<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Migration from Cisco ASA to Checkpoint - FTP/NAS issue in SmartMove</title>
    <link>https://community.checkpoint.com/t5/SmartMove/Migration-from-Cisco-ASA-to-Checkpoint-FTP-NAS-issue/m-p/125569#M380</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;We recently migrate from Cisco ASA cluster to a new Checkpoint cluster.&lt;/P&gt;&lt;P&gt;The configuration has been converted by the Checkpoint migration tool.&lt;/P&gt;&lt;P&gt;Now we are facing few strange problem&lt;/P&gt;&lt;P&gt;Server1 to Server2 NAS flow KO&lt;/P&gt;&lt;P&gt;Server3 to Server4 FTP flow KO&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From the log I can see that the Gateway block the FTP flow that use the high-port.&lt;/P&gt;&lt;P&gt;This is strange because there isn't a rule on ASA that allow the high-port from S1 to S2.&lt;/P&gt;&lt;P&gt;More or less is the same for the NAS: the Gateway block certain port related the NAS protocol but there is no rule on ASA.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;It could be that on ASA we have to allow only the main port like ftp port and not the high port related the same flow as per implicit allow but the CP require and explicit rule for that?&lt;BR /&gt;&lt;BR /&gt;All post-migration problem are related a flow that start with a specific port and continue with other port like FTP&lt;BR /&gt;&lt;BR /&gt;Regards&lt;/P&gt;</description>
    <pubDate>Tue, 03 Aug 2021 09:28:55 GMT</pubDate>
    <dc:creator>charlie</dc:creator>
    <dc:date>2021-08-03T09:28:55Z</dc:date>
    <item>
      <title>Migration from Cisco ASA to Checkpoint - FTP/NAS issue</title>
      <link>https://community.checkpoint.com/t5/SmartMove/Migration-from-Cisco-ASA-to-Checkpoint-FTP-NAS-issue/m-p/125569#M380</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;We recently migrate from Cisco ASA cluster to a new Checkpoint cluster.&lt;/P&gt;&lt;P&gt;The configuration has been converted by the Checkpoint migration tool.&lt;/P&gt;&lt;P&gt;Now we are facing few strange problem&lt;/P&gt;&lt;P&gt;Server1 to Server2 NAS flow KO&lt;/P&gt;&lt;P&gt;Server3 to Server4 FTP flow KO&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From the log I can see that the Gateway block the FTP flow that use the high-port.&lt;/P&gt;&lt;P&gt;This is strange because there isn't a rule on ASA that allow the high-port from S1 to S2.&lt;/P&gt;&lt;P&gt;More or less is the same for the NAS: the Gateway block certain port related the NAS protocol but there is no rule on ASA.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;It could be that on ASA we have to allow only the main port like ftp port and not the high port related the same flow as per implicit allow but the CP require and explicit rule for that?&lt;BR /&gt;&lt;BR /&gt;All post-migration problem are related a flow that start with a specific port and continue with other port like FTP&lt;BR /&gt;&lt;BR /&gt;Regards&lt;/P&gt;</description>
      <pubDate>Tue, 03 Aug 2021 09:28:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SmartMove/Migration-from-Cisco-ASA-to-Checkpoint-FTP-NAS-issue/m-p/125569#M380</guid>
      <dc:creator>charlie</dc:creator>
      <dc:date>2021-08-03T09:28:55Z</dc:date>
    </item>
    <item>
      <title>Re: Migration from Cisco ASA to Checkpoint - FTP/NAS issue</title>
      <link>https://community.checkpoint.com/t5/SmartMove/Migration-from-Cisco-ASA-to-Checkpoint-FTP-NAS-issue/m-p/125573#M381</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;It could be that FTP is related to passive / active mode ;&lt;/P&gt;
&lt;P&gt;please check the traffic and adjust as needed .&lt;/P&gt;
&lt;P&gt;- You can find the file :&amp;nbsp;CiscoNameToNumber.csv - it will map ftp service to port 21.&lt;/P&gt;
&lt;P&gt;- CP_KnownTcpPorts.csv will map port 21 to Check Point FTP service.&lt;/P&gt;
&lt;P&gt;There is no&amp;nbsp;&lt;SPAN&gt;NAS service with SmartMove - which port are you referring&amp;nbsp;to ?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I also cannot find it with Iana :&amp;nbsp;&lt;A href="https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml" target="_blank"&gt;https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Did you had any errors ,warnings with the file ? you can view it form the results html file.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;P.S:&lt;/P&gt;
&lt;P&gt;You can ping me offline : &lt;A href="mailto:sc@checkpoint.com" target="_blank"&gt;sc@checkpoint.com&lt;/A&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Aug 2021 10:00:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SmartMove/Migration-from-Cisco-ASA-to-Checkpoint-FTP-NAS-issue/m-p/125573#M381</guid>
      <dc:creator>Ofir_Shikolski</dc:creator>
      <dc:date>2021-08-03T10:00:23Z</dc:date>
    </item>
  </channel>
</rss>

