While migrating from checkpoint to Palo Alto after defining zones and interface.
Can I simply use any in source and destination zone and create policies with specific objects in source/destination address.
Will it work, for replicating same policies while migrating from checkpoint to Palo Alto.
You can do that, however I would recommend scoping the policies down as much as you can. We also migrated from CP and ended up with some pretty silly policies that had to be tuned. each column in the policy is going to strengthen your security stance so the more the merrier I say!
instead of using any any in the zones I would recommend putting each zone that needs that traffic in there, this will also prevent you from unintentionally allowing any zones that are added later you may not want to allow for said policies.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!