Checkpoint to Palo Alto migration

Showing results for 
Show  only  | Search instead for 
Did you mean: 
Please sign in to see details of an important advisory in our Customer Advisories area.

Checkpoint to Palo Alto migration

L0 Member

Hello Expert,


We are planing to migrate our current checkpoint platform R80 to Palo Alto firewall. I have gone through articles indicating the migration and would like to understand will Expedition tool migrates the NAT and VPN configuration too from checkpoint to palo alto.


Your early response will be highly appreciated.


Thanks in advance.


L5 Sessionator

NAT rules are already supported, but not VPN yet.


Notice that for Checkpoint R80.10 in XML format may be missing some address objects if those are not directly referenced in the security rules or NAT rules, but only in other groups. That means that it may not be able to perform a complete migration as objects may not be found. 

Is there an update?  

1. Is there a way to pull the VPN config from Checkpoint R80 (.jar file does not) and

2. Can Expedition migrate the VPN configuration?

D. Elliott

Hello Doug-Elliott,


Checkpoint VPN config migration is not supported at current version.

I wanted to see if there was an update to this topic. Looking to move from CP R80.40 to PA 10.4.2-h2. I looked through the release notes, but did not see anything about it. Just wanted to see if I overlooked something.

@DarrenVallance VPN for checkpoint migration is still not supported at this point. 

  • 5 replies
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!