<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Shared rulebase to vsys in Expedition Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/expedition-discussions/shared-rulebase-to-vsys/m-p/256056#M1340</link>
    <description>&lt;P&gt;I was trying to avoid that &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;A good chunk of my rules were hand-rolled in Expedition, stupidly evolving this unusable policy.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I need a way to export these orphaned shared rules, if there&amp;nbsp; was a way to move them from shared to vsys1. We can do the reverse (convert a rule in vsys1 to shared) but not the other way around.&lt;/P&gt;</description>
    <pubDate>Thu, 04 Apr 2019 09:53:09 GMT</pubDate>
    <dc:creator>sidetrack</dc:creator>
    <dc:date>2019-04-04T09:53:09Z</dc:date>
    <item>
      <title>Shared rulebase to vsys</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/shared-rulebase-to-vsys/m-p/255888#M1329</link>
      <description>&lt;P&gt;I have ended up in a bit of an odd situation with an undesirable result &lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the process of importing CSV's from an unsupported source, I have ended up importing an entire rulebase into the "shared" VSYS of a standalone base firewall config. This might be OK for objects, or a rulebase in Panorama, but not a valid config for a standalone device.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To make matters worse, I have augmented the policy with a ton of new rules from a design document - mostly manual work. Many hours have gone into this and it's now ready to export to the target gateway.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Only one thing -&amp;nbsp;there is no shared policy in the export (I guess because it's not a valid thing).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The policy can still be editied in config.xml -&amp;gt; shared, all I need is to move the rules to vsys1 or get them in the exported xml. I don't have time to build this rulebase again.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Help me&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11906"&gt;@alestevez&lt;/a&gt;,&amp;nbsp;you're my only hope!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2019 12:24:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/shared-rulebase-to-vsys/m-p/255888#M1329</guid>
      <dc:creator>sidetrack</dc:creator>
      <dc:date>2019-04-03T12:24:52Z</dc:date>
    </item>
    <item>
      <title>Re: Shared rulebase to vsys</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/shared-rulebase-to-vsys/m-p/255928#M1331</link>
      <description>&lt;P&gt;you are right, you could cut the policy from shared and paste into the rulebase under vsys1 and that's it &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; Only check to do if there is a rulename duplicated after the paste &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2019 15:57:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/shared-rulebase-to-vsys/m-p/255928#M1331</guid>
      <dc:creator>alestevez</dc:creator>
      <dc:date>2019-04-03T15:57:19Z</dc:date>
    </item>
    <item>
      <title>Re: Shared rulebase to vsys</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/shared-rulebase-to-vsys/m-p/256008#M1334</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11906"&gt;@alestevez&lt;/a&gt;&amp;nbsp;! Unfortunately I am unable to cut and paste the rulebase in Expedition - ctrl-c / ctrl-v doesn't seem to work and there's no cut/paste in the rule context menus.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The Move button would be great if it supported move to a different rulebase like Panorama but it doesn't have the option.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any other ideas?&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2019 23:05:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/shared-rulebase-to-vsys/m-p/256008#M1334</guid>
      <dc:creator>sidetrack</dc:creator>
      <dc:date>2019-04-03T23:05:42Z</dc:date>
    </item>
    <item>
      <title>Re: Shared rulebase to vsys</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/shared-rulebase-to-vsys/m-p/256033#M1335</link>
      <description>&lt;P&gt;Unless there is a bug in the version you are using, not sure how your security rules were imported to 'shared' as choosing that option will not import into the target config.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Per the attached screenshot you need to choose from the available vsys to import the security policies into.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you post a screenshot showing the security policies were added to shared?&lt;/P&gt;</description>
      <pubDate>Thu, 04 Apr 2019 06:38:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/shared-rulebase-to-vsys/m-p/256033#M1335</guid>
      <dc:creator>sjanita</dc:creator>
      <dc:date>2019-04-04T06:38:43Z</dc:date>
    </item>
    <item>
      <title>Re: Shared rulebase to vsys</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/shared-rulebase-to-vsys/m-p/256042#M1336</link>
      <description>&lt;P&gt;I'm running&amp;nbsp;expedition-beta/unknown 1.1.11 amd64&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I can replicate in an entirely new project, importing a VA base config (it can only have one vsys &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; )&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It has existing rules in vsys1, but we'll demonstrate by importing a simple&amp;nbsp;CSV into the shared vsys:&lt;/P&gt;
&lt;DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;dns;trusted;dns-server;Internet;8.8.8.8;dns;permit&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;This won't work if no vsys is selected (all), the list pops up and you can select from shared and vsys1 - even though shared is not supported for Security Rules.&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="Import CSV, must select from shared or vsys1" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/19399iEC02F3A0AD932ADB/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="2019-04-04.png" alt="Import CSV, must select from shared or vsys1" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Import CSV, must select from shared or vsys1&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="select shared (oops!)" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/19401iF3F2D77D1AC971FE/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="2019-04-04 (1).png" alt="select shared (oops!)" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;select shared (oops!)