{"id":20779,"date":"2026-01-18T03:16:26","date_gmt":"2026-01-17T18:16:26","guid":{"rendered":"https:\/\/aireviewirush.com\/?p=20779"},"modified":"2026-01-18T03:16:26","modified_gmt":"2026-01-17T18:16:26","slug":"navigating-firewall-migrations-greatest-practices-and-palo-alto-to-cisco-subsequent-gen-firewall-specifics","status":"publish","type":"post","link":"https:\/\/aireviewirush.com\/?p=20779","title":{"rendered":"Navigating Firewall Migrations: Greatest Practices and Palo Alto to Cisco Subsequent-Gen Firewall Specifics"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p>Migrating firewalls generally is a advanced endeavor, typically involving intricate insurance policies, essential purposes, and the necessity for seamless transition. This publish distills key insights from skilled architects on greatest practices for any firewall migration, after which dives into the distinctive concerns when transferring from Palo Alto Networks to Cisco Subsequent-Technology Firewalls.<\/p>\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_53 counter-hierarchy ez-toc-counter ez-toc-grey ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title \" >Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><a href=\"#\" class=\"ez-toc-pull-right ez-toc-btn ez-toc-btn-xs ez-toc-btn-default ez-toc-toggle\" aria-label=\"Toggle Table of Content\" role=\"button\"><label for=\"item-6a28b98de96c0\" ><span class=\"\"><span style=\"display:none;\">Toggle<\/span><span class=\"ez-toc-icon-toggle-span\"><svg style=\"fill: #999;color:#999\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"list-377408\" width=\"20px\" height=\"20px\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M6 6H4v2h2V6zm14 0H8v2h12V6zM4 11h2v2H4v-2zm16 0H8v2h12v-2zM4 16h2v2H4v-2zm16 0H8v2h12v-2z\" fill=\"currentColor\"><\/path><\/svg><svg style=\"fill: #999;color:#999\" class=\"arrow-unsorted-368013\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"10px\" height=\"10px\" viewBox=\"0 0 24 24\" version=\"1.2\" baseProfile=\"tiny\"><path d=\"M18.2 9.3l-6.2-6.3-6.2 6.3c-.2.2-.3.4-.3.7s.1.5.3.7c.2.2.4.3.7.3h11c.3 0 .5-.1.7-.3.2-.2.3-.5.3-.7s-.1-.5-.3-.7zM5.8 14.7l6.2 6.3 6.2-6.3c.2-.2.3-.5.3-.7s-.1-.5-.3-.7c-.2-.2-.4-.3-.7-.3h-11c-.3 0-.5.1-.7.3-.2.2-.3.5-.3.7s.1.5.3.7z\"\/><\/svg><\/span><\/span><\/label><input aria-label=\"Toggle\" aria-label=\"item-6a28b98de96c0\"  type=\"checkbox\" id=\"item-6a28b98de96c0\"><\/a><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/aireviewirush.com\/?p=20779\/#Part_0_The_Background\" title=\"Part 0: The Background\">Part 0: The Background<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/aireviewirush.com\/?p=20779\/#Part_1_Basic_Firewall_Migration_Greatest_Practices\" title=\"Part 1: Basic Firewall Migration Greatest Practices\">Part 1: Basic Firewall Migration Greatest Practices<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/aireviewirush.com\/?p=20779\/#Part_2_Key_Variations_and_Migration_Methods_from_Palo_Alto_to_Cisco_Subsequent-Technology_Firewalls\" title=\"Part 2: Key Variations and Migration Methods from Palo Alto to Cisco Subsequent-Technology Firewalls\">Part 2: Key Variations and Migration Methods from Palo Alto to Cisco Subsequent-Technology Firewalls<\/a><\/li><\/ul><\/nav><\/div>\n<h2><span class=\"ez-toc-section\" id=\"Part_0_The_Background\"><\/span>Part 0: The Background<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Buyer management has determined emigrate from PAN to Cisco.\u00a0 This was a enterprise determination based mostly on elevated costs by PAN.\u00a0 In contrast to many firewall migration initiatives CX helps, this engagement had the next complicating components:<\/p>\n<ol>\n<li>Lack of current-state documentation.<\/li>\n<li>Lack of information of present identification answer. Extra particularly, we recognized (with effort) that there was a must make Cisco &amp; PAN co-exist due to many cases of identity-based firewall enforcement.