<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article Expedition User Guide v1.2 in Expedition Articles</title>
    <link>https://live.paloaltonetworks.com/t5/expedition-articles/expedition-user-guide-v1-2/ta-p/285157</link>
    <description>&lt;P&gt;&lt;LI-TOC indent="20" liststyle="none" maxheadinglevel="5"&gt;&lt;/LI-TOC&gt;&lt;/P&gt;
&lt;DIV class="lia-message-template-content-zone"&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;FONT size="5"&gt;Expedition (updated to version 1.1.11)&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;User Guide&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Version 1.2&lt;/STRONG&gt;&lt;/P&gt;
&lt;H2&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Expedition Logo.png" style="width: 245px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21122i632BA61C3A5DE560/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Expedition Logo.png" alt="Expedition Logo.png" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;U&gt;What is Expedition?&lt;/U&gt;&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Expedition&lt;/STRONG&gt; is the fourth evolution of the Palo Alto Networks Migration Tool. The original main purpose of this tool was to help reduce the time and effort to migrate a configuration from one of the supported vendors to Palo Alto Networks.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;By using the Migration Tool, everyone can convert a configuration from Checkpoint or Cisco or any other vendor to a PAN-OS and give you more time to improve the results. Migration Tool 3 added some functionalities to allow our customers to enforce security policies based on App-ID and User-ID as well.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;With Expedition, we have gone one step further, not only because we want to continue helping to facilitate the transition of a security policy from others vendors to PAN-OS but we want to ensure the outcome makes use of the most advanced features of the platform to get you closer to the best of the possible configurations. For this reason, we added a &lt;STRONG&gt;Machine Learning module&lt;/STRONG&gt;, which can help you to generate new security policies based on real log traffic, and we have introduced the &lt;STRONG&gt;Best Practices Assessment Tool&lt;/STRONG&gt;, which checks whether the configuration complies with the Best Practices recommended by our security experts.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;With all these huge improvements, we expect the next time you use Expedition the journey to excellence will be easier.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;Login&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Expedition Web Interface.png" style="width: 512px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21123iD539362C4229238F/image-size/large?v=v2&amp;amp;px=999" role="button" title="Expedition Web Interface.png" alt="Expedition Web Interface.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;H3&gt;&lt;U&gt;Login From the Web Interface&lt;/U&gt;&lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Web Interface Login&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is only referencing the access via web interface&lt;/P&gt;
&lt;BR /&gt;
&lt;TABLE style="width: 536px;"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD bgcolor="#0995c8" style="width: 242px;"&gt;
&lt;DIV&gt;&lt;FONT color="ffffff"&gt;&lt;STRONG&gt; Username&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/DIV&gt;
&lt;/TD&gt;
&lt;TD style="width: 242px;"&gt;
&lt;DIV&gt;&lt;STRONG&gt; admin&lt;/STRONG&gt;&lt;/DIV&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD bgcolor="#0995c8" style="width: 242px;"&gt;
&lt;DIV&gt;&lt;FONT color="ffffff"&gt;&lt;STRONG&gt; Password&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/DIV&gt;
&lt;/TD&gt;
&lt;TD style="width: 242px;"&gt;
&lt;DIV&gt;&lt;STRONG&gt; paloalto&lt;/STRONG&gt;&lt;/DIV&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;MARK&gt;&lt;STRONG&gt;SECURITY WARNING:&lt;/STRONG&gt; We encourage you to change the username and password after your first login.&lt;/MARK&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;&lt;U&gt;Changing default credentials&lt;/U&gt;&lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As a best practice, we recommend that you change the default credentials as soon as possible &lt;FONT color="0995c8"&gt;(DP – upon first log in)&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Web Interface Login&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After you log in via the web browser, follow these instructions to change the password for the “admin” user.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Expedition Save Password.png" style="width: 530px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21126iBD5AD5F0B809B702/image-dimensions/530x60?v=v2" width="530" height="60" role="button" title="Expedition Save Password.png" alt="Expedition Save Password.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-family: inherit;"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-right" image-alt="Expedition Change Password.png" style="width: 250px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21127i85B237A8EBC3CD77/image-dimensions/250x224?v=v2" width="250" height="224" role="button" title="Expedition Change Password.png" alt="Expedition Change Password.png" /&gt;&lt;/span&gt;A new window to change the password will be shown:&lt;/SPAN&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Type the current password&lt;/LI&gt;
&lt;LI&gt;Type NEW password&lt;/LI&gt;
&lt;LI&gt;Re-type NEW password&lt;/LI&gt;
&lt;LI&gt;Click on Save&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;MARK&gt;Remember the password length has to be at least 10 characters long.&lt;/MARK&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;Let’s Migrate&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Expedition can help you migrate pieces of configuration from other security vendors and import them into a Palo Alto Networks configuration. The goal is to reduce time and mistakes. Expedition results always need to be reviewed by a professional with knowledge of the vendor that has been migrated and with Palo Alto Networks technologies as well.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There is no easy button that magically converts a configuration from any vendor to Palo Alto Networks without applying the right methodologies and using qualified people.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;&lt;U&gt;&lt;STRONG&gt;Migration Workflow&lt;/STRONG&gt;&lt;/U&gt;&lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The migration workflow applies to all the vendors we support:&lt;/P&gt;
&lt;OL type="a"&gt;
&lt;LI&gt;Import a Configuration (from a supported vendor)&lt;/LI&gt;
&lt;LI&gt;Export Unused Objects Report&lt;/LI&gt;
&lt;LI&gt;Remove Unused&lt;/LI&gt;
&lt;LI&gt;Clean Invalid Objects&lt;/LI&gt;
&lt;LI&gt;Rename, Remap Interfaces to PAN-OS Naming Convention&lt;/LI&gt;
&lt;LI&gt;Import a Base Configuration (Palo Alto Networks configuration from the device that you are migrating to)&lt;/LI&gt;
&lt;LI&gt;Move Objects From the Configuration Migrated to the Base Configuration.&lt;/LI&gt;
&lt;LI&gt;Merge&lt;/LI&gt;
&lt;LI&gt;Remove Duplicates (if any)&lt;/LI&gt;
&lt;LI&gt;Generate the Output (XML, SET Commands, API Calls)&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;First step will be always creating a Project, then enter the project by double-click on it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;Importing a configuration into the project&lt;/H4&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Expedition Import Tab.png" style="width: 563px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21137iE00324BB9BBFBAEC/image-dimensions/563x110?v=v2" width="563" height="110" role="button" title="Expedition Import Tab.png" alt="Expedition Import Tab.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Expedition can read from different sources. For more specific insights on each vendor, go to the Appendix at the end of this document. Here we will describe the common procedure to migrate any configuration.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Navigate to the Import Tab and select from what vendor you want to migrate. After the configuration has been imported to Expedition, check for invalid objects and clean them before you move forward.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;Project Dashboard&lt;/H4&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As a good starting point, it’s recommended to take a look at the Project Statistics panel. We can search here for invalid, unused, and duplicate objects. We can go straight to review the invalid services by clicking on the number shown under the invalid column for the Services Row. That will move the view to Services, which is located under Objects and will apply a predefined filter to show only the Invalid Services.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Project Statistics View.png" style="width: 512px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21138iC5A26D3BE3E428F7/image-size/large?v=v2&amp;amp;px=999" role="button" title="Project Statistics View.png" alt="Project Statistics View.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;Remove Unused Objects&lt;/H4&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Before searching how to fix those invalid services, it’s important to remove what was imported but not used in any security or NAT policy. Let's call them unused objects. To remove the unused objects, you have to navigate to the Objects Tab and look at the bottom right bar.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Objects Tab Selection.png" style="width: 536px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21139i42EF85DE3D050CB9/image-size/large?v=v2&amp;amp;px=999" role="button" title="Objects Tab Selection.png" alt="Objects Tab Selection.