Understand before converting
Map interfaces, zones, routing, NAT, VPNs, rules, objects, management and HA before building the target.
Damocles Firewall Migration & Implementation combines current-state discovery, target design, rule and object mapping, NAT and routing analysis, change sequencing, rollback planning, implementation support and post-change validation.
A firewall migration can reproduce the existing policy perfectly and still preserve stale access, unsafe architecture and undocumented dependencies. It can also fail operationally if NAT, routing, HA, VPNs, management and application cutover are treated as separate details.
Damocles uses the migration as an opportunity to understand required flows, remove avoidable policy debt and design a controlled transition to the new platform with explicit rollback and validation.
Map interfaces, zones, routing, NAT, VPNs, rules, objects, management and HA before building the target.
Separate required access from stale, duplicate and risky policy that should not be copied forward.
Define sequence, dependencies, rollback and validation so production impact is managed rather than improvised.
The statement of work identifies devices, contexts, interfaces, routing, NAT, VPNs, rule counts, HA, sites and cutover expectations.
Interfaces, zones, routes, NAT, rules, objects, VPNs, HA and management configuration.
Critical application, user, service, management and third-party flows the migration must preserve or intentionally change.
Target interfaces, zones, routing, policy structure, management and resilient design.
Translation of source rules and objects to the target with cleanup and redesign decisions recorded.
Translations, default routes, dynamic routing and path dependencies affecting cutover.
Peer configuration, failover, state synchronisation, upstream dependencies and maintenance behaviour.
Review the source policy, target design and migration controls so required connectivity is preserved while stale, excessive or mistranslated access is identified.
Current rules, objects, routing and known dependencies.
Zones, interfaces, routing and intended enforcement points.
Accurate conversion of services, objects and policy behaviour.
Stale, duplicate and excessive access before migration.
Administrative identity, access and secure configuration.
Representative allowed and denied traffic paths.
Practical restoration steps and decision points.
Logging, monitoring, documentation and ownership.
These are governed procedures from the service assurance profile—not generic marketing categories. The complete matrix below records applicability, access requirements and limitations for every coverage area.
Damocles captures the source platform configuration, software state, interfaces, dependencies and change baseline using native exports.
Damocles maps every in-scope source zone and interface to the target construct and records semantic or platform differences.
Damocles translates and reconciles network, service and identity objects and groups, resolving duplicates and unsupported forms.
Damocles compares source and target rules, preserving required intent while documenting removed, consolidated or changed entries.
Damocles translates source and destination NAT and validates the resulting address, port, zone and published-service behaviour.
Damocles maps static and dynamic routing, policy routes and dependencies and checks target convergence assumptions.
Showing 6 representative areas. The full governed matrix contains 14 coverage areas.
References are shown according to the role they play in the engagement. Methodologies guide testing, taxonomies classify findings, severity methods support consistent scoring, and control mappings connect scoped evidence to broader assurance work.
Testing is structured by the governed service profile and the procedures expressly included in the authorised scope.
Findings are reported against the governed service coverage and customer impact. Separate classification references are shown only where they are part of the approved profile.
The engagement produces point-in-time technical evidence about the configured and observed security behaviour within the authorised Firewall migration and implementation scope.
A reviewed target policy, migration risk register, cutover validation record and prioritised follow-up actions.
What this means: technical evidence may support risk, compliance and audit activity where the mapping is applicable. It does not by itself certify the organisation, establish complete compliance or assess controls outside the authorised scope.
Damocles reconciles current and proposed configurations, traces translated zones, objects, rules, NAT, routing and VPNs, and observes approved pre-cutover, cutover and rollback checks. Review does not authorise implementation, and production changes occur only under the customer change plan.
Directly assessed means the engagement tests the relevant behaviour. Supporting evidence means the result can contribute to a broader control assessment. Contextual references explain relevance without claiming that the control was tested.
Captures and reconciles the source firewall configuration, dependencies and observed service intent.
Reviews translated zones, objects, rules, NAT, routing, VPN and management settings against the source.
Defines acceptance checks, cutover stop conditions and restoration steps and records their execution.
