Field notes on firewall migration, Zero Trust, and the parts of network security that only show up once traffic is flowing.
Written by Roman Dmytriv — network security engineer, CISSP. Two decades securing and modernizing enterprise networks.
"Never trust, always verify" assumes you can answer who or what is on the wire. Service accounts, machine identity, and stale directories are where Zero Trust programs actually stall — not the architecture.
July 2026A full PAN-OS NAT reference with diagrams — DIPP, dynamic IP, static source and destination NAT, dynamic DNAT, combined, U-turn, bidirectional, and no-NAT — each mapped to the Cisco ASA construct it converts from.
June 2026Installing the agents and watching traffic is the easy part. What stalls the project is labeling, application ownership, and a CMDB that turns out to be fiction — none of it a technology problem.
May 2026Every long-lived firewall accumulates rules that never fire. Some are harmless bloat; one kind quietly undoes your security policy. How to find each — and why you can't do it with a text diff.
April 2026Addresses and services look trivial to migrate — until nested groups, mixed-protocol service objects, and the port-vs-App-ID fork turn the simple part into the part that breaks your rules.
March 2026The syntax you can look up. The conceptual leap — from interface-and-security-level to zone-based policy, with different defaults — is what silently breaks traffic after a cutover.
February 2026Conversion tools translate the syntax. The failures that page you at 2 a.m. come from how the two platforms evaluate NAT against security policy — and they don't show up until traffic is flowing.