<img loading=\"lazy\" decoding=\"async\" class=\"lazy lazy-hidden aligncenter size-full wp-image-484119\" data-lazy-type=\"image\" src=\"https:\/\/blogs.cisco.com\/gcs\/ciscoblogs\/1\/2026\/01\/Palo-Alto-1.png\" alt=\"\" width=\"936\" height=\"686\"><noscript><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-484119\" src=\"https:\/\/blogs.cisco.com\/gcs\/ciscoblogs\/1\/2026\/01\/Palo-Alto-1.png\" alt=\"\" width=\"936\" height=\"686\"><\/noscript><\/li>\n<li>Lack of information of firewall historical past (i.e. WHY is there a firewall right here\/what community segments want isolation).<\/li>\n<li>Lack of information\/documentation of applications-and how\/the place the firewall coverage helps the purposes.<\/li>\n<li>24\/7 setting: There isn&#8217;t a \u2018after-hours\u2019 so each migration effort required important planning.<\/li>\n<\/ol>\n<h2><span class=\"ez-toc-section\" id=\"Part_1_Basic_Firewall_Migration_Greatest_Practices\"><\/span>Part 1: Basic Firewall Migration Greatest Practices<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>A profitable firewall migration hinges on meticulous planning, thorough execution, and diligent post-migration actions.\u00a0 There isn&#8217;t a device that may exchange good practices and this part\u2019s intent is to organize an engineer with expertise required to avoid wasting one\u2019s sanity:<\/p>\n<p><strong>1. Complete Prep Work:<\/strong><\/p>\n<ul>\n<li><strong>Pre-migration Cleanup &amp; Optimization:<\/strong>\u00a0Earlier than you even take into consideration transferring, clear up your current firewall. This contains analyzing rule and NAT hit-counts to establish unused or redundant insurance policies, and performing object de-duplication to streamline configurations.\u00a0 Would you progress homes with out first decluttering and throwing away trash?\u00a0 If not, why would you progress stale or irrelevant firewall coverage?\u00a0 A great greatest observe is to make this one thing the shopper is liable for.\u00a0 Like transferring, you&#8217;ll be able to\u2019t declutter indefinitely, so guarantee there&#8217;s a timeline to which the shopper is held accountable to.<\/li>\n<li><strong>Change Administration:<\/strong>\u00a0Ideally, implement a configuration freeze on the supply firewall. If not doable, set up sturdy change monitoring to copy any new guidelines or modifications throughout each the previous and new firewalls.<\/li>\n<li><strong>Stakeholder Engagement:<\/strong>\u00a0Determine all mission-critical purposes and their key stakeholders. Their enter is essential for understanding visitors flows and validating post-migration performance.<\/li>\n<li><strong>Documentation is King:<\/strong>\n<ul>\n<li>Develop an in depth\u00a0<strong>Methodology of Process (MOP)<\/strong>: Define each step, together with whether or not you\u2019ll carry out a \u2018exhausting\u2019 cutover or an incremental\/phased migration. Embody clear time goals.<\/li>\n<li>Conduct\u00a0<strong>Peer Critiques:<\/strong>\u00a0Have a number of eyes in your MOP and configurations.<\/li>\n<li>Create a\u00a0<strong>Thorough Take a look at Plan:<\/strong>\u00a0This isn\u2019t nearly testing purposes; it\u2019s about testing your\u00a0<em>take a look at plan<\/em>\u00a0itself. Guarantee it covers all essential functionalities and edge instances.<\/li>\n<li>Design a\u00a0<strong>Rollback Plan:<\/strong> At all times have a transparent technique to revert to the earlier state if points come up.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p><strong>2. Flawless Migration Execution:<\/strong><\/p>\n<ul>\n<li><strong>Conduct a \u2018Dry-Run\u2019:<\/strong>\u00a0If doable, simulate the migration in a take a look at setting to establish potential points earlier than the precise cutover.