Question
Cisco Security Manager conversion, anyone?
We have to convert 30+ FWSM contexts, that we managed in Cisco Security Manager and the converter cannot be used, because the rules and objects from the individual contexts are wrong and misleading. Cisco Security Manager (CSM) has it's own rules and objects which we need to take over and not the individual contexts. CSM writes down a policy structure that does not resemble the policy in CSM, but it actually does break down the policy into more individual components and, i.e. for a context that we have 130 rules in CSM, on the FWSM we have actually 1250, which the FWSM then even in more detail parses into ACE entries, that could overload available space on the FWSM. 1) Converter should use CSM as input not FWSM context. Otherwise the policies and comments are horrible. 2) Object Groups used everywhere, as there was no impact and simplification each object is a group. Now converter makes a group object, with a single IP subnet objject in it. I think this is not useful and converter should account for that and only create an IP Subnet object with the name of the group. 3) Mesh policies end up with too many policies through the converter. In Cisco many times, e.g. wireless controllers to guest wireless controllers capwap a mesh rule was used, i.e. 10 sources , the same 10 sources as destination with some services. The converter creates some funny combinations. Is there someone who has expierenced this before, are there any scripts from fortinet to actually do a proper CSM to FG conversion?
