- CheckMates
- :
- Products
- :
- Quantum
- :
- SmartMove
- :
- migrations errors cisco asa
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
migrations errors cisco asa
Hi all
It looks like there is some migration issues once migrating from cisco asa.
Looks like if the objects contains -all, -to, -in the objects might not be migrated correct, and some objects are renamed, but not for nat policy. It looks like the objects with -all is not created in the migrated policy.
If migrating several contexts please consider that asdm objects DM_INLINE_NETWORK and DM_INLINE_TCP is auto genrated objects for asdm and is there created objects using CSM these could also have the same name but with diferent content.
Feel free to contact me if you need more details on it.
- Labels:
-
cisco
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @Chris_Stevens, SmartMove is an open-source tool, so you are welcome to provide your feedback and suggested modifications.
Just in case, here is the GitHub project link: https://github.com/CheckPointSW/SmartMove
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I used smart move 3 times to convert from Cisco to CP and it did work every single time just fine. Yes, you are correct that those objects you mentioned do keep the default name, so thats a bit of an annoyance, but nothing that cant be fixed : - )
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I use the tool only for migrating the objects and the policy/nat, and then I use notepad++ to correct both the cfg file before and the output files objects.sh/policy.sh. I create firewall object manual og using vsx_provisioning_tool and import only the object and policy. Correct the zones or the policy and are then good to go. I have mograted about 30 firewalls the last couple of months.
