I think there is not a full understanding at Check Point of the challenge we are facing in this context.
It seems that CheckPoint has missed to migrate/convert(automatically) or block this situation during upgrade from R77.xx to R80.xx ! (if a Traditional Policy is still there) !
it is not only that we need to convert VPN stuff (rules and properties) from Trad. VPN Policy to Simpl. VPN Policy .
Example: I have one customer with a rulebase of about 4000 rules - They never used VPN on this FW. This policy exists since before 2002 ( since Simpl. VPN Policy was introduced). They never had an idea of a difference betw. Simpl. and Trad. VPN
Now after about 1,5 yours with R80 ( now on R80.20 ) we came to this situation:
He introduced a sub-layer - and wanted to move a lot of these 4000 rules to the sub-layer. But during "copy & paste)" he got this strange error:
Now we recognised, that the original policy is still in Trad. VPN mode, but never noticed this anywhere (btw: "VPN" column is hidden by default in a Simpl. VPN policy, too)
( This error says exact the opposite, but is definitly wrong , I tested the other way too- try it!!)
The situation is now as follow:
Main Policy is Trad. VPN and, Sub-layer in Simpl. VPN Mode !!
So , again - I ask as well: what todo next ? - You can try to migrate now this rulebase with 4000 rules, with the complex, slow and tnever working (all my tries with other policys from other customers failed) Python toolkit ?
maybe ...
Any other ideas?
Thanks, Martin