Hi @Sanjay_Ramaiah ,
If the config is not too large and you may not do this again, it may be best to manually configure the PA. Generally, you assign a zone to each interface on the Check Point.
If the migration is huge, then it will pay off to use Expedition. https://live.paloaltonetworks.com/t5/expedition/ct-p/migration_tool You can search on that page and find lots of discussions. Here are a couple good ones you may like:
https://live.paloaltonetworks.com/t5/expedition-discussions/checkpoint-r80-10-migration-document/td-p/256083
https://live.paloaltonetworks.com/t5/expedition-articles/migrating-checkpoint-r80-updated-on-december-2020/ta-p/216298
https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-error-upload-tgz-checkpoint-r81/td-p/328700
One thing that I really like about Expedition is the ability to clean up clutter that has accumulated over the years. It does a great job of identifying unused configuration.
Thanks,
Tom
... View more