<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Firewall migration assistance in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firewall-migration-assistance/m-p/913683#M956437</link>
    <description>&lt;P&gt;I have a customer running Checkpoint  NGx R60 firewall &lt;/P&gt;&lt;P&gt;on a pair of Nokia IP2260.  The management server is &lt;/P&gt;&lt;P&gt;a RedLinux 3 ES.  I've provided this customer over&lt;/P&gt;&lt;P&gt;the year with tech. support.  This firewall has 20 &lt;/P&gt;&lt;P&gt;interfaces and about 1000 rules with over 30000 objects.&lt;/P&gt;&lt;P&gt;we are also running OSPF and BGP on the Nokia.  There&lt;/P&gt;&lt;P&gt;are 45 site-2-site VPNs on the firewalls with double&lt;/P&gt;&lt;P&gt;NAT between this site and customers' site.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I use comercial tools and freeware to monitor the&lt;/P&gt;&lt;P&gt;firewall security.  In other words, if someone&lt;/P&gt;&lt;P&gt;push policy to the firewall, I get alerts.  The&lt;/P&gt;&lt;P&gt;security policy is can also be exported in XML or&lt;/P&gt;&lt;P&gt;HTML so that it can be viewed. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now the customer wants to migrate to a pair of &lt;/P&gt;&lt;P&gt;ASA 5540 platform.  I am looking for a tool that&lt;/P&gt;&lt;P&gt;can convert checkpoint rules to Pix rule. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone know if there is such a tool out there&lt;/P&gt;&lt;P&gt;that can do the job?  I can imagine the ASA&lt;/P&gt;&lt;P&gt;configuration will be at least 800,000 lines&lt;/P&gt;&lt;P&gt;of configuration.  Can the ASA hand the configuration file&lt;/P&gt;&lt;P&gt;that large?  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 11:53:08 GMT</pubDate>
    <dc:creator>cisco24x7</dc:creator>
    <dc:date>2019-03-11T11:53:08Z</dc:date>
    <item>
      <title>Firewall migration assistance</title>
      <link>https://community.cisco.com/t5/network-security/firewall-migration-assistance/m-p/913683#M956437</link>
      <description>&lt;P&gt;I have a customer running Checkpoint  NGx R60 firewall &lt;/P&gt;&lt;P&gt;on a pair of Nokia IP2260.  The management server is &lt;/P&gt;&lt;P&gt;a RedLinux 3 ES.  I've provided this customer over&lt;/P&gt;&lt;P&gt;the year with tech. support.  This firewall has 20 &lt;/P&gt;&lt;P&gt;interfaces and about 1000 rules with over 30000 objects.&lt;/P&gt;&lt;P&gt;we are also running OSPF and BGP on the Nokia.  There&lt;/P&gt;&lt;P&gt;are 45 site-2-site VPNs on the firewalls with double&lt;/P&gt;&lt;P&gt;NAT between this site and customers' site.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I use comercial tools and freeware to monitor the&lt;/P&gt;&lt;P&gt;firewall security.  In other words, if someone&lt;/P&gt;&lt;P&gt;push policy to the firewall, I get alerts.  The&lt;/P&gt;&lt;P&gt;security policy is can also be exported in XML or&lt;/P&gt;&lt;P&gt;HTML so that it can be viewed. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now the customer wants to migrate to a pair of &lt;/P&gt;&lt;P&gt;ASA 5540 platform.  I am looking for a tool that&lt;/P&gt;&lt;P&gt;can convert checkpoint rules to Pix rule. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone know if there is such a tool out there&lt;/P&gt;&lt;P&gt;that can do the job?  I can imagine the ASA&lt;/P&gt;&lt;P&gt;configuration will be at least 800,000 lines&lt;/P&gt;&lt;P&gt;of configuration.  Can the ASA hand the configuration file&lt;/P&gt;&lt;P&gt;that large?  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 11:53:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-migration-assistance/m-p/913683#M956437</guid>
      <dc:creator>cisco24x7</dc:creator>
      <dc:date>2019-03-11T11:53:08Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall migration assistance</title>
      <link>https://community.cisco.com/t5/network-security/firewall-migration-assistance/m-p/913684#M956438</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I saw this link long time ago and saved it for reference,  I have not used it so I cannot provide feedback  but the link may provide you with very usefull information and a start.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Checkpoint NG to ASA/FWSM&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://cisco.com/cgi-bin/tablebuild.pl/sct" target="_blank"&gt;http://cisco.com/cgi-bin/tablebuild.pl/sct&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds&lt;/P&gt;&lt;P&gt;Jorge&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Jan 2008 21:31:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-migration-assistance/m-p/913684#M956438</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2008-01-24T21:31:50Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall migration assistance</title>
      <link>https://community.cisco.com/t5/network-security/firewall-migration-assistance/m-p/913685#M956439</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I used this tool two years ago and it is a&lt;/P&gt;&lt;P&gt;horrible tool.  The conversion was a mess&lt;/P&gt;&lt;P&gt;and that about 99.9% of the information is &lt;/P&gt;&lt;P&gt;totally useless.  This tool could not &lt;/P&gt;&lt;P&gt;convert NAT rules.  The policy I tried&lt;/P&gt;&lt;P&gt;to convert at the time was not a difficult&lt;/P&gt;&lt;P&gt;one but this tool could not do the job.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am looking for a better tool.  I am sure&lt;/P&gt;&lt;P&gt;there will be many more customers that will&lt;/P&gt;&lt;P&gt;be converting from Checkpoint to ASA in the&lt;/P&gt;&lt;P&gt;future.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Jan 2008 21:42:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-migration-assistance/m-p/913685#M956439</guid>
      <dc:creator>cisco24x7</dc:creator>
      <dc:date>2008-01-24T21:42:52Z</dc:date>
    </item>
  </channel>
</rss>

