Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
neiren
Participant
Jump to solution

Using SmartMove to convert competitor Cisco configurations has issues

1. I recently migrated the Cisco firewall configuration of two areas of a customer to cp, and found that after the migration, the ACL policy of the Cisco firewall in one area was much less.

2. I uploaded screenshots of smartmove and some Cisco policies

3. The difference I found so far is that the Cisco configuration that can be successfully converted is the three-layer routing mode, and the one that cannot be converted is the bridging mode

0 Kudos
1 Solution

Accepted Solutions
Chris_Atkinson
MVP Gold CHKP MVP Gold CHKP
MVP Gold CHKP

There are limitations described in sk115416.

Please submit feedback on this SK if you feel there are additional gaps than mentioned there.

CCSM R77/R80/ELITE

View solution in original post

0 Kudos
6 Replies
neiren
Participant

cisco_1.jpgsmartmove_1.jpg

0 Kudos
Chris_Atkinson
MVP Gold CHKP MVP Gold CHKP
MVP Gold CHKP

There are limitations described in sk115416.

Please submit feedback on this SK if you feel there are additional gaps than mentioned there.

CCSM R77/R80/ELITE
0 Kudos
neiren
Participant

I don't know the specific cause of the problem? I suspect that it is because the inside and outside interfaces in the Cisco configuration do not have IP addresses, and the BVI is used to share IP addresses.

0 Kudos
the_rock
MVP Gold
MVP Gold

I I did this sort of conversion from Cisco ASA to CP 3 times and never had an issue, it was always able to move all the rules, regular policies, as well as NAT. 

Andy

0 Kudos
neiren
Participant

We have done a lot of projects on Cisco migration configuration to check point, and this is the first time we have encountered this situation.

0 Kudos
the_rock
MVP Gold
MVP Gold

I always followed the video from the sk and no issues. I also converted Cisco to other vendors before and worked okay as well. I always found Cisco is by far the easiest vendor to convert. Mind you, the reason for that is probably because other vendors' formats are way different.

My colleagues and I usually end up doing regex scripting to do say conversion for cp to fgt or fgt to cp or pan to fortigate, seems to work really well, as long as you make sure format matches with whatever vendor you are converting to.

Hope that helps.

Andy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events