| Coverage area | What Damocles tests | Perspective and access | Evidence produced | References and limits |
|---|---|---|---|---|
| Current-state configuration capture | Damocles captures the source platform configuration, software state, interfaces, dependencies and change baseline using native exports. | Validation and rollback owner Current configuration export or read-only access, diagrams, owners and representative validation endpoints; customer inputs must identify the approved current-state configuration capture targets and expected behaviour. | Configuration excerpts, object or rule identifiers and observed validation results; the record names the tested current-state configuration capture object, path or control and its observed result. | Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 Applicability: Performed when current configuration evidence and a representative endpoint or device are included in the review. Limit: A configuration snapshot cannot prove continuous enforcement across excluded nodes; validation avoids changes unless implementation work is authorised. |
| Zone and interface translation | Damocles maps every in-scope source zone and interface to the target construct and records semantic or platform differences. | Current-state reviewer Assessment requires source and target exports, translation records, topology, owners, test plan, change window and rollback artefacts, selected specifically for zone and interface translation. | Evidence records the configuration comparison, translated object or rule, test result, decision record or change evidence relevant to zone and interface translation. | Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 Applicability: Applies to Zone and interface translation when the migration component and assurance stage are included. Limit: The conclusion is limited to the sampled zone and interface translation; review does not authorise implementation and live outcomes are claimed only when observed. |
| Object and group translation | Damocles translates and reconciles network, service and identity objects and groups, resolving duplicates and unsupported forms. | Current-state reviewer Assessment requires source and target exports, translation records, topology, owners, test plan, change window and rollback artefacts, selected specifically for object and group translation. | Evidence records the configuration comparison, translated object or rule, test result, decision record or change evidence relevant to object and group translation. | Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 Applicability: Applies to Object and group translation when the migration component and assurance stage are included. Limit: The conclusion is limited to the sampled object and group translation; review does not authorise implementation and live outcomes are claimed only when observed. |
| Rulebase rationalisation | Damocles compares source and target rules, preserving required intent while documenting removed, consolidated or changed entries. | Validation and rollback owner Assessment requires source and target exports, translation records, topology, owners, test plan, change window and rollback artefacts, selected specifically for rulebase rationalisation. | Evidence records the configuration comparison, translated object or rule, test result, decision record or change evidence relevant to rulebase rationalisation. | Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 Applicability: Applies to Rulebase rationalisation when the migration component and assurance stage are included. Limit: The conclusion is limited to the sampled rulebase rationalisation; review does not authorise implementation and live outcomes are claimed only when observed. |
| NAT translation | Damocles translates source and destination NAT and validates the resulting address, port, zone and published-service behaviour. | Current-state reviewer Assessment requires source and target exports, translation records, topology, owners, test plan, change window and rollback artefacts, selected specifically for nat translation. | Evidence records the configuration comparison, translated object or rule, test result, decision record or change evidence relevant to nat translation. | Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 Applicability: Applies to NAT translation when the migration component and assurance stage are included. Limit: The conclusion is limited to the sampled nat translation; review does not authorise implementation and live outcomes are claimed only when observed. |
| Routing and dynamic protocols | Damocles maps static and dynamic routing, policy routes and dependencies and checks target convergence assumptions. | Validation and rollback owner Named source and destination test points, expected flow matrix and a safe test window. | Source-to-destination results linked to rule, route or boundary evidence; the record names the tested routing and dynamic protocols object, path or control and its observed result. | Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 Applicability: Performed when both ends of the network path and the enforcing device are owned or expressly authorised for testing. Limit: Results cover the tested source, destination, protocol and route; testing stops on instability and does not authorise third-party or denial-of-service activity. |
| VPN migration | Damocles translates VPN peers, identities, selectors, cryptography, routing and monitoring and records interoperability dependencies. | Current-state reviewer Current configuration export or read-only access, diagrams, owners and representative validation endpoints. | Configuration excerpts, object or rule identifiers and observed validation results; the record names the tested vpn migration object, path or control and its observed result. | Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 Applicability: Performed when both ends of the network path and the enforcing device are owned or expressly authorised for testing. Limit: Results cover the tested source, destination, protocol and route; testing stops on instability and does not authorise third-party or denial-of-service activity. |
| Management-plane hardening | Damocles reviews target management interfaces, AAA, administrator roles, protocols and permitted management sources. | Validation and rollback owner Current configuration export or read-only access, diagrams, owners and representative validation endpoints. | Configuration excerpts, object or rule identifiers and observed validation results; the record names the tested management-plane hardening object, path or control and its observed result. | Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 Applicability: Performed when current configuration evidence and a representative endpoint or device are included in the review. Limit: A configuration snapshot cannot prove continuous enforcement across excluded nodes; validation avoids changes unless implementation work is authorised. |
| Logging integration | Damocles maps source logging and event fields to target destinations, parsers, alerts and operational ownership. | Validation and rollback owner Log-source inventory, representative event identifiers, workflow records and responsible contacts. | Source-health state, event timestamps, investigation timeline and linked action or escalation record. | Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 Applicability: Performed when the relevant telemetry and analyst or customer workflow can be observed during the review window. Limit: Absent or delayed telemetry prevents a detection conclusion, and observation of one event cannot prove continuous detection of all attacks. |
