<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Huawei Firewall to Check Point MIgration Script in Scripts</title>
    <link>https://community.checkpoint.com/t5/Scripts/Huawei-Firewall-to-Check-Point-MIgration-Script/m-p/283432#M1567</link>
    <description>&lt;P dir="ltr"&gt;Hi CheckMates,&lt;/P&gt;
&lt;P dir="ltr"&gt;I recently migrated a Huawei firewall cluster to a Check Point 9700 cluster, with the security policy going into an MDS domain. Based on a similar script I had built for a Forcepoint migration, I created a Python script that reads the Huawei .cfg file and converts it into Check Point formats, because smartmove dont convert this types. It converted more than 120 rules and all network and service objects accurately, which sped up the migration a lot. I only needed to review the result. I expect that helps someone in future:&amp;nbsp;&lt;/P&gt;
&lt;P dir="ltr"&gt;&lt;STRONG&gt;What it generates&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL dir="ltr"&gt;
&lt;LI&gt;CSV files for mgmt_cli: hosts, networks, ranges, DNS domains, groups, services, service groups and access rules&lt;/LI&gt;
&lt;LI&gt;&lt;CODE dir="ltr"&gt;nat-rules.txt&lt;/CODE&gt;: NAT rules in SmartConsole CLI format&lt;/LI&gt;
&lt;LI&gt;&lt;CODE dir="ltr"&gt;gaia_clish_preconfig.txt&lt;/CODE&gt;: Gaia clish draft (hostname, DNS, NTP, SNMP, interfaces, bonds, proxy ARP, static routes), to apply manually on the gateway via serial or SSH&lt;/LI&gt;
&lt;LI&gt;&lt;CODE dir="ltr"&gt;import_commands.txt&lt;/CODE&gt;: the mgmt_cli commands in the correct order, for SMS and MDS&lt;/LI&gt;
&lt;LI&gt;&lt;CODE dir="ltr"&gt;pending_review.txt&lt;/CODE&gt;: items that need manual review&lt;/LI&gt;
&lt;/UL&gt;
&lt;P dir="ltr"&gt;&lt;STRONG&gt;How to use&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL dir="ltr"&gt;
&lt;LI&gt;Run &lt;CODE dir="ltr"&gt;python huawei_to_checkpoint.py&lt;/CODE&gt; (Python 3.6+, no external libraries). Use &lt;CODE dir="ltr"&gt;--help&lt;/CODE&gt; for full instructions.&lt;/LI&gt;
&lt;LI&gt;Copy the files with WinSCP to the SMS, or to the MDS itself for a domain.&lt;/LI&gt;
&lt;LI&gt;In Expert mode, inside the files folder, run the commands from &lt;CODE dir="ltr"&gt;import_commands.txt&lt;/CODE&gt;:&lt;BR /&gt;&lt;BR /&gt;&lt;CODE&gt;# SMS
&lt;BR /&gt;mgmt_cli add host --ignore-errors true -b host.csv
&lt;BR /&gt;&lt;BR /&gt;
# MDS domain
&lt;BR /&gt;mgmt_cli -r true add host --ignore-errors true -b host.csv -d &amp;lt;DOMAIN-IP&amp;gt;&lt;/CODE&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;OL dir="ltr" start="4"&gt;
&lt;LI&gt;Paste &lt;CODE dir="ltr"&gt;nat-rules.txt&lt;/CODE&gt; in SmartConsole &amp;gt; Scripting and publish. On MDS, use the domain's policy package name.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P dir="ltr"&gt;&lt;STRONG&gt;Notes&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL dir="ltr"&gt;
&lt;LI&gt;Rules marked &lt;CODE dir="ltr"&gt;[REVIEW]&lt;/CODE&gt; are imported disabled for checking.&lt;/LI&gt;
&lt;LI&gt;Move the default Cleanup rule to the end of the layer after the import.&lt;/LI&gt;
&lt;LI&gt;VPN, TACACS, admin users and ClusterXL must be configured manually.&lt;/LI&gt;
&lt;LI&gt;Test in a lab first and review everything before installing on production.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P dir="ltr"&gt;Best Regards&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="exemplo-execucao-do-script.png" style="width: 786px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/35506i3DDD2464879D0D03/image-size/large?v=v2&amp;amp;px=999" role="button" title="exemplo-execucao-do-script.png" alt="exemplo-execucao-do-script.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;Example of generated files:&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="imagem - 2026-10-08T175525.912.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/35507i1ABC076F881459B7/image-size/large?v=v2&amp;amp;px=999" role="button" title="imagem - 2026-10-08T175525.912.png" alt="imagem - 2026-10-08T175525.912.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 09 Oct 2026 08:38:51 GMT</pubDate>
    <dc:creator>israelfds95</dc:creator>
    <dc:date>2026-10-09T08:38:51Z</dc:date>
    <item>
      <title>Huawei Firewall to Check Point MIgration Script</title>
      <link>https://community.checkpoint.com/t5/Scripts/Huawei-Firewall-to-Check-Point-MIgration-Script/m-p/283432#M1567</link>
      <description>&lt;P dir="ltr"&gt;Hi CheckMates,&lt;/P&gt;
