Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
AmitS
Participant

Not able to convert full config from CiscoASA to Checkpoint using Smart Move

Dear All,

I am facing issues in converting the Firewall config from Cisco ASA v9.18(4)50  to check Point compatible using the SmartMove tool (v9.50.8370.13807).

The Cisco ASA config consists of 700+ access policies & 1000+ objects (address objects/groups, service objects/groups).

While converting, using tool I am able to see only 5-7 rules being converted, rest rules are not getting converted.

I have tried resolving all Error of Duplicate object name or unique object name, still the same issues.

Need some solution on this asap as we are about to do a migration in coming weeks and manual policy creation will take time.

Also I am getting below errors:

0Cannot find interface assigned to ACL group: Interface details: lan-zone.;
1Cannot find interface assigned to ACL group: Interface details: external-zone.;

Error creating a rule, missing information for source Cisco object:

Error creating a rule, missing information for Cisco service object

 

 

 

 

0 Kudos
2 Replies
Lesley
MVP Gold
MVP Gold

Copy paste from old topic:

interface info must be indented as follows - 

 

interface GigabitEthernet0/0.123 vlan 123 nameif EXAMPLE1 security-level 0 ip address x.x.x.x 255.255.255.240 standby x.x.x.x‍‍‍‍‍

interface command is a parent command, and vlan/nameif/security-level/ip address are child commands and must be indented.

Also did you see:  Before you run SmartMove, replace DHCP / DAIP interfaces with static IP addresses on your cisco Gateway. In https://support.checkpoint.com/results/sk/sk115416

-------
Please press "Accept as Solution" if my post solved it 🙂
0 Kudos
AmitS
Participant

Hi Lesley,

I have Port channel interfaces in cisco as below:

interface Port-channel2
description **Connected to Internal**
nameif lan-zone
security-level 100
ip address x.x.x.x 255.255.255.0 standby x.x.x.x

interface Port-channel95.888
vlan 888
nameif Example1
security-level 80
ip address x.x.x.x 255.255.255.240 standby x.x.x.x

So as per your suggestion, should this config be present in one-line itself, rather then on each new line??? this also I tried still the same issue, not converting the full policy package.

Also I noticed that many network objects are  not getting converted.

Also Any suggestions on the errors mentioned?

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events