Firewall migration and implementation

Move firewall platforms without blindly carrying years of policy debt into the new environment.

Damocles Firewall Migration & Implementation combines current-state discovery, target design, rule and object mapping, NAT and routing analysis, change sequencing, rollback planning, implementation support and post-change validation.

Current-state discoveryTarget architecture and rule mappingCutover and rollback planningPost-change validation
Why customers buy this service

Migrate firewall policy with security and connectivity intact.

A firewall migration can reproduce the existing policy perfectly and still preserve stale access, unsafe architecture and undocumented dependencies. It can also fail operationally if NAT, routing, HA, VPNs, management and application cutover are treated as separate details.

Damocles uses the migration as an opportunity to understand required flows, remove avoidable policy debt and design a controlled transition to the new platform with explicit rollback and validation.

01

Understand before converting

Map interfaces, zones, routing, NAT, VPNs, rules, objects, management and HA before building the target.

02

Clean policy during migration

Separate required access from stale, duplicate and risky policy that should not be copied forward.

03

Control the cutover

Define sequence, dependencies, rollback and validation so production impact is managed rather than improvised.

What we review

Source platform, target platform and all network/security dependencies needed for the approved migration.

The statement of work identifies devices, contexts, interfaces, routing, NAT, VPNs, rule counts, HA, sites and cutover expectations.

CS

Current-state configuration

Interfaces, zones, routes, NAT, rules, objects, VPNs, HA and management configuration.

TF

Traffic flows

Critical application, user, service, management and third-party flows the migration must preserve or intentionally change.

TA

Target architecture

Target interfaces, zones, routing, policy structure, management and resilient design.

MP

Rule and object mapping

Translation of source rules and objects to the target with cleanup and redesign decisions recorded.

NT

NAT and routing

Translations, default routes, dynamic routing and path dependencies affecting cutover.

HA

High availability

Peer configuration, failover, state synchronisation, upstream dependencies and maintenance behaviour.

Technical assurance

Move firewall policy without carrying forward avoidable risk.

Review the source policy, target design and migration controls so required connectivity is preserved while stale, excessive or mistranslated access is identified.

Source policy baseline

Current rules, objects, routing and known dependencies.

Target architecture

Zones, interfaces, routing and intended enforcement points.

Rule translation

Accurate conversion of services, objects and policy behaviour.

Policy cleanup

Stale, duplicate and excessive access before migration.

Management security

Administrative identity, access and secure configuration.

Cutover validation

Representative allowed and denied traffic paths.

Rollback and recovery

Practical restoration steps and decision points.

Operational handover

Logging, monitoring, documentation and ownership.

14governed test areas
3authorised testing perspectives
6controlled evidence outputs
1framework / control evidence mappings
What we actually test

Representative technical coverage with the evidence produced.

These are governed procedures from the service assurance profile—not generic marketing categories. The complete matrix below records applicability, access requirements and limitations for every coverage area.

Jump to full coverage matrix ↓
Coverage area

Current-state configuration capture

Damocles captures the source platform configuration, software state, interfaces, dependencies and change baseline using native exports.

Evidence producedConfiguration excerpts, object or rule identifiers and observed validation results; the record names the tested current-state configuration capture object, path or control and its observed result.
Framework references
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0
Coverage area

Zone and interface translation

Damocles maps every in-scope source zone and interface to the target construct and records semantic or platform differences.

Evidence producedEvidence records the configuration comparison, translated object or rule, test result, decision record or change evidence relevant to zone and interface translation.
Framework references
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0
Coverage area

Object and group translation

Damocles translates and reconciles network, service and identity objects and groups, resolving duplicates and unsupported forms.

Evidence producedEvidence records the configuration comparison, translated object or rule, test result, decision record or change evidence relevant to object and group translation.
Framework references
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0
Coverage area

Rulebase rationalisation

Damocles compares source and target rules, preserving required intent while documenting removed, consolidated or changed entries.

Evidence producedEvidence records the configuration comparison, translated object or rule, test result, decision record or change evidence relevant to rulebase rationalisation.
Framework references
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0
Coverage area

NAT translation

Damocles translates source and destination NAT and validates the resulting address, port, zone and published-service behaviour.

