cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
645
Views
0
Helpful
5
Replies

Juniper to Cisco ASA

Hey, 

 

can Anyone Guide me for Juniper to Cisco ASA 

 

 

Thanks

5 Replies 5

Ji-Won Park
Level 1
Level 1

Hi,

FW migration is tough, that's why lots of companies engage third party to provide PS.

You have to look into lots of features of the firewall - I personally never did Juniper to ASA, but have done Fortinet, Palo Alto, ASA, Checkpoint.

 

1. Interfaces & Routing

2. objects & NAT

3. VPN (site-to-site & remote)

4. Additional Features

 

You have to start with internet functionality which is related to your interfaces, routing, objects, and NAT. Once you finish doing those, you can start VPN configuration and testing. I normally prepare one L3 switch to simulate inside and outside of the network so you can actually simulate VPN connectivity including remote access. Once you finish VPN, you get into additional features that are specialized in different vendors. At this moment, you would be looking at FirePOWER service with ASA to provide NGFW functionality (URL, Malware, IPS).

 

Hope it helps.

g1

Thanks JI won park ,

 

I think in fw migration , NAT and policies are very happy important, in my case juniper config is totally different, so what are the best practices for successful migration?

Configuration is different across all different vendors. The best practice is to follow the guideline I provided.

g1

Hello,

 

As mentioned by Ji Won Park the configuration is way different on both units.

 

My recommendation is to start moving the interface configuration (IP address information).

 

Once you have IP reachability work in the ACLs (This would be the Security Policies on the Juniper Side).

 

Last you can work on the NAT and if any VPN configuration.

 

You can leave the Specific Application Inspection Engine configuration for later as their way of working is way different.

 

Regards

Julio Carvajal
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC

if you have configuration i will translate it to cisco 

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card