- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
How to migrate Cisco ASA configuration to Check Point R80 Management Server database?
Check Point SmartMove tool enables you to convert 3rd party database with firewall security policy and NAT to Check Point database.
At the moment, the tool parses Cisco ASA, Juniper JunosOS and ScreenOS configurations and converts its objects, NAT and firewall policy to a Check Point R80.10 compliant policy. The tool is planned to support additional vendors and security configurations in the future.
The tool generates bash scripts by utilizing Check Point Management API's command line interface, to migrate the converted policy into a R80.10 Management (or Multi-Domain) server.
Check Point SmartMove tool enables you to convert 3rd party database with firewall security policy and NAT to Check Point database.
At the moment, the tool parses Cisco ASA, Juniper JunosOS and ScreenOS configurations and converts its objects, NAT and firewall policy to a Check Point R80.10 compliant policy. The tool is planned to support additional vendors and security configurations in the future.
The tool generates bash scripts by utilizing Check Point Management API's command line interface, to migrate the converted policy into a R80.10 Management (or Multi-Domain) server.
Currently, the following Cisco configurations can be migrated:
| Supported Appliances | Supported Software |
| Cisco ASA |
|
Enjoy.
Hello
On cisco asa configuration we have the below
object network object-192.168.0.237
nat (internal,outside) static 192.168.0.237
and the smart move tool creates 2 manual static rules.
Original Source Original Destination Original Services Translated Source Translated Destination Translated Services
object-192.168.0.237 any any host_192.168.0.237(Nat method static) original original
any host_192.168.0.237 any original object-192.168.0.237(Nat method static) original
Do you think they are needed on checkpoint configuration ?
BR,
Kostas
NAT to itself? I don't think it's required.
I did use same tool for a customer to convert cisco asa config to cp and it worked well, but I did notice certain objects did get messed up. Im wondering if there is a good way to move over vpn users and that configuration over...but might be tricky, as its smart-1 cloud server, not actual on prem, so there is no ssh or web UI.
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY