<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Check Point R77 firewal security rules +400 rules policy migration in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/check-point-r77-firewal-security-rules-400-rules-policy/m-p/290910#M77203</link>
    <description>&lt;P&gt;hi there&lt;/P&gt;&lt;P&gt;just to let you know that , finally, I was able to upload in the Expedition tool, the 400+ fw rules from the Checkpoint , however, I getting issues with the merge, the Expedition just get stuck and freeze while the merge is running.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ideas?&amp;nbsp; will we need to provision more HW to the expedition server?&lt;/P&gt;&lt;P&gt;any idea is more than welcome&lt;/P&gt;&lt;P&gt;cordially&amp;nbsp;&lt;/P&gt;&lt;P&gt;jose&lt;/P&gt;</description>
    <pubDate>Wed, 02 Oct 2019 17:02:11 GMT</pubDate>
    <dc:creator>JoseEspinoza</dc:creator>
    <dc:date>2019-10-02T17:02:11Z</dc:date>
    <item>
      <title>Check Point R77 firewal security rules +400 rules policy migration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/check-point-r77-firewal-security-rules-400-rules-policy/m-p/289812#M77035</link>
      <description>&lt;P&gt;hello team&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have to migrate a Checkpoint R77 policies firewal security rules +400 rules policy migration, however we can't see those policies when we export to the expedition tool, we know that in R80 version you can use the CLI on the CKpoint to export in pieces those big amount of rules from 0-400 and from 400-800 and so.&lt;/P&gt;&lt;P&gt;we try to use the same commands from R80 to do the same in the R77, but those commands failed,&amp;nbsp; there is another way to do in the CheckPoint R77? any hint?&lt;/P&gt;&lt;P&gt;cordially&lt;/P&gt;&lt;P&gt;Jose&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Sep 2019 14:04:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/check-point-r77-firewal-security-rules-400-rules-policy/m-p/289812#M77035</guid>
      <dc:creator>JoseEspinoza</dc:creator>
      <dc:date>2019-09-24T14:04:54Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point R77 firewal security rules +400 rules policy migration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/check-point-r77-firewal-security-rules-400-rules-policy/m-p/289859#M77045</link>
      <description>&lt;P&gt;Hey!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think this has to do with the fact that Gaia pre-R80 handles files in a different format that R80+ (R80 is postgres). So, if you're migrating from R77 those commands won't work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is a selector on top of Expedition when you're importing the config that lets you choose whether the config comes from a pre-R80 or a R80+ system.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 603px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21533iA451FC643311EE0A/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the case of pre-R80, you will need these files:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 133px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21532i25581B924496C61C/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Sep 2019 18:49:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/check-point-r77-firewal-security-rules-400-rules-policy/m-p/289859#M77045</guid>
      <dc:creator>CMachado</dc:creator>
      <dc:date>2019-09-24T18:49:48Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point R77 firewal security rules +400 rules policy migration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/check-point-r77-firewal-security-rules-400-rules-policy/m-p/289860#M77046</link>
      <description>&lt;P&gt;hi CMachado&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the problem is that migration tool can only read under 400 lines of rules, we are not able to read it when we upload on Expedition, that is why we need to find out how to extract from the CKPoint ONLY the segment relate to security rules or firewall rules and from there upload to the expedition tool.&amp;nbsp;&lt;/P&gt;&lt;P&gt;are we in the same line?&amp;nbsp;&lt;/P&gt;&lt;P&gt;we will check again the files, but until now aren/t able to find the fw rules from the ckpoint.&lt;/P&gt;&lt;P&gt;any other hint?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;cordially,&lt;/P&gt;&lt;P&gt;jose&lt;/P&gt;</description>
      <pubDate>Tue, 24 Sep 2019 19:06:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/check-point-r77-firewal-security-rules-400-rules-policy/m-p/289860#M77046</guid>
      <dc:creator>JoseEspinoza</dc:creator>
      <dc:date>2019-09-24T19:06:54Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point R77 firewal security rules +400 rules policy migration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/check-point-r77-firewal-security-rules-400-rules-policy/m-p/290034#M77075</link>
      <description>&lt;P&gt;Oh, now I get it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Maybe try opening and editing the rulebase file with Notepad++ and see if you can remove some of the rules from the original config and try to load it into Expedition. Another option would be to ask in the Check Mates community at community.checkpoint.com if there are any equivalents of the R80 commands in R77.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best of luck.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Sep 2019 17:44:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/check-point-r77-firewal-security-rules-400-rules-policy/m-p/290034#M77075</guid>
      <dc:creator>CMachado</dc:creator>
      <dc:date>2019-09-25T17:44:04Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point R77 firewal security rules +400 rules policy migration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/check-point-r77-firewal-security-rules-400-rules-policy/m-p/290589#M77150</link>
      <description>&lt;P&gt;hi there&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we use another tool from CKpoint, we were able to get all the config file segmented. we will try today if we can be able to just check the firewall rules (+400).&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Mon, 30 Sep 2019 14:00:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/check-point-r77-firewal-security-rules-400-rules-policy/m-p/290589#M77150</guid>
      <dc:creator>JoseEspinoza</dc:creator>
      <dc:date>2019-09-30T14:00:38Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point R77 firewal security rules +400 rules policy migration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/check-point-r77-firewal-security-rules-400-rules-policy/m-p/290910#M77203</link>
      <description>&lt;P&gt;hi there&lt;/P&gt;&lt;P&gt;just to let you know that , finally, I was able to upload in the Expedition tool, the 400+ fw rules from the Checkpoint , however, I getting issues with the merge, the Expedition just get stuck and freeze while the merge is running.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ideas?&amp;nbsp; will we need to provision more HW to the expedition server?&lt;/P&gt;&lt;P&gt;any idea is more than welcome&lt;/P&gt;&lt;P&gt;cordially&amp;nbsp;&lt;/P&gt;&lt;P&gt;jose&lt;/P&gt;</description>
      <pubDate>Wed, 02 Oct 2019 17:02:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/check-point-r77-firewal-security-rules-400-rules-policy/m-p/290910#M77203</guid>
      <dc:creator>JoseEspinoza</dc:creator>
      <dc:date>2019-10-02T17:02:11Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point R77 firewal security rules +400 rules policy migration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/check-point-r77-firewal-security-rules-400-rules-policy/m-p/293151#M77506</link>
      <description>&lt;P&gt;hello to everybody&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;due the limitation from Ckpoint R77 to split large files, we weren't ables to export to expedition, we finally use a&amp;nbsp; excel table to get the information from CKpoint and manually created in PA 3220 all the 257 FW rules.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we are planning to deploy in production this weekend.&lt;/P&gt;&lt;P&gt;cordially&lt;/P&gt;&lt;P&gt;jose&lt;/P&gt;</description>
      <pubDate>Wed, 16 Oct 2019 15:07:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/check-point-r77-firewal-security-rules-400-rules-policy/m-p/293151#M77506</guid>
      <dc:creator>JoseEspinoza</dc:creator>
      <dc:date>2019-10-16T15:07:34Z</dc:date>
    </item>
  </channel>
</rss>

