gt;&lt;P&gt;rule about 10 times in the last two years and&lt;/P&gt;&lt;P&gt;I can say that the success is about 10%.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The SCT tool is completely useless.  I've used&lt;/P&gt;&lt;P&gt;it back in 2005 when it was still in beta.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I remembered one time having to convert a checkpoint security two tier solution over&lt;/P&gt;&lt;P&gt;to Pix/ASA.  There are about 80 rules in the &lt;/P&gt;&lt;P&gt;policy with a lot of group-objects, hosts,&lt;/P&gt;&lt;P&gt;network, services, and netsted group-objects.&lt;/P&gt;&lt;P&gt;and complex natting&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I gave the checkpoint security policy to a &lt;/P&gt;&lt;P&gt;Cisco engineer to do the security conversion.&lt;/P&gt;&lt;P&gt;Two weeks later, he told me that the &lt;/P&gt;&lt;P&gt;configuration is about 450k lines long and &lt;/P&gt;&lt;P&gt;that he is only half way through the &lt;/P&gt;&lt;P&gt;checkpoint security policy.  He loaded the&lt;/P&gt;&lt;P&gt;configuration into a Pix535 and the pix could&lt;/P&gt;&lt;P&gt;not handle it either.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When doing checkpoint to Cisco conversion,&lt;/P&gt;&lt;P&gt;there are several things to keep in mind:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1- are you using secondary on the Checkpoint&lt;/P&gt;&lt;P&gt;platform such as Nokia?  If the answer is yes,&lt;/P&gt;&lt;P&gt;this is unworkable in Cisco, you will need&lt;/P&gt;&lt;P&gt;a new vlan for this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2- do you have any "negate" rules in &lt;/P&gt;&lt;P&gt;checkpoint?  If the answer is yes, this will&lt;/P&gt;&lt;P&gt;not work in Cisco,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3- do you have any "domain" object in the &lt;/P&gt;&lt;P&gt;security policy such as "mydomain.com"?  If&lt;/P&gt;&lt;P&gt;the answer is yes, it will  not work in cisco&lt;/P&gt;&lt;P&gt;either.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are a lot of things that need to be &lt;/P&gt;&lt;P&gt;planned out before the conversion can take &lt;/P&gt;&lt;P&gt;place.  When you convert from one firewall &lt;/P&gt;&lt;P&gt;platform to another one, there will be&lt;/P&gt;&lt;P&gt;architectual redesign whether you like it or&lt;/P&gt;&lt;P&gt;not.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SolSoft can help you with it but I am not sure&lt;/P&gt;&lt;P&gt;either.  When I checked out their product &lt;/P&gt;&lt;P&gt;about 1.5 years ago, it still sucks,  better&lt;/P&gt;&lt;P&gt;than Cisco SCT but still not where it should &lt;/P&gt;&lt;P&gt;be.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CCIE Security&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Mar 2008 14:26:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/checkpoint-to-fwsm-conversion/m-p/1016612#M940447</guid>
      <dc:creator>cisco24x7</dc:creator>
      <dc:date>2008-03-25T14:26:10Z</dc:date>
    </item>
    <item>
      <title>Re: checkpoint to FWSM conversion</title>
      <link>https://community.cisco.com/t5/network-security/checkpoint-to-fwsm-conversion/m-p/1016613#M940448</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank for your input, I understand you have the experience to back the talk.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'am using secondary on the Checkpoint(Nokia) as our VPN gateway, can you ellaborate on what you mean by "you gonna need a new vlan"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Negate rules can be rewritten, I have about 20 odd.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm starting to begin to realise the redesign you mentioned, I have about 250 rules to convert and the topology has to change.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just curious when you say success is about 10% is that with SCT or a full conversion?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Mar 2008 19:30:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/checkpoint-to-fwsm-conversion/m-p/1016613#M940448</guid>
      <dc:creator>770801tvdhaar</dc:creator>
      <dc:date>2008-03-25T19:30:47Z</dc:date>
    </item>
    <item>
      <title>Re: checkpoint to FWSM conversion</title>
      <link>https://community.cisco.com/t5/network-security/checkpoint-to-fwsm-conversion/m-p/1016614#M940449</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Are you using secondary IP addresses on the Nokia?  In other words,&lt;/P&gt;&lt;P&gt;do you have multiple ip addresses on the Nokia interfaces?  If you&lt;/P&gt;&lt;P&gt;do, it will not work on the FWSM and you have create new VLAN for &lt;/P&gt;&lt;P&gt;this.  Secondary IP addresses on the Nokia works the same way as&lt;/P&gt;&lt;P&gt;Cisco IOS routers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Negate rules can be written, yes, but it is not a simple things.&lt;/P&gt;&lt;P&gt;SCT tool couldn't do it either.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Be careful with the FWSM.  If I am not mistaken, it can have &lt;/P&gt;&lt;P&gt;a maximum of 65k lines in the configuration in single-context &lt;/P&gt;&lt;P&gt;mode and 128k lines in the configuration in multiple-context mode.&lt;/P&gt;&lt;P&gt;That is NOT a whole lot when you convert from Checkpoint to FWSM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- When I mentioned 10%, I meant to say I did about 10 checkpoint&lt;/P&gt;&lt;P&gt;to Pix/ASA conversions and 1 out of 10 actually work.  The other &lt;/P&gt;&lt;P&gt;9 was a mess.  Customers were not very happy.  The Cisco Engineers&lt;/P&gt;&lt;P&gt;helping with the  project was a triple-CCIE and he could not&lt;/P&gt;&lt;P&gt;do it either.  At the end, customer decided to stay with Nokia &lt;/P&gt;&lt;P&gt;and upgraded the Nokia to the IP2260.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Last but not least, if you have a lot of interfaces on the Nokia&lt;/P&gt;&lt;P&gt;and complex rules, the harder it will get.  FWSM does NOT support&lt;/P&gt;&lt;P&gt;VPN either. You have to get a spa module for this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Good luck to you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CCIE security&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Mar 2008 20:17:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/checkpoint-to-fwsm-conversion/m-p/1016614#M940449</guid>
      <dc:creator>cisco24x7</dc:creator>
      <dc:date>2008-03-25T20:17:12Z</dc:date>
    </item>
  </channel>
</rss>