Evidence producedEvidence records the configuration comparison, translated object or rule, test result, decision record or change evidence relevant to nat translation.
Framework references
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0
Coverage area

Routing and dynamic protocols

Damocles maps static and dynamic routing, policy routes and dependencies and checks target convergence assumptions.

Evidence producedSource-to-destination results linked to rule, route or boundary evidence; the record names the tested routing and dynamic protocols object, path or control and its observed result.
Framework references
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0

Showing 6 representative areas. The full governed matrix contains 14 coverage areas.

Standards and assurance coverage

See how this engagement is structured, classified and mapped before opening the full evidence matrix.

References are shown according to the role they play in the engagement. Methodologies guide testing, taxonomies classify findings, severity methods support consistent scoring, and control mappings connect scoped evidence to broader assurance work.

01 · Test method

How testing is structured

Testing is structured by the governed service profile and the procedures expressly included in the authorised scope.

02 · Finding language

How weaknesses and severity are classified

Findings are reported against the governed service coverage and customer impact. Separate classification references are shown only where they are part of the approved profile.

03 · Control evidence

What maps into compliance and assurance work

1governed evidence mapping across 1 approved framework, with framework-level context where exact controls are not claimed.
1 contextual
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0Contextual
Framework-level context

The engagement produces point-in-time technical evidence about the configured and observed security behaviour within the authorised Firewall migration and implementation scope.

Jump to full control mapping ↓
04 · Evidence package

What the customer can use after the engagement

A reviewed target policy, migration risk register, cutover validation record and prioritised follow-up actions.

  • Authorised scope and rules of engagement
  • Coverage matrix
  • Retest and residual-risk record
  • + 3 additional controlled outputs

What this means: technical evidence may support risk, compliance and audit activity where the mapping is applicable. It does not by itself certify the organisation, establish complete compliance or assess controls outside the authorised scope.

How we test

Manual validation backed by controlled evidence.

Damocles reconciles current and proposed configurations, traces translated zones, objects, rules, NAT, routing and VPNs, and observes approved pre-cutover, cutover and rollback checks. Review does not authorise implementation, and production changes occur only under the customer change plan.

How to read the mapping

Evidence is mapped to the part of a control we can actually assess.

Directly assessed means the engagement tests the relevant behaviour. Supporting evidence means the result can contribute to a broader control assessment. Contextual references explain relevance without claiming that the control was tested.

All relevant frameworks
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0Information Security Manual June 2026
Testing perspectives3 authorised viewpoints and access models

Current-state reviewer

Captures and reconciles the source firewall configuration, dependencies and observed service intent.

Included when
Used to establish the migration baseline.
Access required
Native exports, topology, inventories, tickets and owners.
Limitations
Undocumented external dependencies may remain.

Migration implementation engineer

Reviews translated zones, objects, rules, NAT, routing, VPN and management settings against the source.

Included when
Used during design and pre-cutover assurance.
Access required
Target configuration, translation records, platform constraints and test plan.
Limitations
Review does not authorise production implementation.

Validation and rollback owner

Defines acceptance checks, cutover stop conditions and restoration steps and records their execution.

Included when
Used for rehearsals and authorised change windows.
Access required
Approved change plan, test endpoints, rollback artefacts and decision authority.
Limitations
No live cutover is claimed unless observed.
Exact test coverage and evidence14 governed coverage areas
What Damocles tests, the evidence produced and the scope boundary for each controlled coverage area.
Coverage areaWhat Damocles testsPerspective and accessEvidence producedReferences and limits
Current-state configuration captureDamocles captures the source platform configuration, software state, interfaces, dependencies and change baseline using native exports.Validation and rollback owner
Current configuration export or read-only access, diagrams, owners and representative validation endpoints; customer inputs must identify the approved current-state configuration capture targets and expected behaviour.
Configuration excerpts, object or rule identifiers and observed validation results; the record names the tested current-state configuration capture object, path or control and its observed result.
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0

Applicability: Performed when current configuration evidence and a representative endpoint or device are included in the review.

Limit: A configuration snapshot cannot prove continuous enforcement across excluded nodes; validation avoids changes unless implementation work is authorised.

