We have a Checkpoint mgmt workstation at R77.30 managing firewalls on R75.47. We are attempting to convert the Checkpoint firewalls to Palo Alto using the Expedition freeware software. But the documentation contains no info as to what format the tools needs to see the Checkpoint info. The Checkpoint to HTML product cpdb2web does not apprear to be the tool. And there is no documentation for Expedition that describes exactly what the import files are supposed to look like. I realize Expedition is freeware, but the lack of documentation and mismatched documentation is very frustrating and makes it virtually useless. TAC Doesn't support it so here's a question exactly WHAT is Expedition expecting from Checkpoint in terms of input files and where is that documentation?
Once you install expedition and head to the import tab the instructions are located there on how to import them. Attached is a screenshot of the steps that need to be taken for an import.
But WHAT FILES? What format? There is no documentation. The .xml files generated by the Checkpoint cpdb2web tool aren't it. All it does is give me a vague error about the file not being in correct format.
1. Objects_5_0.C - found this on: /opt/CPsuite-R77/fw1/conf
2. Rulebases_5_0.fws - found this on: /opt/CPsuite-R77/fw1/conf
3. PolicyName.W - a file with extension .W”, the filename takes the policy’s name (by default Standard.W). Those files are stored in the SmartCenter (Management) under “$FWDIR/conf”
You will need to perform backups of these types of files, also within expedition it does state the file types that are required. XML is not stated as a supported file type since the object files require .C format and the Rulebases .fws and the Policyname a .W
I believe once you create a backup of these files they should be located within a .tgz file as specified within the checkpoint user manual.
For more information regarding checkpoint I would recommend this document.
You should always upgrade to the latest beta release as there are always news updates and fixes to parse the files you are importing, if you would like to stay up to date with all of the releases we have made with expedition feel free to follow it here.
Once you have your expedition online and have imported your checkpoint files we have written articles on next steps you can take here.
Although this is a video on an ASA import most of what you're trying to do applies because after you import your configuration you will need to remap interfaces resolve duplicate addresses etc. So feel free to also view this video has a tool to help with your conversion.
Many questions have been answered here on these forums but we monitor them to help when we can, so feel free to always post more questions here.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!