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;At the very end, you will find three buttons. The green button will recalculate the objects that are defined as used or not used. This should be used after changes have been made on the configuration, so Expedition can recalculate the used objects. The red button is will remove the unused objects from the configuration. The third button with the "X" on it will export a report with all the unused objects.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We recommend exporting the Excel file to track which objects will be removed from the configuration when you click on the red button, and it’s good to keep it for your migration records.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After export the Excel file, click the red button to remove all the unused, and recheck your dashboard to see if you reduced the number of fixes you have to make.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;Fixing Invalid Services&lt;/H4&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Every time you import a configuration from a vendor other than Palo Alto Networks, it's common to have what we call invalid services. We consider invalid services all of those who were based on IP protocols other than TCP or UDP. For example, you can find ICMP services related or IPSec, GRE.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Expedition Valid Protocols.png" style="width: 842px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21141iCFE5976C86EAAC3C/image-size/large?v=v2&amp;amp;px=999" role="button" title="Expedition Valid Protocols.png" alt="Expedition Valid Protocols.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After we have removed the Unused Objects, only the used ones will be kept for remediation. In the case of invalid services, the only way to fix it, in case the original service was not TCP or UDP, is change it to an App-ID from Palo Alto Networks.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Expedition Revised Project Statistics.png" style="width: 512px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21142iC70159F292CBE12A/image-size/large?v=v2&amp;amp;px=999" role="button" title="Expedition Revised Project Statistics.png" alt="Expedition Revised Project Statistics.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To update the App-IDs, just right-click on the invalid service and click Search and Replace from the advanced menu.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Expedition Search and Replace.png" style="width: 512px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21143i259B911EA0BFD7CE/image-size/large?v=v2&amp;amp;px=999" role="button" title="Expedition Search and Replace.png" alt="Expedition Search and Replace.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This will open up the Tools Tab and show you the Search &amp;amp; Replace Tab. The view is divided in two panels: the left panel shows the output of the applied filters and the right panel will show you where the selected items from the left panel are used.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Expedition Filters and Object Groups.png" style="width: 512px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21144i8851C1AC211704EB/image-size/large?v=v2&amp;amp;px=999" role="button" title="Expedition Filters and Object Groups.png" alt="Expedition Filters and Object Groups.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H5&gt;&lt;STRONG&gt;Replace Services by App-ID&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Select the service to be replaced. For instance, in our example, we will select the Group where ICMP was a member and clicked the Replace button located on the bottom bar.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Click Security Policy (1) then select the rule where the service is used and click Replace again.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Expedition Replace App-ID.png" style="width: 512px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21145i4008AC05DDAD3E45/image-size/large?v=v2&amp;amp;px=999" role="button" title="Expedition Replace App-ID.png" alt="Expedition Replace App-ID.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you want to see the rule(s) that use this object, just double-click on the rule and you will be redirected to the Policy Tab and a filter by that rule will be applied.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After review, move back to the Tools Tab, click the Search &amp;amp; Replace Tab, and click on Replace. In this example, we are replacing a service by an App-ID, so select Replace by “Applications” and then to “ICMP” and click Replace All.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There are a couple options enabled by default:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Split rules when needed – In case we are replacing services by App-ID, check if the rule where the invalid service is in use has more services defined. In that situation, the rule will be cloned to allow the new App-ID but removing all the other services from the cloned rule, and then the invalid service will be removed from the original rule. By doing this, we don’t mix services with apps in the same rule which can lead to change the original behavior of the rule.&lt;/LI&gt;
&lt;LI&gt;Remove Service from Group – In case the invalid service was a member of a group, it will be removed after the replace as a member.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Expedition Replace by.png" style="width: 512px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21146i1B59EB57309D0A3D/image-size/large?v=v2&amp;amp;px=999" role="button" title="Expedition Replace by.png" alt="Expedition Replace by.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This procedure can be used in many other ways. For example, if we want to filter by a service or address and remove that object from the configuration, just select the object from the Search Results panel then add to Replace from where it was being used. To replace, select Replace by combo “Remove.” That will remove the object from where it was used, or if you have an address-group or service-group and you want to replace it by the members instead, you will do the same but in the Replace and select “Members” then click Replace All.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;MARK&gt;After replacement of the invalid objects, you can repeat the step for removing the unused objects since they will not be used anymore.&lt;/MARK&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;Remapping Interface Names&lt;/H4&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Expedition, when imports configurations from other vendors, keeps the original interface names to make the validation process easier after the import. The problem with that is naming usually doesn’t match the one that Palo Alto Networks expects, so we have to rename them to ensure the changes will be captured by our Palo Alto Networks configuration.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For example, we import a configuration from Cisco, and the interface names are “Ethernet1/1” which is very similar to a Palo Alto Networks naming convention, but, in our case, it must be all in lowercase.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To convert it to the proper naming convention, you can select the Ethernet1/1 that is parent for more sub-interfaces (vlan tags) and click on the Remap Interface Name located at the bottom left-side bar. From there, select Slot 1 and ethernet1/1.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Expedition Rename Interfaces.png" style="width: 512px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21148i2ED50E6AF00235C6/image-size/large?v=v2&amp;amp;px=999" role="button" title="Expedition Rename Interfaces.png" alt="Expedition Rename Interfaces.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After clicking the Remap button, the Expedition tool will replace the name of the interface in the whole configuration, including any references to it and any subinterfaces.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Expedition Network Interfaces.png" style="width: 512px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21149iB19982A53B6343B0/image-size/large?v=v2&amp;amp;px=999" role="button" title="Expedition Network Interfaces.png" alt="Expedition Network Interfaces.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You will have to repeat the process to adapt all the interfaces that you want to migrate.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;Import Your Base Configuration&lt;/H4&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What is the Base Configuration?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Base Configuration is a device's specific configuration that is usually taken from the Palo Alto Networks device that you are migrating to. The base configuration should be used, as the name suggests, as a base and should be merged with the imported third-party vendor configuration that you have imported and manipulated. The result of the merge should be a working and migrated Palo Alto Networks configuration.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The first PAN-OS configuration imported into the project will be assigned as Base Configuration. The Base Configuration is the one that will be used at the time to export the configuration out of Expedition or by generating an XML file or API calls. Any changes made to the Base Configuration will be applied to the output.