| High-availability configuration | Damocles reviews target HA peers, interfaces, state synchronisation, monitored paths and failure behaviour. | Validation and rollback owner Architecture, dependency list, monitoring view, authorised failover window and rollback owner. | The relevant configuration excerpt or rule identifier, the expected setting and the observed validation result. | Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 Applicability: Performed only when a customer-approved recovery or failover scenario, observer and rollback window are available. Limit: The result covers the exercised failure mode; activity stops at the rollback threshold and does not predict every compound failure. |
| Pre-cutover validation | Damocles executes or reviews the approved pre-cutover test plan against staged configuration and representative flows. | Current-state reviewer Assessment requires source and target exports, translation records, topology, owners, test plan, change window and rollback artefacts, selected specifically for pre-cutover validation. | Evidence records the configuration comparison, translated object or rule, test result, decision record or change evidence relevant to pre-cutover validation. | Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 Applicability: Applies to Pre-cutover validation when the migration component and assurance stage are included. Limit: The conclusion is limited to the sampled pre-cutover validation; review does not authorise implementation and live outcomes are claimed only when observed. |
| Cutover sequencing | Damocles checks the ordered cutover plan, dependencies, decision points, communications and acceptance evidence. | Current-state reviewer Assessment requires source and target exports, translation records, topology, owners, test plan, change window and rollback artefacts, selected specifically for cutover sequencing. | Evidence records the configuration comparison, translated object or rule, test result, decision record or change evidence relevant to cutover sequencing. | Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 Applicability: Applies to Cutover sequencing when the migration component and assurance stage are included. Limit: The conclusion is limited to the sampled cutover sequencing; review does not authorise implementation and live outcomes are claimed only when observed. |
| Rollback criteria | Damocles verifies measurable rollback triggers, decision authority, restoration artefacts and source-platform readiness. | Current-state reviewer Assessment requires source and target exports, translation records, topology, owners, test plan, change window and rollback artefacts, selected specifically for rollback criteria. | Evidence records the configuration comparison, translated object or rule, test result, decision record or change evidence relevant to rollback criteria. | Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 Applicability: Applies to Rollback criteria when the migration component and assurance stage are included. Limit: The conclusion is limited to the sampled rollback criteria; review does not authorise implementation and live outcomes are claimed only when observed. |
| Post-cutover verification | Damocles records post-cutover configuration comparison, representative flow results, logging, monitoring and unresolved variance. | Current-state reviewer Assessment requires source and target exports, translation records, topology, owners, test plan, change window and rollback artefacts, selected specifically for post-cutover verification. | Evidence records the configuration comparison, translated object or rule, test result, decision record or change evidence relevant to post-cutover verification. | Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 Applicability: Applies to Post-cutover verification when the migration component and assurance stage are included. Limit: The conclusion is limited to the sampled post-cutover verification; review does not authorise implementation and live outcomes are claimed only when observed. |
| Framework and controls | Mapping type | What Damocles assesses | Evidence produced | Applicability and limits |
|---|---|---|---|---|
| Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 Framework-level context | Contextual | The engagement produces point-in-time technical evidence about the configured and observed security behaviour within the authorised Firewall migration and implementation scope. | Coverage status, procedure results and findings can inform the customer’s control assessment and risk treatment records. | Applies: Framework-level context is provided when the customer uses NIST SP 800-53 to organise its security control program. Limit: No individual NIST control is published as verified; organisational implementation, continuous operation, governance and complete catalogue coverage remain outside the engagement. |
Assurance boundary: Damocles maps assessed coverage and observations to agreed objectives as traceable technical evidence. The review is not a certification, does not establish complete compliance, and does not confirm controls outside the authorised scope.
Records authorised scope and rules of engagement produced from the authorised Firewall migration and implementation work.
Records coverage matrix produced from the authorised Firewall migration and implementation work.
Records retest and residual-risk record produced from the authorised Firewall migration and implementation work.
Records configuration translation matrix produced from the authorised Firewall migration and implementation work.
Records cutover validation record produced from the authorised Firewall migration and implementation work.
Records rollback readiness record produced from the authorised Firewall migration and implementation work.
A reviewed target policy, migration risk register, cutover validation record and prioritised follow-up actions.
The design and cutover account for both policy correctness and network behaviour.
Stale, duplicate or over-broad access migrated because conversion is treated as a mechanical task.
Translation order or semantics changing application reachability or security policy behaviour.
Asymmetric traffic, dynamic routing or default-path changes that break sessions or bypass expected inspection.
Site-to-site or remote-access dependencies omitted from the migration plan.
Target failover behaviour, links or upstream dependencies not validated before production use.
No realistic path back when a critical application or route fails during cutover.
The engagement can be design-only, migration build, cutover support or end-to-end delivery.
Current-state discovery, target architecture, mapping, cleanup decisions and cutover plan.
Prepare approved target configuration and migration artefacts for implementation.
Support or perform the approved production transition, validation and rollback decisions.
Design, build, implementation, validation and handover under one controlled engagement.
The exact artefacts depend on platform and scope.
Source interfaces, zones, routing, NAT, VPNs, policy and dependencies.
Approved target firewall, zone, routing, policy, management and HA design.
Rule, object, NAT and service mapping with cleanup and redesign decisions.
Detailed sequence, owners, maintenance window, validation checkpoints and decision gates.
Practical restoration path and triggers for stopping or reversing the migration.
Post-change routing, application, policy, VPN, management and failover test results.
Where Damocles performs the migration, approved production changes are executed within the agreed maintenance window with configuration backups, decision points, validation and rollback controls.
Post-cutover work records unresolved exceptions and any follow-up tuning or cleanup required after stable operation is confirmed.
Application remediation, carrier changes, unrelated switching/routing upgrades and identity redesign are included only where explicitly part of the migration program.
Unknown or undocumented dependencies discovered during delivery are assessed before scope or cutover assumptions are changed.
We will define discovery, design, mapping, configuration, implementation, rollback, validation and handover responsibilities.