Check Point Conversions
Check Point differences
General
- The FortiGate set allowaccess command for interfaces doesn’t exist on Check Point. Because FortiGate requires this setting, FortiConverter enables all services for interfaces by default.
- The interface Lead to Internet is a default static route on FortiGate.
- FortiConverter supports Traditional Mode and Simplified Mode IPSec.
Schedule configuration
FortiConverter converts "Day in month" time schedules to FortiGate one-time schedules. It converts "Day in week" and "None" schedules to recurring schedules.
You assign a year range for the "Day in month" schedule. If the specified day doesn't exist for a certain month, FortiConverter doesn't generate the one-time schedule for that month.
NAT and policy configuration
FortiConverter supports the conversion of the following NAT types:
- Hide NAT
- Static NAT
- Manual NAT
FortiConverter doesn't convert NAT global properties.
VPN configuration
Check Point doesn't configure VPN within a firewall rule. When FortiConverter converts the configuration to FortiGate, it generates several VPN policies from non-"Lead to Internet" interfaces to the "Lead to Internet" (default route) interface.
After FortiConverter converts the VPN configuration, the VPN policy destination interface refers to the "Lead to Internet" interface.If you changed the default route egress interface, you may need to update the VPN/Policy configuration manually.
FortiConverter can support VPN IPSec policies configured in both Traditional Mode and Simplified Mode. However, FortiConverter can only convert one mode at a time. If encrypted rules are detected, FortiConverter defaults to Traditional Mode conversion.
To convert Traditional Mode policies to Simplified Mode policies, use the Check Point Security Policy Converter Wizard. This can be found by clicking Policy > Convert to > Simplified VPN from the Check Point SmartDashboard.
FortiConverter can detect and convert meshed and star VPN topologies in Simplified form.
Service objects
Unlike FortiGate service objects, Check Point service objects have a protocol type attribute. FortiGate uses a session helper object to provide the same functionality as the service objects with a protocol type attribute.