Field notes on firewall migration, Zero Trust, and the parts of network security that only show up once traffic is flowing.
Written by Roman Dmytriv — network security engineer, CISSP. Two decades securing and modernizing enterprise networks.
Every long-lived firewall accumulates rules that never fire. Some are harmless bloat; one kind quietly undoes your security policy. How to find each — and why you can't do it with a text diff.
2026Addresses and services look trivial to migrate — until nested groups, mixed-protocol service objects, and the port-vs-App-ID fork turn the simple part into the part that breaks your rules.
2026The syntax you can look up. The conceptual leap — from interface-and-security-level to zone-based policy, with different defaults — is what silently breaks traffic after a cutover.
2026Conversion tools translate the syntax. The failures that page you at 2 a.m. come from how the two platforms evaluate NAT against security policy — and they don't show up until traffic is flowing.