&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="it worked...?" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/19402i40EDC12E2645FC63/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="2019-04-04 (2).png" alt="it worked...?" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;it worked...?&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="here be the shared rule..." style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/19403i8DE78C57B3AD6FF6/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="2019-04-04 (3).png" alt="here be the shared rule..." /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;here be the shared rule...&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="unset base config, no shared policy to export :(" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/19400iC876E926C79FEB51/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="2019-04-04 (4).png" alt="unset base config, no shared policy to export :(" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;unset base config, no shared policy to export &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="no shared  policy in output (it's not exactly valid)" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/19404iF62FA86D573EFDC9/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Untitled.png" alt="no shared  policy in output (it's not exactly valid)" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;no shared  policy in output (it's not exactly valid)&lt;/span&gt;&lt;/span&gt;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Thu, 04 Apr 2019 07:51:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/shared-rulebase-to-vsys/m-p/256042#M1336</guid>
      <dc:creator>sidetrack</dc:creator>
      <dc:date>2019-04-04T07:51:06Z</dc:date>
    </item>
    <item>
      <title>Re: Shared rulebase to vsys</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/shared-rulebase-to-vsys/m-p/256053#M1338</link>
      <description>&lt;P&gt;what you can do is reimport the security policies but choose 'vsys 1' as your target.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you see those security policies in vsys 1, Then go back into the configuration and delete the rules listed in 'Shared'&lt;/P&gt;</description>
      <pubDate>Thu, 04 Apr 2019 09:15:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/shared-rulebase-to-vsys/m-p/256053#M1338</guid>
      <dc:creator>sjanita</dc:creator>
      <dc:date>2019-04-04T09:15:14Z</dc:date>
    </item>
    <item>
      <title>Re: Shared rulebase to vsys</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/shared-rulebase-to-vsys/m-p/256056#M1340</link>
      <description>&lt;P&gt;I was trying to avoid that &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;A good chunk of my rules were hand-rolled in Expedition, stupidly evolving this unusable policy.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I need a way to export these orphaned shared rules, if there&amp;nbsp; was a way to move them from shared to vsys1. We can do the reverse (convert a rule in vsys1 to shared) but not the other way around.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Apr 2019 09:53:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/shared-rulebase-to-vsys/m-p/256056#M1340</guid>
      <dc:creator>sidetrack</dc:creator>
      <dc:date>2019-04-04T09:53:09Z</dc:date>
    </item>
    <item>
      <title>Re: Shared rulebase to vsys</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/shared-rulebase-to-vsys/m-p/256057#M1341</link>
      <description>&lt;P&gt;Looking into it, will get back to you in a few mins&lt;/P&gt;</description>
      <pubDate>Thu, 04 Apr 2019 10:10:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/shared-rulebase-to-vsys/m-p/256057#M1341</guid>
      <dc:creator>sjanita</dc:creator>
      <dc:date>2019-04-04T10:10:01Z</dc:date>
    </item>
    <item>
      <title>Re: Shared rulebase to vsys</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/shared-rulebase-to-vsys/m-p/256058#M1342</link>
      <description>&lt;P&gt;here's one option you can try:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Filter the display to display only the 'Shared' policies (bottom right hand selection choose 'Shared')&lt;/P&gt;
&lt;P&gt;Choose 'Export to Excel' in the upper right hand corner menu&lt;/P&gt;
&lt;P&gt;After opening in excel, save the file to CSV format and reimport (using the import CSV option) into vsys1&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You will need to edit the CSV file and replace the commas with semi-colons which are the separators used by the CSV import&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This will include any changes you had made to those security policies. You will also have to perform those same steps to any objects (Address, groups, services groups) that were moved into shared.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Apr 2019 11:28:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/shared-rulebase-to-vsys/m-p/256058#M1342</guid>
      <dc:creator>sjanita</dc:creator>
      <dc:date>2019-04-04T11:28:50Z</dc:date>
    </item>
    <item>
      <title>Re: Shared rulebase to vsys</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/shared-rulebase-to-vsys/m-p/256063#M1345</link>
      <description>&lt;P&gt;Thanks for the tip sjanita!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Looks like this is my only option, although the individual cells have carriage returns for multiple entries. I'm sure with a bit of NP++-fu I can whip this into shape &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Apr 2019 11:40:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/shared-rulebase-to-vsys/m-p/256063#M1345</guid>
      <dc:creator>sidetrack</dc:creator>
      <dc:date>2019-04-04T11:40:32Z</dc:date>
    </item>
    <item>
      <title>Re: Shared rulebase to vsys</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/shared-rulebase-to-vsys/m-p/256533#M1354</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11906"&gt;@alestevez&lt;/a&gt;&amp;nbsp;I'm considering trying to do this in the DB instead, if there's a way I can dump the table that contains the invalid 'shared' polciy and import it into the vsys1 table?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any hints? &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Matt&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2019 05:49:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/shared-rulebase-to-vsys/m-p/256533#M1354</guid>
      <dc:creator>sidetrack</dc:creator>
      <dc:date>2019-04-08T05:49:01Z</dc:date>
    </item>
  </channel>
</rss>