<\/li>\n<li><strong>Validate ARP Tables:<\/strong>\u00a0Test ARP tables each earlier than and after the migration to make sure correct community connectivity.<\/li>\n<li><strong>Optimize Crucial Visitors:<\/strong>\u00a0Develop pre-filters or \u2018fastpath\u2019 guidelines for essential purposes to make sure their efficiency isn\u2019t impacted.<\/li>\n<li><strong>Pre-stage Monitoring Instruments:<\/strong>\u00a0Put together customized searches and packet captures prematurely to shortly diagnose points throughout the migration.<\/li>\n<li><strong>On-Name Assist:<\/strong>\u00a0Have software testers and homeowners available or on a devoted name throughout the migration window.\u00a0 Necessary observe: These MAY NOT be the identical folks.\u00a0 Usually, we got testers, who lacked any understanding of how the appliance labored.\u00a0 Guarantee it&#8217;s nicely documented the place this expertise lives.\u00a0 Supply\/vacation spot IPs &amp; L4 ports-who is aware of these low-level particulars?<\/li>\n<li style=\"list-style-type: none;\"\/>\n<\/ul>\n<p><strong>3. Publish-Migration Actions for Stability &amp; Optimization:<\/strong><\/p>\n<ul>\n<li><strong>Assessment Publish-Migration Stories:<\/strong>\u00a0Completely analyze any studies generated by migration instruments to establish and tackle lingering points.<\/li>\n<li><strong>Replace Documentation:<\/strong>\u00a0Guarantee all community diagrams, coverage paperwork, and operational procedures are up to date to mirror the brand new firewall configuration.<\/li>\n<li><strong>Steady Monitoring:<\/strong>\u00a0Implement sturdy monitoring to trace efficiency, safety occasions, and potential anomalies.<\/li>\n<li><strong>Coaching and Assist:<\/strong>\u00a0Educate your operations group on the brand new platform and its administration.<\/li>\n<li><strong>Ongoing Optimization:<\/strong>\u00a0Firewall insurance policies aren&#8217;t static. Frequently evaluate and optimize guidelines to keep up effectivity and safety posture.<\/li>\n<\/ul>\n<p><strong>Finish-to-Finish Migration Process (Basic Steps):<\/strong><\/p>\n<ol>\n<li>Obtain and launch the migration device.<\/li>\n<li>Export the supply firewall\u2019s configuration file.<\/li>\n<li>Assessment the pre-migration report.<\/li>\n<li>Map interfaces, safety zones, and interface teams.<\/li>\n<li>Map configurations with purposes.<\/li>\n<li>Specify vacation spot parameters and choose options for migration.<\/li>\n<li>Optimize, evaluate, and validate the migrated configuration.<\/li>\n<li>Push the migrated configuration to the brand new firewall\u2019s administration middle (e.g., FMC).<\/li>\n<li>Deploy the configuration to the firewall.<\/li>\n<li>Obtain and evaluate the post-migration report.<\/li>\n<li>Configure any further handbook objects.<\/li>\n<\/ol>\n<h2><span class=\"ez-toc-section\" id=\"Part_2_Key_Variations_and_Migration_Methods_from_Palo_Alto_to_Cisco_Subsequent-Technology_Firewalls\"><\/span>Part 2: Key Variations and Migration Methods from Palo Alto to Cisco Subsequent-Technology Firewalls<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Migrating from Palo Alto Networks to Cisco Safe Firewall brings its personal set of nuances, notably regarding identification integration, coverage conversion, and platform-specific capabilities.<\/p>\n<ol>\n<li><strong> Id Coexistence Throughout Migration:<\/strong><\/li>\n<\/ol>\n<p>A big problem is guaranteeing person identification mappings (e.g., \u201cLisa is 10.14.10.7\u201d) are constant throughout each Palo Alto and Cisco firewalls throughout the interim migration interval.<\/p>\n<ul>\n<li><strong>The Drawback:<\/strong>\u00a0Cisco wants to pay attention to user-to-IP mappings that Palo Alto\u2019s Person-ID brokers or VPN gateways already know. With out this, visitors from recognized customers may be denied by the Cisco firewall as a result of it lacks the mandatory context.