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To import a Base Configuration, click the Import Tab from the PALO ALTO Tab and enter a link to your XML file that you previously exported from your PAN-OS device or just double click on one of the devices added to the project (if any) to import the config from the snapshot stored in Expedition.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Expedition Import Base Config.png" style="width: 512px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21150i0D0991646D942C43/image-size/large?v=v2&amp;amp;px=999" role="button" title="Expedition Import Base Config.png" alt="Expedition Import Base Config.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After that, you can check from the Export Tab that the config has been set as Base Config by seeing if it has been placed in the right panel.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Expedition Base Config Output.png" style="width: 512px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21151i015D2CF6F94EF376/image-size/large?v=v2&amp;amp;px=999" role="button" title="Expedition Base Config Output.png" alt="Expedition Base Config Output.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From there, you can select what objects we want to move from the left panel to the Base Configuration (right panel) by using drag and drop.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In case you want to move the objects from the left panel and convert them as shared objects, drop them into the Shared vsys/DG. After the merge, they will be transformed into shared objects, and all the references to them will point to the new shared objects (from policies, groups, etc).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;Merge Objects to your Base Configuration&lt;/H4&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;All migrated objects should be visible on the left panel under the Export Tab. The right panel should have your Base Configuration that you previously imported. You just need to drag and drop the migrated objects and policies from the left to the right. You can select certain parts of the migrated configuration to be moved to the final configuration or all of them.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please make sure you place the objects and policies into the desired vsys configuration.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Expedition Source Config Base Config.png" style="width: 512px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21152iBE7146577FF3E10F/image-size/large?v=v2&amp;amp;px=999" role="button" title="Expedition Source Config Base Config.png" alt="Expedition Source Config Base Config.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Repeat the same procedure with the Zones, Interfaces, Virtual Router(s) and drop them into the correct vsys.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Expedition Source Config Interfaces Virtual Routers.png" style="width: 694px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21153iE9FA56E1B321FDFD/image-dimensions/694x207?v=v2" width="694" height="207" role="button" title="Expedition Source Config Interfaces Virtual Routers.png" alt="Expedition Source Config Interfaces Virtual Routers.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The final step is to merge the migrated configuration and your base configuration and create you final configuration. To do this, click the MERGE button.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After this action, all the selected objects will be transferred from one configuration to the Base Configuration. If you want to see how it looks, you need to change the selected configuration and the vsys to the Base Configuration&amp;nbsp;from the bottom bar by going to the Objects Tab. This will filter and show you the objects and rules on the Base Configuration.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Expedition Base Configuration vsys.png" style="width: 512px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21154iB725A9A49658303D/image-size/large?v=v2&amp;amp;px=999" role="button" title="Expedition Base Configuration vsys.png" alt="Expedition Base Configuration vsys.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After you have created the final configuration, you have two options to deploy it. One option is a manual XML file export that can be deployed on the Palo Alto Networks device to which you are migrating, and the other option is to use API calls to send parts of the configuration or the whole configuration to the device&amp;nbsp;if that Palo Alto Networks device is already connected to Expedition.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;Find Duplicates After the Merge and Removing Them&lt;/H4&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It is recommended that you run another check for duplicates and remove or merge them after a configuration migration. A common scenario is to have duplicates amongst objects, services, and/or interfaces.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Using the dashboard from within the project, it will tell you how many duplicated objects you have in your current configuration. You can click on the duplicate object to go to the object view, and Expedition will filter by duplicate and by name predefined filter.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Expedition Project Statistics Duplicated.png" style="width: 629px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21155i1C6D6542972B881D/image-dimensions/629x334?v=v2" width="629" height="334" role="button" title="Expedition Project Statistics Duplicated.png" alt="Expedition Project Statistics Duplicated.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Next, check the duplicated services to demonstrate the workflow to follow and get rid of them.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Expedition Services tab.png" style="width: 512px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21156i61B6E8799F5C1449/image-size/large?v=v2&amp;amp;px=999" role="button" title="Expedition Services tab.png" alt="Expedition Services tab.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The object in Pink is a Shared object, so that means you have selected the vsys equal to all from the bottom bar. This will do a search across all the vsys/DG to find objects seen more than once.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;In our example, we want to keep the object that already exists as Shared and make all the references within the vsys/DG points after the merge to the Shared object only and finally the duplicated object out from the Shared will be removed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;First, select the duplicated objects you want to keep and then right-click and select Merge Options and “Set as Primary.” That will tell Expedition to&amp;nbsp;keep the one we set as Primary after Merging the duplicated objects.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Expedition Merge Options.png" style="width: 512px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21157iEB9CF5727DC474CB/image-size/large?v=v2&amp;amp;px=999" role="button" title="Expedition Merge Options.png" alt="Expedition Merge Options.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When the object has been set as Primary, you will notice a new icon appear.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Expedition Primary Icon.png" style="width: 512px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21158iBEFF1EE00B45B609/image-size/large?v=v2&amp;amp;px=999" role="button" title="Expedition Primary Icon.png" alt="Expedition Primary Icon.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now you can apply the Merge type. In our case, we will use Merge by Name and Value to validate only the same duplicated object is merged. Right-click and select “Merge” then click “By Name &amp;amp; Value.” This will be applied to the selected objects or, in case you didn’t select any, it will be applied to all the results from the filter applied.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can change the filter and add a predefined filter to show only the duplicated services by name only and then apply the merge by the same concept, only by name as well.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;All this can be done with the right-click “Select predefined filter.”&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;Generating the Output&lt;/H4&gt;
&lt;P&gt;When you are finished cleaning your configuration, it’s time to get the results and export from Expedition and import into your Palo Alto Networks device (Firewall or Panorama).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Navigate to the Export TAB.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Under the Mapping Tab, there is a button at the bottom bar-left titled “Generate XML &amp;amp; SET Output.” By pressing this button, Expedition will generate a XML configuration file and based on that configuration (and using a script called Pan-Python made by Kevin Steves &lt;A title="Multi-tool for PAN-OS, Panorama, WildFire and AutoFocus | GitHub" href="https://github.com/kevinsteves/pan-python" target="_self"&gt;https://github.com/kevinsteves/pan-python&lt;/A&gt;) it will generate the Set commands as well. After the generation, a new window with the download links will appear. Click the Downloads button to get access to that window as well.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Expedition Downloads.png" style="width: 512px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21159i86239666288D7384/image-size/large?v=v2&amp;amp;px=999" role="button" title="Expedition Downloads.png" alt="Expedition Downloads.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can generate API Calls to be sent to your devices in case you created them before and you added to the project you are working on. In that case, you will need to go under the tab titled, “API Output Manager.”&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here, you have several options. We will start covering Atomic and Subatomic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Atomic calls will be API calls where with a single API call will add all the address, for instance, to a specific vsys/DG. If you select subatomic, you will get one API call by element you have. If you have 500 addresses, you will get 500 API calls, one for each address. With Atomic, you will get just one API call containing the 500 addresses inside.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Step One:&lt;/STRONG&gt; Click on “Atomic” or “Subatomic” and click the “Step 1” button to create all the API calls.&lt;/P&gt;
