fwconvert
UtilityThe following section describes how to troubleshoot the fwconvert
utility.
The following conditions can cause the conversion to fail:
You do not have permission to read files in /opt/SUNWfw/conf or the directory you specified as the location of the FireWall-1 configuration files.
You do not have permission to write files into the directory that you specified for storing the results of fwconvert
.
The path names that you specified to the Convertor are incorrect.
The policy name that you specified is incorrect.
One of the FireWall-1 configuration files you need to convert is missing.
When fwconvert
encounters these conditions, it displays an error message in the FW-1 Convertor dialog box, as shown in Figure 7-2.
fwconvert
When data can not be parsed, this error is displayed on the terminal window and not in the FW-1 Converter dialog box.
Click the OK bar to clear the error message in the FW-1 Convertor dialog box.
Change permissions on the affected directories, if applicable.
Fill in the corrected information in the fwconvert
FW-1 Convertor dialog box, making sure you have the accurate path names and file names that you need to specify.
Click the Retry button.
When it completes successfully, the FireWall-1 Configuration Converter displays the DONE button.
Click DONE to exit fwconvert
.
fwconvert
creates a set of files that are used to generate the SunScreen EFS configuration.
Verify the converted Rules.
For more information, see the following section, Verifying the Converted Rules.
After the conversion is complete, the generated configuration files are located in the directory you specified in the FireWall-1 Configuration Converter dialog box, /opt/SUNWfwcnv/output by default. The policy.name_Objects and policy.name_Rules files must reside in the same directory as policy.name_efscfg before you can run the policy.name_efscfg generation program. It is suggested you first examine these files to confirm that the information was correctly converted.