1 firewall to 2 vsys?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

1 firewall to 2 vsys?

L1 Bithead

Hi Guys 

 

Does anyone have a method to migrate from a single firewall (specifically checkpoint) to two or more vsys?

 

Thanks

1 accepted solution

Accepted Solutions

your workflow is correct - import 2 separate route files into 2 separate VR's.

 

When you initiate the autozoneassign, you will be prompted to choose which VR to use as the routing reference. prior to running the autozoneassign you will need to assign the interfaces to the appropriate VR's as well as those IP's assigned to the interfaces will be used as local routes and will also be used in the autozoneassign calculations.

View solution in original post

4 REPLIES 4

L5 Sessionator

you'll have to decide on your desried design goal - are you planning to use VSYS or are you ok with using multiple virtual routers to isolate traffic? if you will be using panorama you'll have to decide if the vsys will be in the same or different device groups (DG).

 

Is your plan to split some policies and objects between the 2 vsys? If you will be using Panorama are your plans to have both vsys in the same or different device groups?

if the VSYS will be members of different DG you can import all policies and objects into shared at first then add VSYS specific policies and objects afterwards.

Thanks for your reply sjanita.

 

I am planning on going from a single checkpoint to 2 vsys which reside in 2 seperate device groups.

 

I imaine that the process will be to injest 2 route tables and CSV's into MT then maybe use auto assign to re-assign zones, then possibly use the filtering to remove the irrellevant rules for each new firewall.  

 

Or is there a simpler way as you mentioned?  

 

Thanks

your workflow is correct - import 2 separate route files into 2 separate VR's.

 

When you initiate the autozoneassign, you will be prompted to choose which VR to use as the routing reference. prior to running the autozoneassign you will need to assign the interfaces to the appropriate VR's as well as those IP's assigned to the interfaces will be used as local routes and will also be used in the autozoneassign calculations.

Thank you @sjanita 

  • 1 accepted solution
  • 5343 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!