Hello,
We recently migrate from Cisco ASA cluster to a new Checkpoint cluster.
The configuration has been converted by the Checkpoint migration tool.
Now we are facing few strange problem
Server1 to Server2 NAS flow KO
Server3 to Server4 FTP flow KO
From the log I can see that the Gateway block the FTP flow that use the high-port.
This is strange because there isn't a rule on ASA that allow the high-port from S1 to S2.
More or less is the same for the NAS: the Gateway block certain port related the NAS protocol but there is no rule on ASA.
It could be that on ASA we have to allow only the main port like ftp port and not the high port related the same flow as per implicit allow but the CP require and explicit rule for that?
All post-migration problem are related a flow that start with a specific port and continue with other port like FTP
Regards