Zone and interface translationDamocles maps every in-scope source zone and interface to the target construct and records semantic or platform differences.Current-state reviewer
Assessment requires source and target exports, translation records, topology, owners, test plan, change window and rollback artefacts, selected specifically for zone and interface translation.
Evidence records the configuration comparison, translated object or rule, test result, decision record or change evidence relevant to zone and interface translation.
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0

Applicability: Applies to Zone and interface translation when the migration component and assurance stage are included.

Limit: The conclusion is limited to the sampled zone and interface translation; review does not authorise implementation and live outcomes are claimed only when observed.

Object and group translationDamocles translates and reconciles network, service and identity objects and groups, resolving duplicates and unsupported forms.Current-state reviewer
Assessment requires source and target exports, translation records, topology, owners, test plan, change window and rollback artefacts, selected specifically for object and group translation.
Evidence records the configuration comparison, translated object or rule, test result, decision record or change evidence relevant to object and group translation.
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0

Applicability: Applies to Object and group translation when the migration component and assurance stage are included.

Limit: The conclusion is limited to the sampled object and group translation; review does not authorise implementation and live outcomes are claimed only when observed.

Rulebase rationalisationDamocles compares source and target rules, preserving required intent while documenting removed, consolidated or changed entries.Validation and rollback owner
Assessment requires source and target exports, translation records, topology, owners, test plan, change window and rollback artefacts, selected specifically for rulebase rationalisation.
Evidence records the configuration comparison, translated object or rule, test result, decision record or change evidence relevant to rulebase rationalisation.
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0

Applicability: Applies to Rulebase rationalisation when the migration component and assurance stage are included.

Limit: The conclusion is limited to the sampled rulebase rationalisation; review does not authorise implementation and live outcomes are claimed only when observed.

NAT translationDamocles translates source and destination NAT and validates the resulting address, port, zone and published-service behaviour.Current-state reviewer
Assessment requires source and target exports, translation records, topology, owners, test plan, change window and rollback artefacts, selected specifically for nat translation.
Evidence records the configuration comparison, translated object or rule, test result, decision record or change evidence relevant to nat translation.
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0

Applicability: Applies to NAT translation when the migration component and assurance stage are included.

Limit: The conclusion is limited to the sampled nat translation; review does not authorise implementation and live outcomes are claimed only when observed.

Routing and dynamic protocolsDamocles maps static and dynamic routing, policy routes and dependencies and checks target convergence assumptions.Validation and rollback owner
Named source and destination test points, expected flow matrix and a safe test window.
Source-to-destination results linked to rule, route or boundary evidence; the record names the tested routing and dynamic protocols object, path or control and its observed result.
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0

Applicability: Performed when both ends of the network path and the enforcing device are owned or expressly authorised for testing.

Limit: Results cover the tested source, destination, protocol and route; testing stops on instability and does not authorise third-party or denial-of-service activity.

VPN migrationDamocles translates VPN peers, identities, selectors, cryptography, routing and monitoring and records interoperability dependencies.Current-state reviewer
Current configuration export or read-only access, diagrams, owners and representative validation endpoints.
Configuration excerpts, object or rule identifiers and observed validation results; the record names the tested vpn migration object, path or control and its observed result.
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0

Applicability: Performed when both ends of the network path and the enforcing device are owned or expressly authorised for testing.

Limit: Results cover the tested source, destination, protocol and route; testing stops on instability and does not authorise third-party or denial-of-service activity.

Management-plane hardeningDamocles reviews target management interfaces, AAA, administrator roles, protocols and permitted management sources.Validation and rollback owner
Current configuration export or read-only access, diagrams, owners and representative validation endpoints.
Configuration excerpts, object or rule identifiers and observed validation results; the record names the tested management-plane hardening object, path or control and its observed result.
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0

Applicability: Performed when current configuration evidence and a representative endpoint or device are included in the review.

Limit: A configuration snapshot cannot prove continuous enforcement across excluded nodes; validation avoids changes unless implementation work is authorised.

Logging integrationDamocles maps source logging and event fields to target destinations, parsers, alerts and operational ownership.Validation and rollback owner
Log-source inventory, representative event identifiers, workflow records and responsible contacts.
Source-health state, event timestamps, investigation timeline and linked action or escalation record.
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0

Applicability: Performed when the relevant telemetry and analyst or customer workflow can be observed during the review window.

