Symantec Client Firewall Policy Migration Guide
Installing and using the Symantec Client Firewall Migration Wizard This document includes the following topics: About the Symantec Client Firewall Migration Wizard About installing the Symantec Client Firewall Migration Wizard Installing the Symantec Client Firewall Migration Wizard Converting Symantec Client Firewall policies Importing migrated policies About the Symantec Client Firewall Migration Wizard The Symantec Client Firewall Migration Wizard converts a single Symantec Client Firewall policy into multiple policies that you can import with Symantec Endpoint Protection Manager. You convert a single Symantec Client Firewall policy after you export it from the Symantec Client Firewall Administrator. The formats that are supported for conversion are.cfp,.xml, and.cfu. The.cfp and.xml formats are full policy files. The.cfu format is an update policy file. The Symantec Client Firewall Migration Wizard lets you create the following policies from.cfp and.xml formats: Firewall policy for the default location Firewall policies for each additional location Firewall policy for prules
4 Installing and using the Symantec Client Firewall Migration Wizard About the Symantec Client Firewall Migration Wizard Intrusion Prevention policy The Symantec Client Firewall Migration Wizard lets you create the following policies from.cfu formats: Firewall policy for the default location Firewall policy for prules The following informaiton is migrated from a Symantec Client Firewall Administrator firewall policy to a Symantec Endpoint Protection Manager firewall policy: Rules prules Zones Locations Intrusion Prevention Settings Client Settings Firewall policies generated for locations contain rules created from the following information in the order listed: Restricted Zone entries Trusted Zone entries Protocol Filtering Client Settings System rules Application rules Trojan rules Default rule Firewall policies generated for prules contain rules created from the following: prules Default rule
Installing and using the Symantec Client Firewall Migration Wizard About installing the Symantec Client Firewall Migration Wizard 5 About installing the Symantec Client Firewall Migration Wizard The Symantec Client Firewall Migration Wizard is composed of two files, SCFMigrationTool.bat and SCFMigrationTool.jar. These files are available in the TOOLS directory on the installation CD and from Symantec technical support. The Symantec Client Firewall Migration Wizard also requires Java Runtime Environment (JRE) 1.5 or later and does not include this software. If you install the Symantec Client Firewall Migration Wizard is on a computer that runs the Symantec Endpoint Protection Manager, installing JRE 1.5 is not necessary. Symantec Endpoint Protection Manager automatically installs JRE 1.5. If you install the Symantec Client Firewall Migration Wizard on a computer that does not run the Symantec Endpoint Protection Manager, you must install JRE 1.5 on that computer. You can download JRE 1.5 from http://www.sun.com. Additionally, if you install the Symantec Client Firewall Migration Wizard on a computer that does not run the Symantec Endpoint Protection, you must set the PATH environment variable. The PATH environment variable must point to the JRE 1.5 runtime folder. Installing the Symantec Client Firewall Migration Wizard This installation method is a best practice and lets you quickly import migrated policies into the Symantec Endpoint Protection Manager. To install the Symantec Client Firewall Migration Wizard On a computer that runs the Symantec Endpoint Protection Manager, copy SCFMigrationTool.bat and SCFMigrationTool.jar to the following directory: \\Program Files\Symantec\Symantec Endpoint Protection Manager\bin Converting Symantec Client Firewall policies The migration process involves selecting a policy file to migrate, and selecting an output directory.
6 Installing and using the Symantec Client Firewall Migration Wizard Converting Symantec Client Firewall policies To convert Symantec Client Firewall policies 1 Copy the policies to migrate to a working directory. 2 Browse to and double-click SCFMigrationTool.bat. 3 In the Welcome panel, click Next. 4 In the Policy File Selection panel, click Browse and select a policy file to migrate from your working directory..
Installing and using the Symantec Client Firewall Migration Wizard Converting Symantec Client Firewall policies 7 5 Click Browse, select output directory, and then click Next. 6 In the Options and Migration panel, optionally uncheck policy files that you do not want to create, and then click Migrate. 7 When the migration completes, click Report to review the rules and options that were migrated.
8 Installing and using the Symantec Client Firewall Migration Wizard Importing migrated policies 8 In the Migration Status panel, click Finish. 9 Review the.dat files that are created in your output directory. You import these files with the Symantec Endpoint Protection Manager Console. Importing migrated policies You can import two basic types of policies, Firewall and Intrusion Prevention. To import migrated policies 1 Log on to the Symantec Endpoint Protection Manager Console. 2 Click Policies. 3 Do one of the following Under View Policies, click Firewall. Under View Policies, click Intrusion Prevention. 4 Do one of the following: Under Tasks, click Import a Firewall Policy. Under Tasks, click Import an Intrusion Prevention Policy. 5 In the Import Policy dialog box, browse to and select a migrated policy in your working directory. 6 In the right pane, click on and highlight the imported policy. 7 Under Tasks, click Edit the Policy and review the migrated policy.