Sign in Get started

Firewall migration / Scope first

Cisco ASA
to Palo Alto PAN-OS

Prepare the source, review the translated configuration and validate the behavior that matters to your network. Start with the device, software version and features in scope.

Discuss this migration →Open the platform →

Account approval and feature support apply. A listed migration path does not certify every model, version or configuration.

Define the handoff

What goes in.
What you review.

Source inputs

ASA configuration export and the device/software version. Include interface context and operational captures needed to review routing and NAT.

Target output

Reviewable PAN-OS SET or XML output for the selected target, subject to findings and supported features.

Path-specific boundaries

Cisco ASA is a source platform. Target-device validation and live traffic checks remain necessary; Local ASA preparation is a separate preview workflow.

Scope the review

Check the behavior,
not just the syntax.

REVIEW 01

Interface security levels and target zones

Confirm the intended behavior, supported scope and target-platform requirements.

REVIEW 02

Object, service and policy references

Confirm the intended behavior, supported scope and target-platform requirements.

REVIEW 03

Manual, object and identity NAT behavior

Confirm the intended behavior, supported scope and target-platform requirements.

REVIEW 04

Routing, application dependencies and target import

Confirm the intended behavior, supported scope and target-platform requirements.

These are review areas, not a guarantee that every construct in them is automated. Unsupported features, missing captures and conditional behavior remain part of the engineering review.

See the current product

Explore the workflow.

View dated product captures and a clearly labeled synthetic verification example. A screenshot of an interface does not establish acceptance of this migration path.

See the product tour →

Understand your result

Read the findings and their limits alongside the output. Address blockers, validate device acceptance and test affected traffic before seeking deployment approval.

Read the result guide →

Plan the next step

Bring the details
that make your migration different.

Source and target models, software versions, critical features and the change window help establish a realistic scope.

Discuss your scope →Compare migration paths →