Limit: Absent or delayed telemetry prevents a detection conclusion, and observation of one event cannot prove continuous detection of all attacks.

High-availability configurationDamocles reviews target HA peers, interfaces, state synchronisation, monitored paths and failure behaviour.Validation and rollback owner
Architecture, dependency list, monitoring view, authorised failover window and rollback owner.
The relevant configuration excerpt or rule identifier, the expected setting and the observed validation result.
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0

Applicability: Performed only when a customer-approved recovery or failover scenario, observer and rollback window are available.

Limit: The result covers the exercised failure mode; activity stops at the rollback threshold and does not predict every compound failure.

Pre-cutover validationDamocles executes or reviews the approved pre-cutover test plan against staged configuration and representative flows.Current-state reviewer
Assessment requires source and target exports, translation records, topology, owners, test plan, change window and rollback artefacts, selected specifically for pre-cutover validation.
Evidence records the configuration comparison, translated object or rule, test result, decision record or change evidence relevant to pre-cutover validation.
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0

Applicability: Applies to Pre-cutover validation when the migration component and assurance stage are included.

Limit: The conclusion is limited to the sampled pre-cutover validation; review does not authorise implementation and live outcomes are claimed only when observed.

Cutover sequencingDamocles checks the ordered cutover plan, dependencies, decision points, communications and acceptance evidence.Current-state reviewer
Assessment requires source and target exports, translation records, topology, owners, test plan, change window and rollback artefacts, selected specifically for cutover sequencing.
Evidence records the configuration comparison, translated object or rule, test result, decision record or change evidence relevant to cutover sequencing.
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0

Applicability: Applies to Cutover sequencing when the migration component and assurance stage are included.

Limit: The conclusion is limited to the sampled cutover sequencing; review does not authorise implementation and live outcomes are claimed only when observed.

Rollback criteriaDamocles verifies measurable rollback triggers, decision authority, restoration artefacts and source-platform readiness.Current-state reviewer
Assessment requires source and target exports, translation records, topology, owners, test plan, change window and rollback artefacts, selected specifically for rollback criteria.
Evidence records the configuration comparison, translated object or rule, test result, decision record or change evidence relevant to rollback criteria.
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0

Applicability: Applies to Rollback criteria when the migration component and assurance stage are included.

Limit: The conclusion is limited to the sampled rollback criteria; review does not authorise implementation and live outcomes are claimed only when observed.

Post-cutover verificationDamocles records post-cutover configuration comparison, representative flow results, logging, monitoring and unresolved variance.Current-state reviewer
Assessment requires source and target exports, translation records, topology, owners, test plan, change window and rollback artefacts, selected specifically for post-cutover verification.
Evidence records the configuration comparison, translated object or rule, test result, decision record or change evidence relevant to post-cutover verification.
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0

Applicability: Applies to Post-cutover verification when the migration component and assurance stage are included.

Limit: The conclusion is limited to the sampled post-cutover verification; review does not authorise implementation and live outcomes are claimed only when observed.

Framework and control mappings1 governed evidence mappings
Where scoped technical evidence maps to approved security frameworks and control objectives.
Framework and controlsMapping typeWhat Damocles assessesEvidence producedApplicability and limits
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0
Framework-level context
ContextualThe engagement produces point-in-time technical evidence about the configured and observed security behaviour within the authorised Firewall migration and implementation scope.Coverage status, procedure results and findings can inform the customer’s control assessment and risk treatment records.

Applies: Framework-level context is provided when the customer uses NIST SP 800-53 to organise its security control program.

Limit: No individual NIST control is published as verified; organisational implementation, continuous operation, governance and complete catalogue coverage remain outside the engagement.

Assurance boundary: Damocles maps assessed coverage and observations to agreed objectives as traceable technical evidence. The review is not a certification, does not establish complete compliance, and does not confirm controls outside the authorised scope.

Report and evidence outputs6 controlled output types

Authorised scope and rules of engagement

Records authorised scope and rules of engagement produced from the authorised Firewall migration and implementation work.

