Hello Experts,
we have recently replaced our old nokia gateways on R75 to 5900 appliances on R77.30. Now we are plan to migrate to R80.30 as a pre -requisite we have run PUV that has identified the below error
Firewall policies with Traditional VPN mode
Description:
Traditional mode refers to legacy VPN policy, which was replaced by Simplified VPN (first introduced at 2002 in version NG FP3). Please change the below policies by using one of the methods:
1. Convert your Firewall policies: In SmartConsole, go to Policy > Convert To > Simplified VPN, and follow the wizard instructions.
2. In your Firewall policy, delete rules that contain the actions Encrypt or Client Encrypt.
If you have a specific case in which you have to use Traditional VPN mode, please contact Check Point support.
These are the Traditional VPN policies or rules that must be converted or deleted:
I have gone through the R77.30 admin guide to migrate from traditional vpn to simplified vpn and i have some queries related to that as we need to run the conversion process
Policy> Convert to > Simplified VPN.
1.When we run the conversion process it will be run on each policy package separately and not on all the policy package on the mgmt server ?
2.For each rule that allows traffic for traditional vpn that has action assigned as encrypt will be converted to two rules ?
3.Do we need to create communities prior running the conversions process ?
4. Is the conversion process reversible ? What can be a fall back plan ?
I have also seen an alternate procedure in the guide
1. On the Global Properties > VPN page, select either Simplified mode to all new Security
Policies, or Traditional or Simplified per new Security Policy. File > Save.
2. File > New... The New Policy Package window opens.
3. Create a name for the new security policy package and select Firewall and Address
Translation.
In the Security Policy Rule Base, a new column marked VPN appears and the Encrypt option is no
longer available in the Action column. You are now working in Simplified Mode
So if we make changes in the global properties will it only apply to new policy package created and wont affect the current policy packages that are using traditional vpn ?
What i was thinking of doing is to create a new policy package that uses simplified vpn and then copy the rules from the old policy package (thats using traditional vpn).
Then create the vpn rules and communities in new policy package and during migration attach the new policy package to the gateways . In case we have an issue will can attach the old policy package to roll back.
Please share any suggestions
Regards,
Sijeel