Roman Dmytriv

Network security, from the config up.

Field notes on firewall migration, Zero Trust, and the parts of network security that only show up once traffic is flowing.

Written by Roman Dmytriv — network security engineer, CISSP. Two decades securing and modernizing enterprise networks.

Writing

2026

Finding shadowed, redundant, and unreachable firewall rules

Every long-lived firewall accumulates rules that never fire. Some are harmless bloat; one kind quietly undoes your security policy. How to find each — and why you can't do it with a text diff.

hygienerulesaudit
2026

Translating ASA object-groups to PAN-OS

Addresses and services look trivial to migrate — until nested groups, mixed-protocol service objects, and the port-vs-App-ID fork turn the simple part into the part that breaks your rules.

migrationpan-osobjects
2026

Zones vs. interfaces: the mental shift from ASA to PAN-OS

The syntax you can look up. The conceptual leap — from interface-and-security-level to zone-based policy, with different defaults — is what silently breaks traffic after a cutover.

migrationpan-oszones
2026

What breaks when you migrate ASA NAT to PAN-OS

Conversion tools translate the syntax. The failures that page you at 2 a.m. come from how the two platforms evaluate NAT against security policy — and they don't show up until traffic is flowing.

migrationpan-osnat