Included when
Included in the final deliverable when the relevant procedure is performed.
Limitations
Contains only evidence gathered from authorised systems, identities and review material.

Coverage matrix

Records coverage matrix produced from the authorised Firewall migration and implementation work.

Included when
Included in the final deliverable when the relevant procedure is performed.
Limitations
Contains only evidence gathered from authorised systems, identities and review material.

Retest and residual-risk record

Records retest and residual-risk record produced from the authorised Firewall migration and implementation work.

Included when
Included in the final deliverable when the relevant procedure is performed.
Limitations
Contains only evidence gathered from authorised systems, identities and review material.

Configuration translation matrix

Records configuration translation matrix produced from the authorised Firewall migration and implementation work.

Included when
Included in the final deliverable when the relevant procedure is performed.
Limitations
Contains only evidence gathered from authorised systems, identities and review material.

Cutover validation record

Records cutover validation record produced from the authorised Firewall migration and implementation work.

Included when
Included in the final deliverable when the relevant procedure is performed.
Limitations
Contains only evidence gathered from authorised systems, identities and review material.

Rollback readiness record

Records rollback readiness record produced from the authorised Firewall migration and implementation work.

Included when
Included in the final deliverable when the relevant procedure is performed.
Limitations
Contains only evidence gathered from authorised systems, identities and review material.
What you receive

A reviewed target policy, migration risk register, cutover validation record and prioritised follow-up actions.

What we commonly find

Migration risks that commonly turn a security upgrade into an outage or a copy of the old problems.

The design and cutover account for both policy correctness and network behaviour.

PD

Policy debt copied forward

Stale, duplicate or over-broad access migrated because conversion is treated as a mechanical task.

NT

NAT mismatch

Translation order or semantics changing application reachability or security policy behaviour.

RT

Routing/path mismatch

Asymmetric traffic, dynamic routing or default-path changes that break sessions or bypass expected inspection.

VP

VPN dependency failure

Site-to-site or remote-access dependencies omitted from the migration plan.

HA

HA/failover surprise

Target failover behaviour, links or upstream dependencies not validated before production use.

RB

Weak rollback

No realistic path back when a critical application or route fails during cutover.

Engagement options

Choose the migration role Damocles needs to perform.

The engagement can be design-only, migration build, cutover support or end-to-end delivery.

Design
DS

Migration design

Current-state discovery, target architecture, mapping, cleanup decisions and cutover plan.

Build
BL

Configuration build

Prepare approved target configuration and migration artefacts for implementation.

Cutover
CO

Cutover support

Support or perform the approved production transition, validation and rollback decisions.

End-to-end
ED

End-to-end migration delivery

Design, build, implementation, validation and handover under one controlled engagement.

What you receive

Migration artefacts that show what changes, what stays and how the cutover will be validated.

The exact artefacts depend on platform and scope.

CM

Current-state map

Source interfaces, zones, routing, NAT, VPNs, policy and dependencies.

TA

Target architecture

Approved target firewall, zone, routing, policy, management and HA design.

MM

Migration mapping

Rule, object, NAT and service mapping with cleanup and redesign decisions.

CP

Cutover plan

Detailed sequence, owners, maintenance window, validation checkpoints and decision gates.

RB

Rollback plan

Practical restoration path and triggers for stopping or reversing the migration.

VR

Validation record

Post-change routing, application, policy, VPN, management and failover test results.

Implementation and remediation

Implementation is a core option of this service, not an assumed afterthought.

Where Damocles performs the migration, approved production changes are executed within the agreed maintenance window with configuration backups, decision points, validation and rollback controls.

Post-cutover work records unresolved exceptions and any follow-up tuning or cleanup required after stable operation is confirmed.

Scope boundaries

Migration scope is limited to the approved source and target platforms, sites and dependencies.

Application remediation, carrier changes, unrelated switching/routing upgrades and identity redesign are included only where explicitly part of the migration program.

Unknown or undocumented dependencies discovered during delivery are assessed before scope or cutover assumptions are changed.

Scope the service

Tell us the source platform, target platform, sites and cutover requirement.

We will define discovery, design, mapping, configuration, implementation, rollback, validation and handover responsibilities.