<\/li>\n<li><strong>Options Explored:<\/strong>\n<ul>\n<li><strong>Devoted ISE-PIC Deployment:<\/strong>\u00a0Whereas tried, utilizing an current ISE deployment for this objective will be problematic, particularly since PassiveID is incompatible with 802.1x Machine Authentication. Word: ISE-PIC has reached Finish-of-Life.<\/li>\n<li><strong>Syslog Forwarding:<\/strong> A viable technique entails configuring the Palo Alto VPN firewall to ahead Syslog messages containing user-to-IP mappings to Cisco ISE.<\/li>\n<li><strong>Energetic Listing Brokers:<\/strong> Deploying brokers on Energetic Listing servers or terminal servers will help each platforms collect identification info.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>By together with a mixture of syslog forwarding on the PAN VPN firewall and new Cisco brokers on the shopper AD servers, we had been in a position to migrate a downstream PAN firewall to Cisco.<\/p>\n<p>Ought to customers be coming from on-premise (passive authentication) or by way of remote-access VPN, the Cisco firewall may have a user-&gt;IP mapping to verify the suitable firewall coverage is being matched.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"lazy lazy-hidden aligncenter size-full wp-image-484120\" data-lazy-type=\"image\" src=\"https:\/\/blogs.cisco.com\/gcs\/ciscoblogs\/1\/2026\/01\/Palo-Alto-2.png\" alt=\"\" width=\"610\" height=\"296\"><noscript><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-484120\" src=\"https:\/\/blogs.cisco.com\/gcs\/ciscoblogs\/1\/2026\/01\/Palo-Alto-2.png\" alt=\"\" width=\"610\" height=\"296\"><\/noscript><\/p>\n<p>As of Firewall Administration Middle 7.6, the passive ID performance is offered instantly with out the necessity for ISE-PIC (which went EOL on 5\/5\/2025).<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"lazy lazy-hidden aligncenter size-full wp-image-484121\" data-lazy-type=\"image\" src=\"https:\/\/blogs.cisco.com\/gcs\/ciscoblogs\/1\/2026\/01\/Palo-Alto-3.jpg\" alt=\"\" width=\"595\" height=\"598\"><noscript><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-484121\" src=\"https:\/\/blogs.cisco.com\/gcs\/ciscoblogs\/1\/2026\/01\/Palo-Alto-3.jpg\" alt=\"\" width=\"595\" height=\"598\"><\/noscript><\/p>\n<p><strong>2. Coverage Conversion with the Safe Firewall Migration Software:<\/strong><\/p>\n<p>The Cisco Safe Firewall migration device is designed to help with this transition, however understanding its capabilities and limitations is vital.<\/p>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li><strong>Extraction &amp; Mixture:<\/strong>\u00a0The device can extract and mix Palo Alto configurations, figuring out parts like Entry Management guidelines, Community\/Port objects, Interfaces, Routes, and Functions.<\/li>\n<li><strong>Function Choice:<\/strong>\u00a0You&#8217;ll be able to choose which parts of the configuration (e.g., Interfaces, Routes, Entry Management) emigrate.<\/li>\n<li><strong>Software Mapping:<\/strong>\u00a0It\u2019s essential to resolve any clean or invalid software mappings. In some instances, you may want so as to add port-based equivalents if a direct software mapping isn\u2019t out there. Assets like Cisco AppID and Palo Alto\u2019s Applipedia will help.<\/li>\n<li><strong>Bulk Actions &amp; Optimization:<\/strong>\u00a0The device facilitates bulk actions and permits for ACL optimization, however keep in mind to pre-stage File and IPS insurance policies within the Cisco Firepower Administration Middle (FMC).<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p><strong> <img loading=\"lazy\" decoding=\"async\" class=\"lazy lazy-hidden alignright size-medium wp-image-484122\" data-lazy-type=\"image\" src=\"https:\/\/blogs.cisco.com\/gcs\/ciscoblogs\/1\/2026\/01\/Palo-Alto-4-300x226.png\" alt=\"\" width=\"300\" height=\"226\"><noscript><img loading=\"lazy\" decoding=\"async\" class=\"alignright size-medium wp-image-484122\" src=\"https:\/\/blogs.cisco.com\/gcs\/ciscoblogs\/1\/2026\/01\/Palo-Alto-4-300x226.png\" alt=\"\" width=\"300\" height=\"226\"><\/noscript>3. Palo Alto Configuration Limitations for Migration:<\/strong><\/p>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li><strong>PAN-OS Model:<\/strong>\u00a0The supply Palo Alto firewall have to be working PAN-OS software program model 8.0 or increased for the migration device to perform appropriately.