&lt;P&gt;After that, the ID of each API call will tell you the order in which you have to send the API call. Yes, order matters. If you don’t select any, all API calls will be sent in the proper order.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Step Two:&lt;/STRONG&gt; Click “Step 2” button and select the DEVICE where you want to send the API calls and send them all.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Expedition Send API Calls.png" style="width: 472px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21160iECFD3B4E6CB9D697/image-size/large?v=v2&amp;amp;px=999" role="button" title="Expedition Send API Calls.png" alt="Expedition Send API Calls.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After the API call is sent, you will get the response from the device itself. If it was successful, you will see in the output.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Expedition API Call Notice.png" style="width: 512px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21161i09EEDBC690FCB8AD/image-size/large?v=v2&amp;amp;px=999" role="button" title="Expedition API Call Notice.png" alt="Expedition API Call Notice.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;Appendix A: Import&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;Importing CSV files&lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From within a project, it's possible to import CSV files containing objects that you want to add to you current configuration.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;Requirements&lt;/H4&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You must have a configuration previously loaded in order to import something else on top by using CSV files.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How the CSV file must be created:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The character used to split by columns is the semi-colon “;”&lt;/LI&gt;
&lt;LI&gt;The character used to split members inside a column is the comma “,”&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;Process&lt;/H4&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Select the object type you want to import. Example: Static Routes&lt;/LI&gt;
&lt;LI&gt;Select the CSV file from your laptop&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Expedition Source Object Import.png" style="width: 512px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21162i33BA8B8BAE2CC632/image-size/large?v=v2&amp;amp;px=999" role="button" title="Expedition Source Object Import.png" alt="Expedition Source Object Import.png" /&gt;&lt;/span&gt;&lt;/LI&gt;
&lt;LI&gt;Map your columns with the predefined fields from the right panel&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Expedition Data Preview Mapping.png" style="width: 512px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21163i52406F5D2750E563/image-size/large?v=v2&amp;amp;px=999" role="button" title="Expedition Data Preview Mapping.png" alt="Expedition Data Preview Mapping.png" /&gt;&lt;/span&gt;&lt;/LI&gt;
&lt;LI&gt;Select where to import the new data loaded from the CSV and mapped&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Expedition Destination.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21164i03F34B118C349E6D/image-size/large?v=v2&amp;amp;px=999" role="button" title="Expedition Destination.png" alt="Expedition Destination.png" /&gt;&lt;/span&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;MARK&gt;In this example, routes are part of Templates and need to be imported into a Virtual-Router. Plus, select the virtual-system where your VR is located. Then click Import Data.&lt;/MARK&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Order matters! If want to import Service Groups, you need to first import the services used on those Groups or the import will not be successful.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;Importing an IronSkillet Day1 Configuration&lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;IronSkillet is a project made by Palo Alto Networks to create a configuration that is already configured with some of the best practices recommended by our security experts. If you need to add a Base Configuration into Expedition to use it as a base to migrate something else, it's very simple now with the integration built in Expedition.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;Process&lt;/H4&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Create a project and click to get in. After you enter the project, go to IMPORT. Then click the Tab title "Iron-Skillet."&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Expedition IronSkillet View.png" style="width: 512px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21165i9F1912E1A3B0D538/image-size/large?v=v2&amp;amp;px=999" role="button" title="Expedition IronSkillet View.png" alt="Expedition IronSkillet View.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From here, you can configure some parameters before the configuration is created. You can modify the parameters by hand, or, if you have an IronSkillet configuration file, you can load it to automatically fill the fields.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Select the Configuration Type (Firewall or Panorama) this will generate the type of configuration selected.&lt;/LI&gt;
&lt;LI&gt;PAN-OS Version. You can select if the configuration you need but it must be 8.0 or 8.1 or X.X&lt;/LI&gt;
&lt;LI&gt;If you have an IronSkillet configuration, you can click LOAD FROM CLIPBOARD and paste the content from the file and then click SAVE. That will automatically fill the fields configured.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Example: &lt;A href="https://raw.githubusercontent.com/PaloAltoNetworks/iron-skillet/panos_v8.0/my_configs/sample-mgmt-dhcp/my_variables.py" target="_blank" rel="noopener"&gt;https://raw.githubusercontent.com/PaloAltoNetworks/iron-skillet/panos_v8.0/my_configs/sample-mgmt-dhcp/my_variables.py&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Expedition Copyright 2018 Palo Alto Networks.png" style="width: 730px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21168iC8D65B11F48DA4ED/image-size/large?v=v2&amp;amp;px=999" role="button" title="Expedition Copyright 2018 Palo Alto Networks.png" alt="Expedition Copyright 2018 Palo Alto Networks.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Expedition Import Palo Alto IronSkillet.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21167i2AF7086F2D7A7A4F/image-size/large?v=v2&amp;amp;px=999" role="button" title="Expedition Import Palo Alto IronSkillet.png" alt="Expedition Import Palo Alto IronSkillet.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After the changes are made, you have to click on GENERATE CONFIG AND IMPORT. This will create a Palo Alto Networks configuration file based on your selection (Firewall or Panorama) and with the selected version and all the changes made in the parameters will be applied to it. After IronSkillet generates the new configuration, Expedition will Encrypt it and automatically imported into the Project. If this is the first Palo Alto Networks configuration loaded on the Project, Expedition will set it as the Base Configuration.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;Revision History&lt;/H3&gt;
&lt;TABLE&gt;
&lt;TBODY&gt;
&lt;TR bgcolor="#0995c8"&gt;
&lt;TD&gt;
&lt;P&gt;&lt;FONT color="ffffff"&gt;&lt;STRONG&gt;Date&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;FONT color="ffffff"&gt;&lt;STRONG&gt;Revision&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;FONT color="ffffff"&gt;&lt;STRONG&gt;Comment&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;June 22, 2018&lt;/TD&gt;
&lt;TD&gt;A&lt;/TD&gt;
&lt;TD&gt;First release of this document.&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;October 16,2018&lt;/TD&gt;
&lt;TD&gt;B&lt;/TD&gt;
&lt;TD&gt;Added Appendix A&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;April 1,2019&lt;/TD&gt;
&lt;TD&gt;C&lt;/TD&gt;
&lt;TD&gt;Updated Screenshots&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;August 27, 2019&lt;/TD&gt;
&lt;TD&gt;D&lt;/TD&gt;
&lt;TD&gt;Created LIVEcommunity Article and Editorial Revisions&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;</description>
    <pubDate>Thu, 29 Aug 2019 18:51:50 GMT</pubDate>
    <dc:creator>Retired Member</dc:creator>
    <dc:date>2019-08-29T18:51:50Z</dc:date>
    <item>
      <title>Expedition User Guide v1.2</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-articles/expedition-user-guide-v1-2/ta-p/285157</link>
      <description>&lt;P&gt;&lt;LI-TOC indent="20" liststyle="none" maxheadinglevel="5"&gt;&lt;/LI-TOC&gt;&lt;/P&gt;
&lt;DIV class="lia-message-template-content-zone"&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;FONT size="5"&gt;Expedition (updated to version 1.1.11)&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;User Guide&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Version 1.2&lt;/STRONG&gt;&lt;/P&gt;
