<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SmartMove from Juniper with LSYS in SmartMove</title>
    <link>https://community.checkpoint.com/t5/SmartMove/SmartMove-from-Juniper-with-LSYS/m-p/265790#M676</link>
    <description>&lt;P&gt;Thanks.&lt;BR /&gt;Now i am playing around and testing the mgmt_cli outout and this is challenging as we have MDM and its bit more complex thant to create everything without domains &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 19 Dec 2025 12:37:24 GMT</pubDate>
    <dc:creator>Vincent_Bacher</dc:creator>
    <dc:date>2025-12-19T12:37:24Z</dc:date>
    <item>
      <title>SmartMove from Juniper with LSYS</title>
      <link>https://community.checkpoint.com/t5/SmartMove/SmartMove-from-Juniper-with-LSYS/m-p/265422#M601</link>
      <description>&lt;P&gt;Hey,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to migrate from a Juniper with logical systems to Check Point VSX. I know I can't count on SmartMove to do everything for me, but I would want it to at least help me move the 1000+ policies &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; Any idea how to do it? When I exported the whole xml file off the Juniper and put it into SmartMove I only got the policies from the root logical system. Exporting the logical system itself didn't work either. At this point doesn't even matter if it puts everything in one policy, or does separate ones, as long as I get the rules and objects on the SMS. Any advice would be appreciated.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Dec 2025 13:38:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SmartMove/SmartMove-from-Juniper-with-LSYS/m-p/265422#M601</guid>
      <dc:creator>robertp</dc:creator>
      <dc:date>2025-12-16T13:38:07Z</dc:date>
    </item>
    <item>
      <title>Re: SmartMove from Juniper with LSYS</title>
      <link>https://community.checkpoint.com/t5/SmartMove/SmartMove-from-Juniper-with-LSYS/m-p/265424#M602</link>
      <description>&lt;P&gt;Not sure if you are allowed to send the file, but I would be happy to try it in the lab and see if I can make it work. I did this with Fortigate, Cisco, PAN, always worked fine.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Dec 2025 13:41:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SmartMove/SmartMove-from-Juniper-with-LSYS/m-p/265424#M602</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-12-16T13:41:48Z</dc:date>
    </item>
    <item>
      <title>Re: SmartMove from Juniper with LSYS</title>
      <link>https://community.checkpoint.com/t5/SmartMove/SmartMove-from-Juniper-with-LSYS/m-p/265426#M603</link>
      <description>&lt;P&gt;I built R82 latest jumbo 44 mgmt server, so if you are allowed/willing to send the Juniper config file, Im happy to give it a go.&lt;/P&gt;
&lt;P&gt;Cheers.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Dec 2025 14:21:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SmartMove/SmartMove-from-Juniper-with-LSYS/m-p/265426#M603</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-12-16T14:21:14Z</dc:date>
    </item>
    <item>
      <title>Re: SmartMove from Juniper with LSYS</title>
      <link>https://community.checkpoint.com/t5/SmartMove/SmartMove-from-Juniper-with-LSYS/m-p/265428#M604</link>
      <description>&lt;P&gt;Hi, I am not, but I'm deploying two logical systems on a test SRX I have, I will add a few policies, check if it gives me the same output as the production one, and if it does I will send that one over. Any potential fix should be valid for the production boxes also. Not sure if I will make it today due to some other tasks but I'll keep in touch max tomorrow. Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 16 Dec 2025 14:34:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SmartMove/SmartMove-from-Juniper-with-LSYS/m-p/265428#M604</guid>
      <dc:creator>robertp</dc:creator>
      <dc:date>2025-12-16T14:34:09Z</dc:date>
    </item>
    <item>
      <title>Re: SmartMove from Juniper with LSYS</title>
      <link>https://community.checkpoint.com/t5/SmartMove/SmartMove-from-Juniper-with-LSYS/m-p/265437#M605</link>
      <description>&lt;P&gt;No worries...lab test mgmt is ready on my end.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Dec 2025 15:11:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SmartMove/SmartMove-from-Juniper-with-LSYS/m-p/265437#M605</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-12-16T15:11:27Z</dc:date>
    </item>
    <item>
      <title>Re: SmartMove from Juniper with LSYS</title>
      <link>https://community.checkpoint.com/t5/SmartMove/SmartMove-from-Juniper-with-LSYS/m-p/265445#M606</link>