&lt;P dir="ltr"&gt;I recently migrated a Huawei firewall cluster to a Check Point 9700 cluster, with the security policy going into an MDS domain. Based on a similar script I had built for a Forcepoint migration, I created a Python script that reads the Huawei .cfg file and converts it into Check Point formats, because smartmove dont convert this types. It converted more than 120 rules and all network and service objects accurately, which sped up the migration a lot. I only needed to review the result. I expect that helps someone in future:&amp;nbsp;&lt;/P&gt;
&lt;P dir="ltr"&gt;&lt;STRONG&gt;What it generates&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL dir="ltr"&gt;
&lt;LI&gt;CSV files for mgmt_cli: hosts, networks, ranges, DNS domains, groups, services, service groups and access rules&lt;/LI&gt;
&lt;LI&gt;&lt;CODE dir="ltr"&gt;nat-rules.txt&lt;/CODE&gt;: NAT rules in SmartConsole CLI format&lt;/LI&gt;
&lt;LI&gt;&lt;CODE dir="ltr"&gt;gaia_clish_preconfig.txt&lt;/CODE&gt;: Gaia clish draft (hostname, DNS, NTP, SNMP, interfaces, bonds, proxy ARP, static routes), to apply manually on the gateway via serial or SSH&lt;/LI&gt;
&lt;LI&gt;&lt;CODE dir="ltr"&gt;import_commands.txt&lt;/CODE&gt;: the mgmt_cli commands in the correct order, for SMS and MDS&lt;/LI&gt;
&lt;LI&gt;&lt;CODE dir="ltr"&gt;pending_review.txt&lt;/CODE&gt;: items that need manual review&lt;/LI&gt;
&lt;/UL&gt;
&lt;P dir="ltr"&gt;&lt;STRONG&gt;How to use&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL dir="ltr"&gt;
&lt;LI&gt;Run &lt;CODE dir="ltr"&gt;python huawei_to_checkpoint.py&lt;/CODE&gt; (Python 3.6+, no external libraries). Use &lt;CODE dir="ltr"&gt;--help&lt;/CODE&gt; for full instructions.&lt;/LI&gt;
&lt;LI&gt;Copy the files with WinSCP to the SMS, or to the MDS itself for a domain.&lt;/LI&gt;
&lt;LI&gt;In Expert mode, inside the files folder, run the commands from &lt;CODE dir="ltr"&gt;import_commands.txt&lt;/CODE&gt;:&lt;BR /&gt;&lt;BR /&gt;&lt;CODE&gt;# SMS
&lt;BR /&gt;mgmt_cli add host --ignore-errors true -b host.csv
&lt;BR /&gt;&lt;BR /&gt;
# MDS domain
&lt;BR /&gt;mgmt_cli -r true add host --ignore-errors true -b host.csv -d &amp;lt;DOMAIN-IP&amp;gt;&lt;/CODE&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;OL dir="ltr" start="4"&gt;
&lt;LI&gt;Paste &lt;CODE dir="ltr"&gt;nat-rules.txt&lt;/CODE&gt; in SmartConsole &amp;gt; Scripting and publish. On MDS, use the domain's policy package name.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P dir="ltr"&gt;&lt;STRONG&gt;Notes&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL dir="ltr"&gt;
&lt;LI&gt;Rules marked &lt;CODE dir="ltr"&gt;[REVIEW]&lt;/CODE&gt; are imported disabled for checking.&lt;/LI&gt;
&lt;LI&gt;Move the default Cleanup rule to the end of the layer after the import.&lt;/LI&gt;
&lt;LI&gt;VPN, TACACS, admin users and ClusterXL must be configured manually.&lt;/LI&gt;
&lt;LI&gt;Test in a lab first and review everything before installing on production.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P dir="ltr"&gt;Best Regards&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="exemplo-execucao-do-script.png" style="width: 786px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/35506i3DDD2464879D0D03/image-size/large?v=v2&amp;amp;px=999" role="button" title="exemplo-execucao-do-script.png" alt="exemplo-execucao-do-script.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;Example of generated files:&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="imagem - 2026-10-08T175525.912.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/35507i1ABC076F881459B7/image-size/large?v=v2&amp;amp;px=999" role="button" title="imagem - 2026-10-08T175525.912.png" alt="imagem - 2026-10-08T175525.912.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Oct 2026 08:38:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Scripts/Huawei-Firewall-to-Check-Point-MIgration-Script/m-p/283432#M1567</guid>
      <dc:creator>israelfds95</dc:creator>
      <dc:date>2026-10-09T08:38:51Z</dc:date>
    </item>
    <item>
      <title>Re: Huawei Firewall to Check Point MIgration Script</title>
      <link>https://community.checkpoint.com/t5/Scripts/Huawei-Firewall-to-Check-Point-MIgration-Script/m-p/283460#M1568</link>
      <description>&lt;P&gt;Nicely done!&lt;/P&gt;</description>
      <pubDate>Fri, 09 Oct 2026 15:12:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Scripts/Huawei-Firewall-to-Check-Point-MIgration-Script/m-p/283460#M1568</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2026-10-09T15:12:49Z</dc:date>
    </item>
  </channel>
</rss>

