Migrating from one firewall vendor to another can be a huge undertaking requiring hours of tedious access and NAT rule rewriting. Wouldn’t it be nice if someone came up with a FREE tool that converted one vendor’s firewall configuration files into another vendor’s format? Think of the tens or hundreds of man hours that it could save you. Well you’re in luck. That is exactly what Cisco has created with its free SCT tool. The bummer is it only works for converting Check Point firewall configs to Cisco ASA, PIX or FWSM configs. It currently works with Check Point 4.x, NG, UTM, and NGX. It won’t work with any other vendors yet. But if you’re doing a Check Point to Cisco firewall conversion, the SCT tool is a godsend.
Cisco SCT is available to anyone with a Cisco.com login. Be aware that the user of the tool should be trained properly and understand its limitations. Cisco recommends that you review/scrub the output to verify its accuracy. To that end, they have made a training slide deck and full documentation available to you. Another nice thing is that support is available by emailing to .
I find the SCT tool extremely easy to use, very accurate, and a huge time saver. The tool runs on a Windows PC. So how does it work exactly? Well, let’s see…
First you import the appropriate Check Point Firewall files into the tool. You’ll need the following files:
Here is a screen shot of the first page of the wizard:

The next step is to tell SCT how to format your Cisco firewall output files. You pick the platform (ASA, PIX, or FWSM) and other options as shown below:
The final step is to configure the Cisco firewall interfaces as shown below:
That’s it! The tool will convert all of the following from Check Point format to Cisco format:
The output from the SCT tool is fairly robust. It is formatted in HTML and heavily hyperlinked. It includes a conversion report indicating any conversion errors or notes. The output is formatted in such a way as to make it easier to understand exactly what Check Point rule created which Cisco rule. Here is a screenshot of a conversion report:

The original Check Point config is shown and is fully hyperlink enabled. Check out this example:

The final ASA config file is shown below with full comments and even shows which Check Point rule maps to each ASA rule.

All in all, the SCT tool is a huge time saver. Just its ability to transfer all of the network and service groups from Check Point to ASA is worth its weight in gold. True, the output should be looked over very carefully to make sure it is correct before putting it into production, but this pales in comparison with the time it takes to do a conversion from scratch. You can download the training and SCT tool here.
http://www.cisco.com/cgi-bin/tablebuild.pl/sct
The opinions and information presented here are my personal views and not those of my employer.
Latest software headlines from Network World:
At 10, Google reiterates commitment to CIOs
As Google turns 10, enterprise success in question
Zoho adds Google Docs-like file management
|
Does Verizon's Voyager stack up to the iPhone? |
|
|
5 IT skills that won't boost your salary
[1,407]
Women 4 times more likely than men to cough up personal info
[589]
Japan's 10 funniest tech-related commercials [Videos]
[407]
Throwing away a promo CD is "unauthorized distribution"?
[1,265]
Adults too quick to dismiss educational video games
[682]
Attack of the iPhone clones [Slideshow]
[578]
10 things IT needs to know about AJAX
[1,258]
This Year's 25 Geekiest 25th Anniversaries [Slideshow]
[409]
|
|