      <description>&lt;P&gt;First of all, I would like to congratulate you on your decision to leave SRX. No matter where you go, anywhere is better than SRX. Except for Cisco FTD. I speak from experience.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Anyway, I read this in the sk for SmartMove&lt;BR /&gt;“Multi routing instance configuration - only single routing instance is supported”&lt;BR /&gt;I assume they mean lsys. However, I can't find anywhere in the sk how to deal with multi lsys.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Dec 2025 15:42:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SmartMove/SmartMove-from-Juniper-with-LSYS/m-p/265445#M606</guid>
      <dc:creator>Vincent_Bacher</dc:creator>
      <dc:date>2025-12-16T15:42:55Z</dc:date>
    </item>
    <item>
      <title>Re: SmartMove from Juniper with LSYS</title>
      <link>https://community.checkpoint.com/t5/SmartMove/SmartMove-from-Juniper-with-LSYS/m-p/265470#M607</link>
      <description>&lt;P&gt;I only worked once with SRX, was challenging, to say the least. As far as Cisco FTD, while back, not recently, so not sure how much it changed.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Dec 2025 20:50:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SmartMove/SmartMove-from-Juniper-with-LSYS/m-p/265470#M607</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-12-16T20:50:51Z</dc:date>
    </item>
    <item>
      <title>Re: SmartMove from Juniper with LSYS</title>
      <link>https://community.checkpoint.com/t5/SmartMove/SmartMove-from-Juniper-with-LSYS/m-p/265481#M608</link>
      <description>&lt;P&gt;To be honest, I've had a bad experience with SRX and FTD.&lt;BR /&gt;We once lost a lucrative customer, a bank, because of Juniper and SRX.&lt;BR /&gt;We had only recently acquired the customer and, at their request, migrated an important cluster to SRX. Then an upgrade was due, and during the change we had a split brain situation. Even the Juniper experts present couldn't find the cause at first. Until a colleague of mine found out in a user group that the behaviour of sync traffic in VLAN had changed with the new release and how to revert it. But that was still enough for the customer to kick us out.&lt;BR /&gt;As for FTD, we once set up a two-tier DMZ environment. Checkpoint on the inside and FTD on the outside. Again, after an FTD upgrade, every few days the FTD cluster decided to reject all DNS requests to the outside. The only workaround until a patch version was delivered was to reboot the nodes. Simultaneously.&lt;BR /&gt;Since these incidents, I have not wanted to have anything to do with either of them.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Dec 2025 22:57:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SmartMove/SmartMove-from-Juniper-with-LSYS/m-p/265481#M608</guid>
      <dc:creator>Vincent_Bacher</dc:creator>
      <dc:date>2025-12-16T22:57:41Z</dc:date>
    </item>
    <item>
      <title>Re: SmartMove from Juniper with LSYS</title>
      <link>https://community.checkpoint.com/t5/SmartMove/SmartMove-from-Juniper-with-LSYS/m-p/265482#M609</link>
      <description>&lt;P&gt;Im never gonna forget the call I had once with Cisco support guy about FTD when it was somewhat new and I could tell even he was not familiar with it, so I genuinly felt bad, but you know how it goes when we have to help our own clients.&lt;/P&gt;
&lt;P&gt;Anyway, after some time, I could tell we were not going anywhere and I asked him if he could maybe escalate the case and he says to me ( NOT paraphrasing) "You know Mr Andy, I will be 100% honest with you, I can escalate this case, but next engineer will probably know less than me about this"&lt;/P&gt;
&lt;P&gt;Gave me good laugh LOL&lt;/P&gt;</description>
      <pubDate>Tue, 16 Dec 2025 23:03:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SmartMove/SmartMove-from-Juniper-with-LSYS/m-p/265482#M609</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-12-16T23:03:42Z</dc:date>
    </item>
    <item>
      <title>Re: SmartMove from Juniper with LSYS</title>
      <link>https://community.checkpoint.com/t5/SmartMove/SmartMove-from-Juniper-with-LSYS/m-p/265483#M610</link>
      <description>&lt;P&gt;Yes I know well the issue to have to support the customers but now I am at the customer side.&lt;/P&gt;
&lt;P&gt;An I as well had times where I frequently had to fight with tac to get an engineer that was not less experienced and qualified than myself. But I will not name the vendor&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Dec 2025 23:15:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SmartMove/SmartMove-from-Juniper-with-LSYS/m-p/265483#M610</guid>
      <dc:creator>Vincent_Bacher</dc:creator>
