Conversion of SonicWALL NSA3600 config to PA 220?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Conversion of SonicWALL NSA3600 config to PA 220?

L2 Linker

Is it possible to convert (migrate) a SonicWALL NSA3600 configuration to a PA 220?

Using Expedition 4.0?

Other method?

 

Thanks

2 accepted solutions

Accepted Solutions

Cyber Elite
Cyber Elite

@catrock,

No and yes.

Expedition doesn't have a direct convertion for Sonicwall, but you can do it through the Machine Learning module. Personally what I would recommend is that you actually take a look at your Sonicwall configuration and manually rebuild the policies on the Palo Alto. The issue with migrations, at least to me, is that you have to spend a large amount of time going back through and 'Palotizing' the configuration once everything is up and running.

I personally find simply rebuilding the configuration, in a Palo centric manner, to be drastically easier and overall faster then using any of the migration assistants. 

View solution in original post

Hello,

I agree with @BPry, I usually rebuild from scratch since you are going from a traditional layer3 firewall to a layer 7. Build the policies as layer 3/4 and then build you more specific ones above those to make sure the new layer 7 policies are getting hit. Then start removing the layer3/4 traditional rules.

 

It is a process and not an easy one at that. But its worth it in the end.

 

Regards,

View solution in original post

2 REPLIES 2

Cyber Elite
Cyber Elite

@catrock,

No and yes.

Expedition doesn't have a direct convertion for Sonicwall, but you can do it through the Machine Learning module. Personally what I would recommend is that you actually take a look at your Sonicwall configuration and manually rebuild the policies on the Palo Alto. The issue with migrations, at least to me, is that you have to spend a large amount of time going back through and 'Palotizing' the configuration once everything is up and running.

I personally find simply rebuilding the configuration, in a Palo centric manner, to be drastically easier and overall faster then using any of the migration assistants. 

Hello,

I agree with @BPry, I usually rebuild from scratch since you are going from a traditional layer3 firewall to a layer 7. Build the policies as layer 3/4 and then build you more specific ones above those to make sure the new layer 7 policies are getting hit. Then start removing the layer3/4 traditional rules.

 

It is a process and not an easy one at that. But its worth it in the end.

 

Regards,

  • 2 accepted solutions
  • 3086 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!