Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
robertp
Participant

SmartMove from Juniper with LSYS

Hey,

 

I am trying to migrate from a Juniper with logical systems to Check Point VSX. I know I can't count on SmartMove to do everything for me, but I would want it to at least help me move the 1000+ policies 🙂 Any idea how to do it? When I exported the whole xml file off the Juniper and put it into SmartMove I only got the policies from the root logical system. Exporting the logical system itself didn't work either. At this point doesn't even matter if it puts everything in one policy, or does separate ones, as long as I get the rules and objects on the SMS. Any advice would be appreciated.

0 Kudos
10 Replies
the_rock
MVP Platinum
MVP Platinum

Not sure if you are allowed to send the file, but I would be happy to try it in the lab and see if I can make it work. I did this with Fortigate, Cisco, PAN, always worked fine.

Best,
Andy
0 Kudos
the_rock
MVP Platinum
MVP Platinum

I built R82 latest jumbo 44 mgmt server, so if you are allowed/willing to send the Juniper config file, Im happy to give it a go.

Cheers.

Best,
Andy
0 Kudos
robertp
Participant

Hi, I am not, but I'm deploying two logical systems on a test SRX I have, I will add a few policies, check if it gives me the same output as the production one, and if it does I will send that one over. Any potential fix should be valid for the production boxes also. Not sure if I will make it today due to some other tasks but I'll keep in touch max tomorrow. Thanks

0 Kudos
the_rock
MVP Platinum
MVP Platinum

No worries...lab test mgmt is ready on my end.

Best,
Andy
0 Kudos
Vincent_Bacher

First of all, I would like to congratulate you on your decision to leave SRX. No matter where you go, anywhere is better than SRX. Except for Cisco FTD. I speak from experience.


Anyway, I read this in the sk for SmartMove
“Multi routing instance configuration - only single routing instance is supported”
I assume they mean lsys. However, I can't find anywhere in the sk how to deal with multi lsys.

and now to something completely different - CCVS, CCAS, CCTE, CCCS, CCSM elite
the_rock
MVP Platinum
MVP Platinum

I only worked once with SRX, was challenging, to say the least. As far as Cisco FTD, while back, not recently, so not sure how much it changed.

Best,
Andy
0 Kudos
Vincent_Bacher

To be honest, I've had a bad experience with SRX and FTD.
We once lost a lucrative customer, a bank, because of Juniper and SRX.
We had only recently acquired the customer and, at their request, migrated an important cluster to SRX. Then an upgrade was due, and during the change we had a split brain situation. Even the Juniper experts present couldn't find the cause at first. Until a colleague of mine found out in a user group that the behaviour of sync traffic in VLAN had changed with the new release and how to revert it. But that was still enough for the customer to kick us out.
As for FTD, we once set up a two-tier DMZ environment. Checkpoint on the inside and FTD on the outside. Again, after an FTD upgrade, every few days the FTD cluster decided to reject all DNS requests to the outside. The only workaround until a patch version was delivered was to reboot the nodes. Simultaneously.
Since these incidents, I have not wanted to have anything to do with either of them.

and now to something completely different - CCVS, CCAS, CCTE, CCCS, CCSM elite
0 Kudos
the_rock
MVP Platinum
MVP Platinum

Im never gonna forget the call I had once with Cisco support guy about FTD when it was somewhat new and I could tell even he was not familiar with it, so I genuinly felt bad, but you know how it goes when we have to help our own clients.

Anyway, after some time, I could tell we were not going anywhere and I asked him if he could maybe escalate the case and he says to me ( NOT paraphrasing) "You know Mr Andy, I will be 100% honest with you, I can escalate this case, but next engineer will probably know less than me about this"

Gave me good laugh LOL

Best,
Andy
0 Kudos
Vincent_Bacher

Yes I know well the issue to have to support the customers but now I am at the customer side.

An I as well had times where I frequently had to fight with tac to get an engineer that was not less experienced and qualified than myself. But I will not name the vendor 

and now to something completely different - CCVS, CCAS, CCTE, CCCS, CCSM elite
0 Kudos
the_rock
MVP Platinum
MVP Platinum

Truth be told, it could happen with any vendor, specially when there is lots of pressure to fix the problem right over the phone. I recall once with Cisco, lady was so persistent wanting to fix the problem, I had to tell her 10 times I was going to miss the flight to Bora Bora if we go over 6 pm lol

Anyway, we all know how stressfull IT world can be...

@robertp If you are allowed to send any config files, I got time Wednesday to try and see if import works via smartmove tool.

Best,
Andy
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events