&lt;H2&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Expedition Logo.png" style="width: 245px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21122i632BA61C3A5DE560/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Expedition Logo.png" alt="Expedition Logo.png" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;U&gt;What is Expedition?&lt;/U&gt;&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Expedition&lt;/STRONG&gt; is the fourth evolution of the Palo Alto Networks Migration Tool. The original main purpose of this tool was to help reduce the time and effort to migrate a configuration from one of the supported vendors to Palo Alto Networks.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;By using the Migration Tool, everyone can convert a configuration from Checkpoint or Cisco or any other vendor to a PAN-OS and give you more time to improve the results. Migration Tool 3 added some functionalities to allow our customers to enforce security policies based on App-ID and User-ID as well.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;With Expedition, we have gone one step further, not only because we want to continue helping to facilitate the transition of a security policy from others vendors to PAN-OS but we want to ensure the outcome makes use of the most advanced features of the platform to get you closer to the best of the possible configurations. For this reason, we added a &lt;STRONG&gt;Machine Learning module&lt;/STRONG&gt;, which can help you to generate new security policies based on real log traffic, and we have introduced the &lt;STRONG&gt;Best Practices Assessment Tool&lt;/STRONG&gt;, which checks whether the configuration complies with the Best Practices recommended by our security experts.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;With all these huge improvements, we expect the next time you use Expedition the journey to excellence will be easier.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;Login&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Expedition Web Interface.png" style="width: 512px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21123iD539362C4229238F/image-size/large?v=v2&amp;amp;px=999" role="button" title="Expedition Web Interface.png" alt="Expedition Web Interface.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;H3&gt;&lt;U&gt;Login From the Web Interface&lt;/U&gt;&lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Web Interface Login&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is only referencing the access via web interface&lt;/P&gt;
&lt;BR /&gt;
&lt;TABLE style="width: 536px;"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD bgcolor="#0995c8" style="width: 242px;"&gt;
&lt;DIV&gt;&lt;FONT color="ffffff"&gt;&lt;STRONG&gt; Username&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/DIV&gt;
&lt;/TD&gt;
&lt;TD style="width: 242px;"&gt;
&lt;DIV&gt;&lt;STRONG&gt; admin&lt;/STRONG&gt;&lt;/DIV&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD bgcolor="#0995c8" style="width: 242px;"&gt;
&lt;DIV&gt;&lt;FONT color="ffffff"&gt;&lt;STRONG&gt; Password&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/DIV&gt;
&lt;/TD&gt;
&lt;TD style="width: 242px;"&gt;
&lt;DIV&gt;&lt;STRONG&gt; paloalto&lt;/STRONG&gt;&lt;/DIV&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;MARK&gt;&lt;STRONG&gt;SECURITY WARNING:&lt;/STRONG&gt; We encourage you to change the username and password after your first login.&lt;/MARK&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;&lt;U&gt;Changing default credentials&lt;/U&gt;&lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As a best practice, we recommend that you change the default credentials as soon as possible &lt;FONT color="0995c8"&gt;(DP – upon first log in)&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Web Interface Login&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After you log in via the web browser, follow these instructions to change the password for the “admin” user.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Expedition Save Password.png" style="width: 530px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21126iBD5AD5F0B809B702/image-dimensions/530x60?v=v2" width="530" height="60" role="button" title="Expedition Save Password.png" alt="Expedition Save Password.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-family: inherit;"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-right" image-alt="Expedition Change Password.png" style="width: 250px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21127i85B237A8EBC3CD77/image-dimensions/250x224?v=v2" width="250" height="224" role="button" title="Expedition Change Password.png" alt="Expedition Change Password.png" /&gt;&lt;/span&gt;A new window to change the password will be shown:&lt;/SPAN&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Type the current password&lt;/LI&gt;
&lt;LI&gt;Type NEW password&lt;/LI&gt;
&lt;LI&gt;Re-type NEW password&lt;/LI&gt;
&lt;LI&gt;Click on Save&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;MARK&gt;Remember the password length has to be at least 10 characters long.&lt;/MARK&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;Let’s Migrate&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Expedition can help you migrate pieces of configuration from other security vendors and import them into a Palo Alto Networks configuration. The goal is to reduce time and mistakes. Expedition results always need to be reviewed by a professional with knowledge of the vendor that has been migrated and with Palo Alto Networks technologies as well.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There is no easy button that magically converts a configuration from any vendor to Palo Alto Networks without applying the right methodologies and using qualified people.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;&lt;U&gt;&lt;STRONG&gt;Migration Workflow&lt;/STRONG&gt;&lt;/U&gt;&lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The migration workflow applies to all the vendors we support:&lt;/P&gt;
&lt;OL type="a"&gt;
&lt;LI&gt;Import a Configuration (from a supported vendor)&lt;/LI&gt;
&lt;LI&gt;Export Unused Objects Report&lt;/LI&gt;
&lt;LI&gt;Remove Unused&lt;/LI&gt;
&lt;LI&gt;Clean Invalid Objects&lt;/LI&gt;
&lt;LI&gt;Rename, Remap Interfaces to PAN-OS Naming Convention&lt;/LI&gt;
&lt;LI&gt;Import a Base Configuration (Palo Alto Networks configuration from the device that you are migrating to)&lt;/LI&gt;
&lt;LI&gt;Move Objects From the Configuration Migrated to the Base Configuration.&lt;/LI&gt;
&lt;LI&gt;Merge&lt;/LI&gt;
&lt;LI&gt;Remove Duplicates (if any)&lt;/LI&gt;
&lt;LI&gt;Generate the Output (XML, SET Commands, API Calls)&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;First step will be always creating a Project, then enter the project by double-click on it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;Importing a configuration into the project&lt;/H4&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Expedition Import Tab.png" style="width: 563px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21137iE00324BB9BBFBAEC/image-dimensions/563x110?v=v2" width="563" height="110" role="button" title="Expedition Import Tab.png" alt="Expedition Import Tab.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Expedition can read from different sources. For more specific insights on each vendor, go to the Appendix at the end of this document. Here we will describe the common procedure to migrate any configuration.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Navigate to the Import Tab and select from what vendor you want to migrate. After the configuration has been imported to Expedition, check for invalid objects and clean them before you move forward.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;Project Dashboard&lt;/H4&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As a good starting point, it’s recommended to take a look at the Project Statistics panel. We can search here for invalid, unused, and duplicate objects. We can go straight to review the invalid services by clicking on the number shown under the invalid column for the Services Row. That will move the view to Services, which is located under Objects and will apply a predefined filter to show only the Invalid Services.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Project Statistics View.png" style="width: 512px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21138iC5A26D3BE3E428F7/image-size/large?v=v2&amp;amp;px=999" role="button" title="Project Statistics View.png" alt="Project Statistics View.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;Remove Unused Objects&lt;/H4&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Before searching how to fix those invalid services, it’s important to remove what was imported but not used in any security or NAT policy. Let's call them unused objects. To remove the unused objects, you have to navigate to the Objects Tab and look at the bottom right bar.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Objects Tab Selection.png" style="width: 536px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21139i42EF85DE3D050CB9/image-size/large?v=v2&amp;amp;px=999" role="button" title="Objects Tab Selection.png" alt="Objects Tab Selection.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;At the very end, you will find three buttons. The green button will recalculate the objects that are defined as used or not used. This should be used after changes have been made on the configuration, so Expedition can recalculate the used objects. The red button is will remove the unused objects from the configuration. The third button with the "X" on it will export a report with all the unused objects.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We recommend exporting the Excel file to track which objects will be removed from the configuration when you click on the red button, and it’s good to keep it for your migration records.