ScreenOS Firewalls (NOT SRX)
Reply
JBM
Visitor
JBM
Posts: 5
Registered: ‎05-13-2009
0

Convert Router Junos firewall filters to ScreenOS policies

Hi,

 

I'm new in Juniper products, and I new to replicate a M10i router firewall filter configuration to a Netscreen firewall policies.

Is there any way to do it? Or should I configure by hand each filter?

 

Thanks in advance,

Javier

Distinguished Expert
Screenie
Posts: 1,076
Registered: ‎01-10-2008
0

Re: Convert Router Junos firewall filters to ScreenOS policies

I'm afraid It has to be done manualy. Of course you could do some scripting if you have many rules.
best regards,

Screenie.
Juniper Ambassador,
JNCIA IDP AC WX JNCIS FW SSL JNCIP SEC ENT SP JNCI

If this worked for you please flag my post as an "Accepted Solution" so others can benefit. A kudo would be cool if you think I earned it.
JBM
Visitor
JBM
Posts: 5
Registered: ‎05-13-2009
0

Re: Convert Router Junos firewall filters to ScreenOS policies

Thanks Screenie,

 

I suposed that I should do it by hand.. but there are more than 30k lines of firewall filter configuration :smileysad:

I only have a config file, do you know if is there any way to convert it to html o something easier to read?

 

Best regards

Distinguished Expert
Screenie
Posts: 1,076
Registered: ‎01-10-2008
0

Re: Convert Router Junos firewall filters to ScreenOS policies

ScreenOS config to HTML you mean? There's a tool for this http://ns2html.sourceforge.net/  it's creating HTML documentation on your ScreenOS config. Nice tool, gives an overview of your policies.
best regards,

Screenie.
Juniper Ambassador,
JNCIA IDP AC WX JNCIS FW SSL JNCIP SEC ENT SP JNCI

If this worked for you please flag my post as an "Accepted Solution" so others can benefit. A kudo would be cool if you think I earned it.
JBM
Visitor
JBM
Posts: 5
Registered: ‎05-13-2009
0

Re: Convert Router Junos firewall filters to ScreenOS policies

What I would like to convert is Junos M10i config file.

 

I've been read about ns2html, but I'd like to find a junos2html script :smileywink:

 

Thanks

Distinguished Expert
Screenie
Posts: 1,076
Registered: ‎01-10-2008
0

Re: Convert Router Junos firewall filters to ScreenOS policies

I'm not awre at such a script. I'd go for AWK or PERL to generate objects definition statements. But: you have to deal with zones. So maybe set criterea on network addresses for selecting the right zones?  After that more or less the same for policies. It's a hugh task I'm afraid. Buy a lot of coffee to go along with it!
best regards,

Screenie.
Juniper Ambassador,
JNCIA IDP AC WX JNCIS FW SSL JNCIP SEC ENT SP JNCI

If this worked for you please flag my post as an "Accepted Solution" so others can benefit. A kudo would be cool if you think I earned it.
JBM
Visitor
JBM
Posts: 5
Registered: ‎05-13-2009
0

Re: Convert Router Junos firewall filters to ScreenOS policies

Thanks Screenie,

 

I think that I'm going to need something more than coffee!

 

Regards

Distinguished Expert
Screenie
Posts: 1,076
Registered: ‎01-10-2008
0

Re: Convert Router Junos firewall filters to ScreenOS policies

So come over here, lot's of coffeeshops in Amsterdam :smileywink:
best regards,

Screenie.
Juniper Ambassador,
JNCIA IDP AC WX JNCIS FW SSL JNCIP SEC ENT SP JNCI

If this worked for you please flag my post as an "Accepted Solution" so others can benefit. A kudo would be cool if you think I earned it.
Copyright© 1999-2013 Juniper Networks, Inc. All rights reserved.