      <dc:date>2025-12-16T23:15:26Z</dc:date>
    </item>
    <item>
      <title>Re: SmartMove from Juniper with LSYS</title>
      <link>https://community.checkpoint.com/t5/SmartMove/SmartMove-from-Juniper-with-LSYS/m-p/265484#M611</link>
      <description>&lt;P&gt;Truth be told, it could happen with any vendor, specially when there is lots of pressure to fix the problem right over the phone. I recall once with Cisco, lady was so persistent wanting to fix the problem, I had to tell her 10 times I was going to miss the flight to Bora Bora if we go over 6 pm lol&lt;/P&gt;
&lt;P&gt;Anyway, we all know how stressfull IT world can be...&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/107375"&gt;@robertp&lt;/a&gt;&amp;nbsp;If you are allowed to send any config files, I got time Wednesday to try and see if import works via smartmove tool.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Dec 2025 23:22:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SmartMove/SmartMove-from-Juniper-with-LSYS/m-p/265484#M611</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-12-16T23:22:08Z</dc:date>
    </item>
    <item>
      <title>Re: SmartMove from Juniper with LSYS</title>
      <link>https://community.checkpoint.com/t5/SmartMove/SmartMove-from-Juniper-with-LSYS/m-p/265507#M612</link>
      <description>&lt;P&gt;Hey, sorry for the delay. Attaching an xml from a test firewall I configured. The firewall looks like this:&lt;/P&gt;&lt;P&gt;root logical system:&lt;/P&gt;&lt;P&gt;1 zone-to-zone policy&lt;/P&gt;&lt;P&gt;1 global deny policy&lt;/P&gt;&lt;P&gt;two logical systems (WAN and WWW) each have the same policies:&lt;/P&gt;&lt;P&gt;2 zone-to-zone policies and 1 global policy&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When using smartmove I get the zone-to-zone policy from root and a lot of deny rules ( I guess some are the implied rules that Juniper has by default). The result is exactly the same as for the production firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Reg the comments about vendors - SRX is a good L3 firewall, more stable and easier to configure than any other I worked on. It is definitely not a next-gen firewall, even though the vendor says so. As we all know - every vendor has it's problems. I don't even want to start talking about various TAC engagements (for any vendor) as I want to keep it civilized &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I proposed a migration from the SRX to CP to the customer and honestly it has been one large headache till now. The outcome might be worth it in the end but not yet... If the smartmove tool doesn't work it will be yet another delay (possibly a large one now as someone will have to go and rewrite the policies by hand).&lt;/P&gt;</description>
      <pubDate>Wed, 17 Dec 2025 13:53:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SmartMove/SmartMove-from-Juniper-with-LSYS/m-p/265507#M612</guid>
      <dc:creator>robertp</dc:creator>
      <dc:date>2025-12-17T13:53:19Z</dc:date>
    </item>
    <item>
      <title>Re: SmartMove from Juniper with LSYS</title>
      <link>https://community.checkpoint.com/t5/SmartMove/SmartMove-from-Juniper-with-LSYS/m-p/265509#M613</link>
      <description>&lt;P&gt;Thank you! Give me some time, as I have large Fortigate -&amp;gt; CP cutover tomorrow, so that takes priority. But, I will definitely give this a go today and update you.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Dec 2025 13:57:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SmartMove/SmartMove-from-Juniper-with-LSYS/m-p/265509#M613</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-12-17T13:57:28Z</dc:date>
    </item>
    <item>
      <title>Re: SmartMove from Juniper with LSYS</title>
      <link>https://community.checkpoint.com/t5/SmartMove/SmartMove-from-Juniper-with-LSYS/m-p/265514#M614</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/107375"&gt;@robertp&lt;/a&gt;&amp;nbsp;Just realized I got an hour to spare, so let me try this now. Otherwise, will continue this afternoon and update you.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Dec 2025 14:05:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SmartMove/SmartMove-from-Juniper-with-LSYS/m-p/265514#M614</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-12-17T14:05:49Z</dc:date>
    </item>
    <item>
      <title>Re: SmartMove from Juniper with LSYS</title>
      <link>https://community.checkpoint.com/t5/SmartMove/SmartMove-from-Juniper-with-LSYS/m-p/265516#M615</link>
      <description>&lt;P&gt;No worries, freeze period starting soon anyway, I won't have much else to do than try to fix it for some time so it's not super urgent right now. Much appreciated!&lt;/P&gt;</description>
