<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Checkpoint migration to PA-820 in Expedition Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/expedition-discussions/checkpoint-migration-to-pa-820/m-p/257648#M1427</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Im trying to migrate a CheckPoint to PA-820, but am having issues importing the CheckPoint json config files.&amp;nbsp; I get the error:&lt;/P&gt;
&lt;P&gt;JSON error - Syntax error, malformed JSON&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There are 439 security rules, 36 NAT rules&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have access to the new PA-820, but I don't have access to the CheckPoint - I request info, and hopefully it is executed and sent back to me as requested.&lt;/P&gt;
&lt;P&gt;I have Expedition v1.1.13 running on VMWorkstation.&lt;/P&gt;
&lt;P&gt;I've added the PA-820 device and seems to be linked sufficiently.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've imported a sample palo alto config into a test project, and see the Project Statistics sufficiently.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I requested the CheckPoint admin run these commands, and send me the files:&lt;/P&gt;
&lt;P&gt;For the Security Rules:&lt;/P&gt;
&lt;P&gt;mgmt_cli show access-rulebase name "yourRulebaseName" details-level "full" use-object-dictionary true --format json&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For the NAT rules:&lt;/P&gt;
&lt;P&gt;mgmt_cli show nat-rulebase package "yourRulebaseName" details-level "full" use-object-dictionary true --format json&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For the Routes:&lt;/P&gt;
&lt;P&gt;Routes file can be created by running from the Firewall the command&amp;nbsp;&lt;STRONG&gt;"netstat -nr"&lt;/STRONG&gt;&amp;nbsp;or&amp;nbsp;&lt;STRONG&gt;"show route all"&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have the csv export of the Security and NAT rules, as well as the config file.&lt;/P&gt;
&lt;P&gt;The config file shows:&amp;nbsp;Language version: 13.1v1 (is that the Checkpoint software version?)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The security rules.json file has source and destination fields that seem to be some kind of object database key.&amp;nbsp; Could it be they didnt run the object-dictionary part of the command?&lt;/P&gt;
&lt;P&gt;"source" : [ "97aeb369-9aea-11d5-bd16-0090272ccb30" ]&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Help would be greatly appreciated.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 15 Apr 2019 20:28:48 GMT</pubDate>
    <dc:creator>Solomon_Grable</dc:creator>
    <dc:date>2019-04-15T20:28:48Z</dc:date>
    <item>
      <title>Checkpoint migration to PA-820</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/checkpoint-migration-to-pa-820/m-p/257648#M1427</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Im trying to migrate a CheckPoint to PA-820, but am having issues importing the CheckPoint json config files.&amp;nbsp; I get the error:&lt;/P&gt;
&lt;P&gt;JSON error - Syntax error, malformed JSON&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There are 439 security rules, 36 NAT rules&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have access to the new PA-820, but I don't have access to the CheckPoint - I request info, and hopefully it is executed and sent back to me as requested.&lt;/P&gt;
&lt;P&gt;I have Expedition v1.1.13 running on VMWorkstation.&lt;/P&gt;
&lt;P&gt;I've added the PA-820 device and seems to be linked sufficiently.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've imported a sample palo alto config into a test project, and see the Project Statistics sufficiently.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I requested the CheckPoint admin run these commands, and send me the files:&lt;/P&gt;
&lt;P&gt;For the Security Rules:&lt;/P&gt;
&lt;P&gt;mgmt_cli show access-rulebase name "yourRulebaseName" details-level "full" use-object-dictionary true --format json&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For the NAT rules:&lt;/P&gt;
&lt;P&gt;mgmt_cli show nat-rulebase package "yourRulebaseName" details-level "full" use-object-dictionary true --format json&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For the Routes:&lt;/P&gt;
&lt;P&gt;Routes file can be created by running from the Firewall the command&amp;nbsp;&lt;STRONG&gt;"netstat -nr"&lt;/STRONG&gt;&amp;nbsp;or&amp;nbsp;&lt;STRONG&gt;"show route all"&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have the csv export of the Security and NAT rules, as well as the config file.&lt;/P&gt;
&lt;P&gt;The config file shows:&amp;nbsp;Language version: 13.1v1 (is that the Checkpoint software version?)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The security rules.json file has source and destination fields that seem to be some kind of object database key.&amp;nbsp; Could it be they didnt run the object-dictionary part of the command?&lt;/P&gt;
&lt;P&gt;"source" : [ "97aeb369-9aea-11d5-bd16-0090272ccb30" ]&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Help would be greatly appreciated.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Apr 2019 20:28:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/checkpoint-migration-to-pa-820/m-p/257648#M1427</guid>
      <dc:creator>Solomon_Grable</dc:creator>
      <dc:date>2019-04-15T20:28:48Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint migration to PA-820</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/checkpoint-migration-to-pa-820/m-p/257659#M1429</link>
      <description>&lt;P&gt;you will need to validate the json formatting. You can try to open the file in firefox for example which provides debug messages as to the source of the malformed json format.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Otherwise if you email the json file to fwmigrate&amp;nbsp;@paloaltonetworks.com I can look at the file.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Apr 2019 23:15:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/checkpoint-migration-to-pa-820/m-p/257659#M1429</guid>
      <dc:creator>sjanita</dc:creator>
      <dc:date>2019-04-15T23:15:15Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint migration to PA-820</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/checkpoint-migration-to-pa-820/m-p/257745#M1437</link>
      <description>&lt;P&gt;Thanks, the leading text in the file:&lt;/P&gt;
&lt;PRE&gt;Username: &lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;before the first opening bracket was the issue as you suggested.&lt;/P&gt;
&lt;P&gt;The files imported after removing that text before the first opening {&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 16 Apr 2019 20:53:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/checkpoint-migration-to-pa-820/m-p/257745#M1437</guid>
      <dc:creator>Solomon_Grable</dc:creator>
      <dc:date>2019-04-16T20:53:30Z</dc:date>
    </item>
  </channel>
</rss>

