MT 3.1 and CheckPoint VSX

Reply
L6 Presenter

MT 3.1 and CheckPoint VSX

We're running a really old version of CP 71.40 running VSX with multiple virtual firewalls.

 

This document describes where to get a config file from, but this does't account for a virtualized enviornment and the file nor directory exists for these virtual CheckPoint Firewall.

 

 

https://live.paloaltonetworks.com/t5/Migration-Tool-Articles/Checkpoint-Different-Source-Files-Forma...

 

 

Has anyone had any experience in migrating a CheckPoint config in a VSX enviornment?

 

 I was able to find the directory for my virtualized FWs.  In there I found "objects_5_0.C" and "rulebases_5_0.fws"

 

But the MT UI kep saying I needed to import "Policy" too, so I looked in the same folder and only cound "connectra_policy.C"

 

 

When I loaded all 3 up I see the objects, I see "NAT" rules, but in "Security" there are no Security Rules.  Any ideas?

 

 

Thanks in advance for any suggestions.  (We already contacted our support vendor who said basically your version is too old to even provide assitance with)

 

Thanks,

Brandon

L7 Applicator

Re: MT 3.1 and CheckPoint VSX

Inside the rulebases file you will find different policies, just keep the one you want to migrate inside the file and then use it as a Security Policy and not as a rulebases file, you have to check the OPTION A. Hope that helps

L6 Presenter

Re: MT 3.1 and CheckPoint VSX

I did and no luck.  The "security" part of the MT is blank.  it didn't create any Palo rules to be imported.

 

 

L7 Applicator

Re: MT 3.1 and CheckPoint VSX

Can you send us the first 4 lines from your rules file? To validate it? Or you can send us the whole config to fwmigrate@paloaltonetworks.com

 

Regards

L6 Presenter

Re: MT 3.1 and CheckPoint VSX

@alestevez How would I send the whole config?  Can I export the project some how?  E-mail you the individual files?

L7 Applicator

Re: MT 3.1 and CheckPoint VSX

You can send us your config to fwmigrate@paloaltonetworks.com Regards

L6 Presenter

Re: MT 3.1 and CheckPoint VSX

@alestevez sorry I mean literally, I know via e-mail, but what's the config you're looking for?  The CheckPoint files I'm using?  Exporting some config out of the MT somehow?

L7 Applicator

Re: MT 3.1 and CheckPoint VSX

You can send us the config files from checkpoint, the routes, objects_5_0.C or rules.C and rulebases_5_0.fws if you have as well.

 

thanks !

L6 Presenter

Re: MT 3.1 and CheckPoint VSX

Thanks to @alestevez for his help this morning.  We got on a WebEx and he was able to help me get into my Prod CP enviornment and get the files needed for use in the MT 3.3.

L0 Member

Re: MT 3.1 and CheckPoint VSX

@Brandon_Wertz@alestevez Any chance the solution to this could be published; I'm having what sounds like the same problem.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!