<\/li>\n<li><strong>VSYS Migration:<\/strong>\u00a0The device helps migration of both single or multi-vsys configurations, that are sometimes merged with VRFs to attain segmentation in Cisco FTD.<\/li>\n<li><strong>System Configuration:<\/strong>\u00a0Crucial system configurations, akin to Platform Insurance policies (e.g., NTP, SSH entry) in FTD, are usually\u00a0<em>not<\/em>\u00a0migrated by the device and require handbook setup.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p><strong>4. Particular Challenges and Guide Configurations:<\/strong><\/p>\n<p>A number of parts require handbook consideration or have totally different implementations between the 2 platforms:<\/p>\n<ul>\n<li><strong>NAT IP and Port Oversubscription:<\/strong>\u00a0Palo Alto can deal with increased ranges of NAT oversubscription (e.g., 1x, 2x, 4x, 8x reuse of similar tackle\/port). When migrating to Cisco, you typically want to extend the PAT pool measurement to accommodate this.<\/li>\n<li><strong>URL Wildcards:<\/strong>\u00a0Palo Alto makes use of characters like\u00a0*\u00a0or\u00a0^\u00a0for URL wildcards, whereas Cisco sometimes helps substring matching (e.g.,\u00a0cisco.com\u00a0as an alternative of\u00a0*.cisco.com). These want adjustment.<\/li>\n<li><strong>Nested Object Teams:<\/strong>\u00a0Community and port object teams nested deeper than 10 ranges aren&#8217;t supported in Cisco FMC and can want flattening.<\/li>\n<li><strong>Id Realm\/Energetic Listing Integration:<\/strong>\u00a0Whereas newer variations of the migration device (FMT 7.7+) help AD\/Realm integration, you\u2019ll typically must manually add identification to relevant guidelines and pre-stage the Realm and AD configurations within the FMC.<\/li>\n<li><strong>NAT Supply Alternative:<\/strong>\u00a0Manually exchange NAT supply in Entry Management Coverage (ACP) guidelines with the NAT vacation spot (i.e., swap the translated tackle with the unique vacation spot).<\/li>\n<li><strong>Unmigrated Objects Requiring Guide Configuration:<\/strong>\n<ul>\n<li><strong>Time-based entry management guidelines.\u00a0 <\/strong>Cisco doesn&#8217;t <strong><em>presently <\/em><\/strong>help time-based entry management guidelines.<\/li>\n<li><strong>Id-based entry management guidelines:<\/strong>\u00a0You\u2019ll must explicitly affiliate identification teams or particular person identities.<\/li>\n<li><strong>FQDN objects:<\/strong>\u00a0Particularly these beginning with or containing particular characters. Wildcard FQDNs typically want substitute or updates.<\/li>\n<li><strong>URL Filtering Insurance policies:<\/strong>\u00a0Add the respective classes as insurance policies utilizing URL filtering may not translate instantly.<\/li>\n<li><strong>Software Mapping:<\/strong>\u00a0If a rule in Palo Alto used \u201csoftware default\u201d for service, it should seemingly be migrated as \u201cany\u201d service in Cisco, requiring handbook refinement.\u00a0 In some case we added port-based equivalents.<strong><img loading=\"lazy\" decoding=\"async\" class=\"lazy lazy-hidden aligncenter size-full wp-image-484124\" data-lazy-type=\"image\" src=\"https:\/\/blogs.cisco.com\/gcs\/ciscoblogs\/1\/2026\/01\/Palo-Alto-5.png\" alt=\"\" width=\"528\" height=\"514\"><noscript><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-484124\" src=\"https:\/\/blogs.cisco.com\/gcs\/ciscoblogs\/1\/2026\/01\/Palo-Alto-5.png\" alt=\"\" width=\"528\" height=\"514\"><\/noscript><\/strong><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li><strong>Negate Guidelines:<\/strong>\u00a0Palo Alto\u2019s \u201cenable X however exclude Y\u201d logic must be translated into express \u201cdeny\u201d guidelines in FTD.