<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 1 firewall to 2 vsys? in Expedition Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/expedition-discussions/1-firewall-to-2-vsys/m-p/271507#M1711</link>
    <description>&lt;P&gt;Thanks for your reply sjanita.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am planning on going from a single checkpoint to 2 vsys which reside in 2 seperate device groups.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I imaine that the process will be to injest 2 route tables and CSV's into MT then maybe use auto assign to re-assign zones, then possibly use the filtering to remove the irrellevant rules for each new firewall.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Or is there a simpler way as you mentioned?&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Thu, 20 Jun 2019 00:52:26 GMT</pubDate>
    <dc:creator>timedout</dc:creator>
    <dc:date>2019-06-20T00:52:26Z</dc:date>
    <item>
      <title>1 firewall to 2 vsys?</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/1-firewall-to-2-vsys/m-p/271232#M1704</link>
      <description>&lt;P&gt;Hi Guys&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does anyone have a method to migrate from a single firewall (specifically checkpoint) to two or more vsys?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jun 2019 08:49:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/1-firewall-to-2-vsys/m-p/271232#M1704</guid>
      <dc:creator>timedout</dc:creator>
      <dc:date>2019-06-19T08:49:15Z</dc:date>
    </item>
    <item>
      <title>Re: 1 firewall to 2 vsys?</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/1-firewall-to-2-vsys/m-p/271379#M1708</link>
      <description>&lt;P&gt;you'll have to decide on your desried design goal - are you planning to use VSYS or are you ok with using multiple virtual routers to isolate traffic? if you will be using panorama you'll have to decide if the vsys will be in the same or different device groups (DG).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is your plan to split some policies and objects between the 2 vsys? If you will be using Panorama are your plans to have both vsys in the same or different device groups?&lt;/P&gt;
&lt;P&gt;if the VSYS will be members of different DG you can import all policies and objects into shared at first then add VSYS specific policies and objects afterwards.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jun 2019 15:46:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/1-firewall-to-2-vsys/m-p/271379#M1708</guid>
      <dc:creator>sjanita</dc:creator>
      <dc:date>2019-06-19T15:46:51Z</dc:date>
    </item>
    <item>
      <title>Re: 1 firewall to 2 vsys?</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/1-firewall-to-2-vsys/m-p/271507#M1711</link>
      <description>&lt;P&gt;Thanks for your reply sjanita.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am planning on going from a single checkpoint to 2 vsys which reside in 2 seperate device groups.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I imaine that the process will be to injest 2 route tables and CSV's into MT then maybe use auto assign to re-assign zones, then possibly use the filtering to remove the irrellevant rules for each new firewall.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Or is there a simpler way as you mentioned?&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jun 2019 00:52:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/1-firewall-to-2-vsys/m-p/271507#M1711</guid>
      <dc:creator>timedout</dc:creator>
      <dc:date>2019-06-20T00:52:26Z</dc:date>
    </item>
    <item>
      <title>Re: 1 firewall to 2 vsys?</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/1-firewall-to-2-vsys/m-p/272338#M1721</link>
      <description>&lt;P&gt;your workflow is correct - import 2 separate route files into 2 separate VR's.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When you initiate the autozoneassign, you will be prompted to choose which VR to use as the routing reference. prior to running the autozoneassign you will need to assign the interfaces to the appropriate VR's as well as those IP's assigned to the interfaces will be used as local routes and will also be used in the autozoneassign calculations.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jun 2019 20:48:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/1-firewall-to-2-vsys/m-p/272338#M1721</guid>
      <dc:creator>sjanita</dc:creator>
      <dc:date>2019-06-21T20:48:32Z</dc:date>
    </item>
    <item>
      <title>Re: 1 firewall to 2 vsys?</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/1-firewall-to-2-vsys/m-p/272997#M1731</link>
      <description>&lt;P&gt;Thank you&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/41"&gt;@sjanita&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jun 2019 01:55:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/1-firewall-to-2-vsys/m-p/272997#M1731</guid>
      <dc:creator>timedout</dc:creator>
      <dc:date>2019-06-26T01:55:57Z</dc:date>
    </item>
  </channel>
</rss>

