Roman Dmytriv

Network security, from the config up.

Field notes on firewall migration, Zero Trust, and the parts of network security that only show up once traffic is flowing.

Written by Roman Dmytriv — network security engineer, CISSP. Two decades securing and modernizing enterprise networks.

Writing

August 2026

Zero Trust's hardest problem is identity

"Never trust, always verify" assumes you can answer who or what is on the wire. Service accounts, machine identity, and stale directories are where Zero Trust programs actually stall — not the architecture.

zero-trustidentityarchitecture
July 2026

Every Palo Alto NAT type, and the ASA construct it maps from

A full PAN-OS NAT reference with diagrams — DIPP, dynamic IP, static source and destination NAT, dynamic DNAT, combined, U-turn, bidirectional, and no-NAT — each mapped to the Cisco ASA construct it converts from.

referencepan-osnat
June 2026

What actually makes Illumio micro-segmentation hard

Installing the agents and watching traffic is the easy part. What stalls the project is labeling, application ownership, and a CMDB that turns out to be fiction — none of it a technology problem.

micro-segmentationillumiozero-trust
May 2026

Finding shadowed, redundant, and unreachable firewall rules

Every long-lived firewall accumulates rules that never fire. Some are harmless bloat; one kind quietly undoes your security policy. How to find each — and why you can't do it with a text diff.

hygienerulesaudit
April 2026

Translating ASA object-groups to PAN-OS

Addresses and services look trivial to migrate — until nested groups, mixed-protocol service objects, and the port-vs-App-ID fork turn the simple part into the part that breaks your rules.

migrationpan-osobjects
March 2026

Zones vs. interfaces: the mental shift from ASA to PAN-OS

The syntax you can look up. The conceptual leap — from interface-and-security-level to zone-based policy, with different defaults — is what silently breaks traffic after a cutover.

migrationpan-oszones
February 2026

What breaks when you migrate ASA NAT to PAN-OS

Conversion tools translate the syntax. The failures that page you at 2 a.m. come from how the two platforms evaluate NAT against security policy — and they don't show up until traffic is flowing.

migrationpan-osnat