\u00a0 Cisco doesn&#8217;t <strong><em>presently <\/em><\/strong>help negate guidelines.\u00a0 This was completed by merely implementing a \u2018deny\u2019 rule in FTD.<\/li>\n<li><strong>Dynamic Routing:<\/strong>\u00a0Requires handbook configuration.\u00a0 This won&#8217;t be ported by way of the migration device.<\/li>\n<li><strong>Route Reflector:<\/strong>\u00a0Add FTD as an eBGP peer manually.\u00a0 Extra particularly, <strong>cisco doesn&#8217;t presently (as of this weblog posting) help iBGP route reflector configuration.\u00a0 <\/strong>This was overcome by manually configuring a brand new eBGP autonomous quantity for the firewall.\u00a0 This additionally required the extra configuration of \u2018allow-as in\u2019 as there have been cases the place route propagation hair pinned the firewall.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p><strong>5. Partially Supported, Ignored, or Disabled Objects:<\/strong><\/p>\n<p>Remember that sure configurations aren&#8217;t absolutely supported or are ignored throughout migration:<\/p>\n<ul>\n<li>Administration Settings (like NTP, SSH entry).<\/li>\n<li>Syslog Dynamic Routing.<\/li>\n<li>Service Insurance policies (these typically translate to FlexConfig in FTD).<\/li>\n<li>Distant-Entry VPN reserved IP addresses (require workarounds by way of ISE or AD).<\/li>\n<li>System-Particular Web site-to-Web site VPN configurations.<\/li>\n<li>Connection log settings.<\/li>\n<\/ul>\n<hr\/>\n<p>By adhering to normal greatest practices and understanding these particular variations when migrating from Palo Alto to Cisco Subsequent-Technology Firewalls, organizations can obtain a smoother, safer, and environment friendly transition.<\/p>\n<\/p><\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>Migrating firewalls generally is a advanced endeavor, typically involving intricate insurance policies, essential purposes, and the necessity for seamless transition. This publish distills key insights from skilled architects on greatest practices for any firewall migration, after which dives into the distinctive concerns when transferring from Palo Alto Networks to Cisco Subsequent-Technology Firewalls. Part 0: The [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":20781,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[20],"tags":[],"class_list":["post-20779","post","type-post","status-publish","format-standard","has-post-thumbnail","category-cloud-computing"],"_links":{"self":[{"href":"https:\/\/aireviewirush.com\/index.php?rest_route=\/wp\/v2\/posts\/20779","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/aireviewirush.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/aireviewirush.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/aireviewirush.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/aireviewirush.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=20779"}],"version-history":[{"count":1,"href":"https:\/\/aireviewirush.com\/index.php?rest_route=\/wp\/v2\/posts\/20779\/revisions"}],"predecessor-version":[{"id":20780,"href":"https:\/\/aireviewirush.com\/index.php?rest_route=\/wp\/v2\/posts\/20779\/revisions\/20780"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/aireviewirush.com\/index.php?rest_route=\/wp\/v2\/media\/20781"}],"wp:attachment":[{"href":"https:\/\/aireviewirush.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=20779"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/aireviewirush.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=20779"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/aireviewirush.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=20779"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}