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After export the Excel file, click the red button to remove all the unused, and recheck your dashboard to see if you reduced the number of fixes you have to make.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;Fixing Invalid Services&lt;/H4&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Every time you import a configuration from a vendor other than Palo Alto Networks, it's common to have what we call invalid services. We consider invalid services all of those who were based on IP protocols other than TCP or UDP. For example, you can find ICMP services related or IPSec, GRE.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Expedition Valid Protocols.png" style="width: 842px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21141iCFE5976C86EAAC3C/image-size/large?v=v2&amp;amp;px=999" role="button" title="Expedition Valid Protocols.png" alt="Expedition Valid Protocols.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After we have removed the Unused Objects, only the used ones will be kept for remediation. In the case of invalid services, the only way to fix it, in case the original service was not TCP or UDP, is change it to an App-ID from Palo Alto Networks.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Expedition Revised Project Statistics.png" style="width: 512px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21142iC70159F292CBE12A/image-size/large?v=v2&amp;amp;px=999" role="button" title="Expedition Revised Project Statistics.png" alt="Expedition Revised Project Statistics.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To update the App-IDs, just right-click on the invalid service and click Search and Replace from the advanced menu.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Expedition Search and Replace.png" style="width: 512px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21143i259B911EA0BFD7CE/image-size/large?v=v2&amp;amp;px=999" role="button" title="Expedition Search and Replace.png" alt="Expedition Search and Replace.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This will open up the Tools Tab and show you the Search &amp;amp; Replace Tab. The view is divided in two panels: the left panel shows the output of the applied filters and the right panel will show you where the selected items from the left panel are used.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Expedition Filters and Object Groups.png" style="width: 512px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21144i8851C1AC211704EB/image-size/large?v=v2&amp;amp;px=999" role="button" title="Expedition Filters and Object Groups.png" alt="Expedition Filters and Object Groups.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H5&gt;&lt;STRONG&gt;Replace Services by App-ID&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Select the service to be replaced. For instance, in our example, we will select the Group where ICMP was a member and clicked the Replace button located on the bottom bar.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Click Security Policy (1) then select the rule where the service is used and click Replace again.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Expedition Replace App-ID.png" style="width: 512px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21145i4008AC05DDAD3E45/image-size/large?v=v2&amp;amp;px=999" role="button" title="Expedition Replace App-ID.png" alt="Expedition Replace App-ID.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you want to see the rule(s) that use this object, just double-click on the rule and you will be redirected to the Policy Tab and a filter by that rule will be applied.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After review, move back to the Tools Tab, click the Search &amp;amp; Replace Tab, and click on Replace. In this example, we are replacing a service by an App-ID, so select Replace by “Applications” and then to “ICMP” and click Replace All.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There are a couple options enabled by default:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Split rules when needed – In case we are replacing services by App-ID, check if the rule where the invalid service is in use has more services defined. In that situation, the rule will be cloned to allow the new App-ID but removing all the other services from the cloned rule, and then the invalid service will be removed from the original rule. By doing this, we don’t mix services with apps in the same rule which can lead to change the original behavior of the rule.&lt;/LI&gt;
&lt;LI&gt;Remove Service from Group – In case the invalid service was a member of a group, it will be removed after the replace as a member.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Expedition Replace by.png" style="width: 512px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21146i1B59EB57309D0A3D/image-size/large?v=v2&amp;amp;px=999" role="button" title="Expedition Replace by.png" alt="Expedition Replace by.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This procedure can be used in many other ways. For example, if we want to filter by a service or address and remove that object from the configuration, just select the object from the Search Results panel then add to Replace from where it was being used. To replace, select Replace by combo “Remove.” That will remove the object from where it was used, or if you have an address-group or service-group and you want to replace it by the members instead, you will do the same but in the Replace and select “Members” then click Replace All.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;MARK&gt;After replacement of the invalid objects, you can repeat the step for removing the unused objects since they will not be used anymore.&lt;/MARK&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;Remapping Interface Names&lt;/H4&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Expedition, when imports configurations from other vendors, keeps the original interface names to make the validation process easier after the import. The problem with that is naming usually doesn’t match the one that Palo Alto Networks expects, so we have to rename them to ensure the changes will be captured by our Palo Alto Networks configuration.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For example, we import a configuration from Cisco, and the interface names are “Ethernet1/1” which is very similar to a Palo Alto Networks naming convention, but, in our case, it must be all in lowercase.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To convert it to the proper naming convention, you can select the Ethernet1/1 that is parent for more sub-interfaces (vlan tags) and click on the Remap Interface Name located at the bottom left-side bar. From there, select Slot 1 and ethernet1/1.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Expedition Rename Interfaces.png" style="width: 512px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21148i2ED50E6AF00235C6/image-size/large?v=v2&amp;amp;px=999" role="button" title="Expedition Rename Interfaces.png" alt="Expedition Rename Interfaces.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After clicking the Remap button, the Expedition tool will replace the name of the interface in the whole configuration, including any references to it and any subinterfaces.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Expedition Network Interfaces.png" style="width: 512px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21149iB19982A53B6343B0/image-size/large?v=v2&amp;amp;px=999" role="button" title="Expedition Network Interfaces.png" alt="Expedition Network Interfaces.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You will have to repeat the process to adapt all the interfaces that you want to migrate.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;Import Your Base Configuration&lt;/H4&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What is the Base Configuration?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Base Configuration is a device's specific configuration that is usually taken from the Palo Alto Networks device that you are migrating to. The base configuration should be used, as the name suggests, as a base and should be merged with the imported third-party vendor configuration that you have imported and manipulated. The result of the merge should be a working and migrated Palo Alto Networks configuration.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The first PAN-OS configuration imported into the project will be assigned as Base Configuration. The Base Configuration is the one that will be used at the time to export the configuration out of Expedition or by generating an XML file or API calls. Any changes made to the Base Configuration will be applied to the output.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To import a Base Configuration, click the Import Tab from the PALO ALTO Tab and enter a link to your XML file that you previously exported from your PAN-OS device or just double click on one of the devices added to the project (if any) to import the config from the snapshot stored in Expedition.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Expedition Import Base Config.png" style="width: 512px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21150i0D0991646D942C43/image-size/large?v=v2&amp;amp;px=999" role="button" title="Expedition Import Base Config.png" alt="Expedition Import Base Config.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After that, you can check from the Export Tab that the config has been set as Base Config by seeing if it has been placed in the right panel.