      <pubDate>Wed, 17 Dec 2025 14:09:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SmartMove/SmartMove-from-Juniper-with-LSYS/m-p/265516#M615</guid>
      <dc:creator>robertp</dc:creator>
      <dc:date>2025-12-17T14:09:25Z</dc:date>
    </item>
    <item>
      <title>Re: SmartMove from Juniper with LSYS</title>
      <link>https://community.checkpoint.com/t5/SmartMove/SmartMove-from-Juniper-with-LSYS/m-p/265518#M616</link>
      <description>&lt;P&gt;Not to sound cheese or corny now, but I always look at this comunity as brotherhood/sisterhood, so we are here to always help, so I will certainly test it and let you know the results mate.&lt;/P&gt;
&lt;P&gt;Stand by &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Dec 2025 14:11:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SmartMove/SmartMove-from-Juniper-with-LSYS/m-p/265518#M616</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-12-17T14:11:10Z</dc:date>
    </item>
    <item>
      <title>Re: SmartMove from Juniper with LSYS</title>
      <link>https://community.checkpoint.com/t5/SmartMove/SmartMove-from-Juniper-with-LSYS/m-p/265523#M617</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/107375"&gt;@robertp&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I got no clue if this looks right, but this is what it gave me, took literally 10 mins.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/32457iD8770B3E67296230/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_2.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/32458i65202016F9AC2E97/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_2.png" alt="Screenshot_2.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_3.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/32456iEFB0C08ABDBD19D4/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_3.png" alt="Screenshot_3.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;   &lt;/P&gt;</description>
      <pubDate>Wed, 17 Dec 2025 14:23:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SmartMove/SmartMove-from-Juniper-with-LSYS/m-p/265523#M617</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-12-17T14:23:12Z</dc:date>
    </item>
    <item>
      <title>Re: SmartMove from Juniper with LSYS</title>
      <link>https://community.checkpoint.com/t5/SmartMove/SmartMove-from-Juniper-with-LSYS/m-p/265528#M618</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;It doesn't I'm afraid, the policies that are under logical-systems in the SRX are not here at all. Normally in a perfect world there should be 3 policies generated from this xml - one root, one called WWW and one WAN. It's also fine(ish) if they generate all in one policy and I could just separate them myself. For example, in your import you cannot see the two below policies, because they are under the 'logical-systems' section:&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="Zrzut ekranu 2025-12-17 153200.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/32459i93307465F2EED203/image-size/large?v=v2&amp;amp;px=999" role="button" title="Zrzut ekranu 2025-12-17 153200.png" alt="Zrzut ekranu 2025-12-17 153200.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Dec 2025 14:36:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SmartMove/SmartMove-from-Juniper-with-LSYS/m-p/265528#M618</guid>
      <dc:creator>robertp</dc:creator>
      <dc:date>2025-12-17T14:36:26Z</dc:date>
    </item>
    <item>
      <title>Re: SmartMove from Juniper with LSYS</title>
      <link>https://community.checkpoint.com/t5/SmartMove/SmartMove-from-Juniper-with-LSYS/m-p/265530#M619</link>
      <description>&lt;P&gt;So how many rules you say should be there all together?&lt;/P&gt;</description>
      <pubDate>Wed, 17 Dec 2025 14:38:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SmartMove/SmartMove-from-Juniper-with-LSYS/m-p/265530#M619</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-12-17T14:38:21Z</dc:date>
    </item>
    <item>
      <title>Re: SmartMove from Juniper with LSYS</title>
      <link>https://community.checkpoint.com/t5/SmartMove/SmartMove-from-Juniper-with-LSYS/m-p/265531#M620</link>
      <description>&lt;P&gt;At least 8, maybe more if it also imports the implied rules which it seems it does. If that's the case then 11.&lt;/P&gt;&lt;P&gt;5 rules with permits and custom objects, and the rest denies.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Dec 2025 14:45:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SmartMove/SmartMove-from-Juniper-with-LSYS/m-p/265531#M620</guid>
      <dc:creator>robertp</dc:creator>
      <dc:date>2025-12-17T14:45:26Z</dc:date>
    </item>
  </channel>
</rss>

