The log files describe instances where fwconvert could not directly convert your FireWall-1 policy to an equivalent SunScreen policy. After conversion, you should review the contents of the log files to see what else you may need to do to the new SunScreen configuration.
The policyname_Obj.log file lists objects found in your FireWall-1 security policy that were not directly supported in SunScreen 3.2. The following table lists the FireWall-1 objects and shows whether they were converted to SunScreen 3.2.
Table 8-3 How Conversion to SunScreen 3.2 Affects FireWall-1 Objects
FireWall-1 Object |
SunScreen Equivalent |
Conversion Status |
---|---|---|
Host |
Host |
Yes. |
Network |
Range |
Yes. |
Router |
None |
No. See the policyname_Obj.log file for details. |
Switch |
None |
No. See the policyname_Obj log file for details. |
Domain |
None |
No. See the policyname_Obj log file for details. |
Group |
Group |
Yes. |
Gateways |
None |
No. However, they are logged in the policyname_OBJ.log file. Gateways require more configuration within SunScreen to assure that the IP addresses of the gateway are correct. See the SunScreen 3.2 Administration Guide for more information. |
The following figure shows a sample policyname_Obj.log file, similar to the file that you can generate from your FireWall-1 policy.
/***** SunScreen: Firewall-1 conversion log *****/ /***** @(#)ObjStore.java 3.7 99/11/09 Sun Microsystems, Inc. *****/ Objects of type: gateway, need some user decisions You had a gateway with name "skil" ipaddr 205.167.60.13 If this is the gateway on which SunScreen is being installed please refer to the 'ssadm edit' command to enable the interfaces |
This file shows rules generated from FireWall-1 rules that cannot be used in the SunScreenenvironment without modification. The policyname_Rule.log file explains why these rules were not added to the SunScreen firewall, for example:
Source, Destination, or Installed on objects are of a type not supported by SunScreen
FireWall-1 Service is of a type not supported by SunScreen
FireWall-1 Action is not supported by SunScreen
SunScreen does not support FireWall-1 encryption, user authentication, or client authentication. Encryption in SunScreen is accomplished through SunScreen IKE or SunScreen SKIP, as explained in the SunScreen 3.2 Administrator's Overview. For more information regarding SKIP, see the SunScreen SKIP User's Guide, Release 1.5.1.
All FireWall-1 rules are generated during the conversion. You must remove any rules that you do not need manually.
The following shows a sample policyname_Rule.log file that might be generated after the FireWall-1 to SunScreen conversion.
/***** SunScreen: Firewall-1 conversion log *****/ /***** @(#)RuleStore.java 3.6 99/11/09 Sun Microsystems, Inc. *****/ Rule below not added as the action Encrypt is configured differently in SunScreen. add_nocheck Rule "smtp" "aiims" "*" Encrypt Rule below not added as the action Encrypt is configured differently in SunScreen. add_nocheck Rule "echo" "aiims" "*" Encrypt Rule below not added as the action User Authentication is not valid in SunScreen. add_nocheck Rule "ftp" "*" "aiims" User Rule below not added as the action Client Encryption/Authentication is not valid in SunScreen. add_nocheck Rule "dns" """ "*" Client |
|
The following figure lists FireWall-1 objects encountered in your policy that are not supported by SunScreen.
#Invalid Objects from FW-1 #Wed Mar 31 17:40:23 PST 1999 invalidobj1=gateway skil |