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Expedition Base Config Output.png" style="width: 512px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21151i015D2CF6F94EF376/image-size/large?v=v2&amp;amp;px=999" role="button" title="Expedition Base Config Output.png" alt="Expedition Base Config Output.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From there, you can select what objects we want to move from the left panel to the Base Configuration (right panel) by using drag and drop.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In case you want to move the objects from the left panel and convert them as shared objects, drop them into the Shared vsys/DG. After the merge, they will be transformed into shared objects, and all the references to them will point to the new shared objects (from policies, groups, etc).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;Merge Objects to your Base Configuration&lt;/H4&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;All migrated objects should be visible on the left panel under the Export Tab. The right panel should have your Base Configuration that you previously imported. You just need to drag and drop the migrated objects and policies from the left to the right. You can select certain parts of the migrated configuration to be moved to the final configuration or all of them.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please make sure you place the objects and policies into the desired vsys configuration.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Expedition Source Config Base Config.png" style="width: 512px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21152iBE7146577FF3E10F/image-size/large?v=v2&amp;amp;px=999" role="button" title="Expedition Source Config Base Config.png" alt="Expedition Source Config Base Config.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Repeat the same procedure with the Zones, Interfaces, Virtual Router(s) and drop them into the correct vsys.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Expedition Source Config Interfaces Virtual Routers.png" style="width: 694px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21153iE9FA56E1B321FDFD/image-dimensions/694x207?v=v2" width="694" height="207" role="button" title="Expedition Source Config Interfaces Virtual Routers.png" alt="Expedition Source Config Interfaces Virtual Routers.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The final step is to merge the migrated configuration and your base configuration and create you final configuration. To do this, click the MERGE button.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After this action, all the selected objects will be transferred from one configuration to the Base Configuration. If you want to see how it looks, you need to change the selected configuration and the vsys to the Base Configuration&amp;nbsp;from the bottom bar by going to the Objects Tab. This will filter and show you the objects and rules on the Base Configuration.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Expedition Base Configuration vsys.png" style="width: 512px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21154iB725A9A49658303D/image-size/large?v=v2&amp;amp;px=999" role="button" title="Expedition Base Configuration vsys.png" alt="Expedition Base Configuration vsys.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After you have created the final configuration, you have two options to deploy it. One option is a manual XML file export that can be deployed on the Palo Alto Networks device to which you are migrating, and the other option is to use API calls to send parts of the configuration or the whole configuration to the device&amp;nbsp;if that Palo Alto Networks device is already connected to Expedition.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;Find Duplicates After the Merge and Removing Them&lt;/H4&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It is recommended that you run another check for duplicates and remove or merge them after a configuration migration. A common scenario is to have duplicates amongst objects, services, and/or interfaces.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Using the dashboard from within the project, it will tell you how many duplicated objects you have in your current configuration. You can click on the duplicate object to go to the object view, and Expedition will filter by duplicate and by name predefined filter.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Expedition Project Statistics Duplicated.png" style="width: 629px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21155i1C6D6542972B881D/image-dimensions/629x334?v=v2" width="629" height="334" role="button" title="Expedition Project Statistics Duplicated.png" alt="Expedition Project Statistics Duplicated.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Next, check the duplicated services to demonstrate the workflow to follow and get rid of them.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Expedition Services tab.png" style="width: 512px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21156i61B6E8799F5C1449/image-size/large?v=v2&amp;amp;px=999" role="button" title="Expedition Services tab.png" alt="Expedition Services tab.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The object in Pink is a Shared object, so that means you have selected the vsys equal to all from the bottom bar. This will do a search across all the vsys/DG to find objects seen more than once.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;In our example, we want to keep the object that already exists as Shared and make all the references within the vsys/DG points after the merge to the Shared object only and finally the duplicated object out from the Shared will be removed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;First, select the duplicated objects you want to keep and then right-click and select Merge Options and “Set as Primary.” That will tell Expedition to&amp;nbsp;keep the one we set as Primary after Merging the duplicated objects.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Expedition Merge Options.png" style="width: 512px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21157iEB9CF5727DC474CB/image-size/large?v=v2&amp;amp;px=999" role="button" title="Expedition Merge Options.png" alt="Expedition Merge Options.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When the object has been set as Primary, you will notice a new icon appear.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Expedition Primary Icon.png" style="width: 512px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21158iBEFF1EE00B45B609/image-size/large?v=v2&amp;amp;px=999" role="button" title="Expedition Primary Icon.png" alt="Expedition Primary Icon.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now you can apply the Merge type. In our case, we will use Merge by Name and Value to validate only the same duplicated object is merged. Right-click and select “Merge” then click “By Name &amp;amp; Value.” This will be applied to the selected objects or, in case you didn’t select any, it will be applied to all the results from the filter applied.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can change the filter and add a predefined filter to show only the duplicated services by name only and then apply the merge by the same concept, only by name as well.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;All this can be done with the right-click “Select predefined filter.”&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;Generating the Output&lt;/H4&gt;
&lt;P&gt;When you are finished cleaning your configuration, it’s time to get the results and export from Expedition and import into your Palo Alto Networks device (Firewall or Panorama).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Navigate to the Export TAB.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Under the Mapping Tab, there is a button at the bottom bar-left titled “Generate XML &amp;amp; SET Output.” By pressing this button, Expedition will generate a XML configuration file and based on that configuration (and using a script called Pan-Python made by Kevin Steves &lt;A title="Multi-tool for PAN-OS, Panorama, WildFire and AutoFocus | GitHub" href="https://github.com/kevinsteves/pan-python" target="_self"&gt;https://github.com/kevinsteves/pan-python&lt;/A&gt;) it will generate the Set commands as well. After the generation, a new window with the download links will appear. Click the Downloads button to get access to that window as well.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Expedition Downloads.png" style="width: 512px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21159i86239666288D7384/image-size/large?v=v2&amp;amp;px=999" role="button" title="Expedition Downloads.png" alt="Expedition Downloads.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can generate API Calls to be sent to your devices in case you created them before and you added to the project you are working on. In that case, you will need to go under the tab titled, “API Output Manager.”&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here, you have several options. We will start covering Atomic and Subatomic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Atomic calls will be API calls where with a single API call will add all the address, for instance, to a specific vsys/DG. If you select subatomic, you will get one API call by element you have. If you have 500 addresses, you will get 500 API calls, one for each address. With Atomic, you will get just one API call containing the 500 addresses inside.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Step One:&lt;/STRONG&gt; Click on “Atomic” or “Subatomic” and click the “Step 1” button to create all the API calls.&lt;/P&gt;
