<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Expedition bugs? in Expedition Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-bugs/m-p/247068#M1043</link>
    <description>&lt;P&gt;Version could have been 1.1.3 not 1.0.107&lt;/P&gt;</description>
    <pubDate>Wed, 23 Jan 2019 03:58:14 GMT</pubDate>
    <dc:creator>sidetrack</dc:creator>
    <dc:date>2019-01-23T03:58:14Z</dc:date>
    <item>
      <title>Expedition bugs?</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-bugs/m-p/247067#M1042</link>
      <description>&lt;P&gt;I stumbled across two potential bugs in Expedition 1.0.107 the other day, using&amp;nbsp;it to&amp;nbsp;merge&amp;nbsp;duplicates and unused objects from a Panorama (8.1.5) config.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. Editing a config that originally contained over 10,000 objects (across different DGs) resulted in some shared objects being defined twice - this was after merging duplicate and removing unused objects, the config imported to Panorama would not commit and resulted in an error "objecet already exists". We found the object was defined twice in the shared candidate config:&lt;/P&gt;
&lt;PRE&gt;&amp;nbsp; &amp;lt;shared&amp;gt;
&amp;nbsp; &amp;nbsp; &amp;lt;address&amp;gt;
&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;lt;entry name="test.com"&amp;gt;
&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;lt;fqdn&amp;gt;test.com&amp;lt;/fqdn&amp;gt;
&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;lt;/entry&amp;gt;
&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;lt;entry name="test.com"&amp;gt;
&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;lt;fqdn&amp;gt;test.com&amp;lt;/fqdn&amp;gt;
&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;lt;/entry&amp;gt;
&amp;nbsp; &amp;nbsp; &amp;lt;/address&amp;gt;
&amp;nbsp; &amp;lt;/shared&amp;gt;&lt;/PRE&gt;
&lt;P&gt;&lt;SPAN&gt;And also defined twice within the shared config in the output from Expedition:&lt;/SPAN&gt;&lt;/P&gt;
&lt;PRE&gt;&amp;lt;entry name="test.com"&amp;gt;&amp;lt;fqdn&amp;gt;test.com&amp;lt;/fqdn&amp;gt;&amp;lt;/entry&amp;gt;&amp;lt;snip/&amp;gt;&amp;lt;entry name="test.com"&amp;gt;&amp;lt;fqdn&amp;gt;test.com&amp;lt;/fqdn&amp;gt;&amp;lt;/entry&amp;gt;&lt;/PRE&gt;
&lt;P&gt;&lt;SPAN&gt;We couldn't manually remove the duplicates from the XML as there were at least two more if not hundereds of these duplicated entries. After some manipulation of the source XML I got the object count down to about 4,000 before merging duplicates in Expedition, after which the exported config was fine until we hit the next bug.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;2. Authentication rules failed to commit due to an invalid log-authentication-timeout. Appears&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Expedition introduced this log-authentication-timeout setting with no values as it did not exist in the imported config and was not accepted by Panorama 8.1.5:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;&amp;nbsp;&amp;lt;pre-rulebase&amp;gt;
&amp;nbsp;&amp;nbsp;&amp;lt;authentication&amp;gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;lt;rules&amp;gt;&amp;lt;entry name="example"&amp;gt;&amp;lt;snip/&amp;gt;&amp;lt;log-authentication-timeout/&amp;gt;&amp;lt;timeout&amp;gt;60&amp;lt;/timeout&amp;gt;&amp;lt;snip/&amp;gt;&amp;lt;/entry&amp;gt;&amp;lt;/rules&amp;gt;
&amp;nbsp;&amp;nbsp;&amp;lt;/authentication&amp;gt;
&amp;nbsp;&amp;lt;/pre-rulebase&amp;gt;&lt;/PRE&gt;
&lt;P&gt;&lt;SPAN&gt;The workaround was to remove the log-authentication-timeout entries in the XML.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/45"&gt;@aestevez&lt;/a&gt;&amp;nbsp;I can&amp;nbsp;share the raw and optimised configs if you need.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jan 2019 03:56:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-bugs/m-p/247067#M1042</guid>
      <dc:creator>sidetrack</dc:creator>
      <dc:date>2019-01-23T03:56:38Z</dc:date>
    </item>
    <item>
      <title>Re: Expedition bugs?</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-bugs/m-p/247068#M1043</link>
      <description>&lt;P&gt;Version could have been 1.1.3 not 1.0.107&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jan 2019 03:58:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-bugs/m-p/247068#M1043</guid>
      <dc:creator>sidetrack</dc:creator>
      <dc:date>2019-01-23T03:58:14Z</dc:date>
    </item>
    <item>
      <title>Re: Expedition bugs?</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-bugs/m-p/247116#M1047</link>
      <description>&lt;P&gt;Yes, please. Share those with us at fwmigrate at paloaltonetworks dot com.&lt;/P&gt;
&lt;P&gt;We will take a look into it&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jan 2019 10:45:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-bugs/m-p/247116#M1047</guid>
      <dc:creator>dgildelaig</dc:creator>
      <dc:date>2019-01-23T10:45:12Z</dc:date>
    </item>
  </channel>
</rss>