&lt;P&gt;After that, the ID of each API call will tell you the order in which you have to send the API call. Yes, order matters. If you don’t select any, all API calls will be sent in the proper order.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Step Two:&lt;/STRONG&gt; Click “Step 2” button and select the DEVICE where you want to send the API calls and send them all.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Expedition Send API Calls.png" style="width: 472px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21160iECFD3B4E6CB9D697/image-size/large?v=v2&amp;amp;px=999" role="button" title="Expedition Send API Calls.png" alt="Expedition Send API Calls.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After the API call is sent, you will get the response from the device itself. If it was successful, you will see in the output.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Expedition API Call Notice.png" style="width: 512px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21161i09EEDBC690FCB8AD/image-size/large?v=v2&amp;amp;px=999" role="button" title="Expedition API Call Notice.png" alt="Expedition API Call Notice.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;Appendix A: Import&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;Importing CSV files&lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From within a project, it's possible to import CSV files containing objects that you want to add to you current configuration.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;Requirements&lt;/H4&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You must have a configuration previously loaded in order to import something else on top by using CSV files.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How the CSV file must be created:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The character used to split by columns is the semi-colon “;”&lt;/LI&gt;
&lt;LI&gt;The character used to split members inside a column is the comma “,”&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;Process&lt;/H4&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Select the object type you want to import. Example: Static Routes&lt;/LI&gt;
&lt;LI&gt;Select the CSV file from your laptop&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Expedition Source Object Import.png" style="width: 512px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21162i33BA8B8BAE2CC632/image-size/large?v=v2&amp;amp;px=999" role="button" title="Expedition Source Object Import.png" alt="Expedition Source Object Import.png" /&gt;&lt;/span&gt;&lt;/LI&gt;
&lt;LI&gt;Map your columns with the predefined fields from the right panel&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Expedition Data Preview Mapping.png" style="width: 512px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21163i52406F5D2750E563/image-size/large?v=v2&amp;amp;px=999" role="button" title="Expedition Data Preview Mapping.png" alt="Expedition Data Preview Mapping.png" /&gt;&lt;/span&gt;&lt;/LI&gt;
&lt;LI&gt;Select where to import the new data loaded from the CSV and mapped&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Expedition Destination.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21164i03F34B118C349E6D/image-size/large?v=v2&amp;amp;px=999" role="button" title="Expedition Destination.png" alt="Expedition Destination.png" /&gt;&lt;/span&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;MARK&gt;In this example, routes are part of Templates and need to be imported into a Virtual-Router. Plus, select the virtual-system where your VR is located. Then click Import Data.&lt;/MARK&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Order matters! If want to import Service Groups, you need to first import the services used on those Groups or the import will not be successful.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;Importing an IronSkillet Day1 Configuration&lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;IronSkillet is a project made by Palo Alto Networks to create a configuration that is already configured with some of the best practices recommended by our security experts. If you need to add a Base Configuration into Expedition to use it as a base to migrate something else, it's very simple now with the integration built in Expedition.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;Process&lt;/H4&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Create a project and click to get in. After you enter the project, go to IMPORT. Then click the Tab title "Iron-Skillet."&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Expedition IronSkillet View.png" style="width: 512px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21165i9F1912E1A3B0D538/image-size/large?v=v2&amp;amp;px=999" role="button" title="Expedition IronSkillet View.png" alt="Expedition IronSkillet View.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From here, you can configure some parameters before the configuration is created. You can modify the parameters by hand, or, if you have an IronSkillet configuration file, you can load it to automatically fill the fields.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Select the Configuration Type (Firewall or Panorama) this will generate the type of configuration selected.&lt;/LI&gt;
&lt;LI&gt;PAN-OS Version. You can select if the configuration you need but it must be 8.0 or 8.1 or X.X&lt;/LI&gt;
&lt;LI&gt;If you have an IronSkillet configuration, you can click LOAD FROM CLIPBOARD and paste the content from the file and then click SAVE. That will automatically fill the fields configured.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Example: &lt;A href="https://raw.githubusercontent.com/PaloAltoNetworks/iron-skillet/panos_v8.0/my_configs/sample-mgmt-dhcp/my_variables.py" target="_blank" rel="noopener"&gt;https://raw.githubusercontent.com/PaloAltoNetworks/iron-skillet/panos_v8.0/my_configs/sample-mgmt-dhcp/my_variables.py&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Expedition Copyright 2018 Palo Alto Networks.png" style="width: 730px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21168iC8D65B11F48DA4ED/image-size/large?v=v2&amp;amp;px=999" role="button" title="Expedition Copyright 2018 Palo Alto Networks.png" alt="Expedition Copyright 2018 Palo Alto Networks.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Expedition Import Palo Alto IronSkillet.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21167i2AF7086F2D7A7A4F/image-size/large?v=v2&amp;amp;px=999" role="button" title="Expedition Import Palo Alto IronSkillet.png" alt="Expedition Import Palo Alto IronSkillet.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After the changes are made, you have to click on GENERATE CONFIG AND IMPORT. This will create a Palo Alto Networks configuration file based on your selection (Firewall or Panorama) and with the selected version and all the changes made in the parameters will be applied to it. After IronSkillet generates the new configuration, Expedition will Encrypt it and automatically imported into the Project. If this is the first Palo Alto Networks configuration loaded on the Project, Expedition will set it as the Base Configuration.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;Revision History&lt;/H3&gt;
&lt;TABLE&gt;
&lt;TBODY&gt;
&lt;TR bgcolor="#0995c8"&gt;
&lt;TD&gt;
&lt;P&gt;&lt;FONT color="ffffff"&gt;&lt;STRONG&gt;Date&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;FONT color="ffffff"&gt;&lt;STRONG&gt;Revision&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;FONT color="ffffff"&gt;&lt;STRONG&gt;Comment&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;June 22, 2018&lt;/TD&gt;
&lt;TD&gt;A&lt;/TD&gt;
&lt;TD&gt;First release of this document.&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;October 16,2018&lt;/TD&gt;
&lt;TD&gt;B&lt;/TD&gt;
&lt;TD&gt;Added Appendix A&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;April 1,2019&lt;/TD&gt;
&lt;TD&gt;C&lt;/TD&gt;
&lt;TD&gt;Updated Screenshots&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;August 27, 2019&lt;/TD&gt;
&lt;TD&gt;D&lt;/TD&gt;
&lt;TD&gt;Created LIVEcommunity Article and Editorial Revisions&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;</description>
      <pubDate>Thu, 29 Aug 2019 18:51:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-articles/expedition-user-guide-v1-2/ta-p/285157</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2019-08-29T18:51:50Z</dc:date>
    </item>
    <item>
      <title>Re: Expedition User Guide v1.2</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-articles/expedition-user-guide-v1-2/tac-p/1224051#M522</link>
      <description>&lt;P&gt;hi,my&amp;nbsp;&lt;SPAN&gt;expedition version is:1.2.102&lt;BR /&gt;In expedition-device，The device has been added, but the system version and configuration cannot be read and no&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV class="lia-quilt-row lia-quilt-row-message-main"&gt;
&lt;DIV class="lia-quilt-column lia-quilt-column-24 lia-quilt-column-single lia-quilt-column-message-main-content"&gt;
&lt;DIV class="lia-quilt-column-alley lia-quilt-column-alley-single"&gt;
&lt;DIV class="lia-message-body-wrapper lia-component-message-view-widget-body"&gt;
&lt;DIV id="bodyDisplay_19" class="lia-message-body"&gt;
&lt;DIV class="lia-message-body-content"&gt;
&lt;P&gt;any error dispaly, why?&lt;BR /&gt;&lt;SPAN&gt;I open the project, click on import, select the added device, click on ImportDevice, and it prompts:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;There is no configuration downloaded for the Device [PA-3020].&lt;BR /&gt;Import cancelled.&lt;/SPAN&gt;&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Tue, 18 Mar 2025 01:59:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-articles/expedition-user-guide-v1-2/tac-p/1224051#M522</guid>
      <dc:creator>yulog1</dc:creator>
      <dc:date>2025-03-18T01:59:54Z</dc:date>
    </item>
  </channel>
</rss>

