<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Issues getting a Checkpoint R80 config to load into the Migration tool. in Expedition Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/expedition-discussions/issues-getting-a-checkpoint-r80-config-to-load-into-the/m-p/215337#M2</link>
    <description>&lt;P&gt;The customer is using SmartCenter (not ProviderOne) and it appears that smartcenter uses some sort of quasi-global object repository that doesn’t export everything when you run the suggested export command in the Migration Tool (Expedition version). PSC's observed that only a subset of the object repository is exported into the config file.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any Help please?&amp;nbsp; Are we missing something?&lt;/P&gt;</description>
    <pubDate>Thu, 24 May 2018 15:33:42 GMT</pubDate>
    <dc:creator>plingeman</dc:creator>
    <dc:date>2018-05-24T15:33:42Z</dc:date>
    <item>
      <title>Issues getting a Checkpoint R80 config to load into the Migration tool.</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/issues-getting-a-checkpoint-r80-config-to-load-into-the/m-p/215337#M2</link>
      <description>&lt;P&gt;The customer is using SmartCenter (not ProviderOne) and it appears that smartcenter uses some sort of quasi-global object repository that doesn’t export everything when you run the suggested export command in the Migration Tool (Expedition version). PSC's observed that only a subset of the object repository is exported into the config file.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any Help please?&amp;nbsp; Are we missing something?&lt;/P&gt;</description>
      <pubDate>Thu, 24 May 2018 15:33:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/issues-getting-a-checkpoint-r80-config-to-load-into-the/m-p/215337#M2</guid>
      <dc:creator>plingeman</dc:creator>
      <dc:date>2018-05-24T15:33:42Z</dc:date>
    </item>
    <item>
      <title>Re: Issues getting a Checkpoint R80 config to load into the Migration tool.</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/issues-getting-a-checkpoint-r80-config-to-load-into-the/m-p/215443#M3</link>
      <description>&lt;P&gt;The problem was in the Checkpoint side Paul? &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 25 May 2018 02:14:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/issues-getting-a-checkpoint-r80-config-to-load-into-the/m-p/215443#M3</guid>
      <dc:creator>alestevez</dc:creator>
      <dc:date>2018-05-25T02:14:33Z</dc:date>
    </item>
    <item>
      <title>Re: Issues getting a Checkpoint R80 config to load into the Migration tool.</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/issues-getting-a-checkpoint-r80-config-to-load-into-the/m-p/215965#M23</link>
      <description>&lt;P&gt;I think we close this issue. The last single files you sent me this morning as per my request worked, Expedition took them, load the configuration without issues. &lt;U&gt;I got it loaded and all consistent&lt;/U&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- I have done a quick review and it looks clean&lt;/P&gt;
&lt;P&gt;- Daniel please review it, I think now you can actually start your migration clean-up process with this.&lt;/P&gt;
&lt;P&gt;- You got all objects, object-groups as we should, all the Security Rules and NATs as well as the extra clone created by the tool.&lt;/P&gt;
&lt;P&gt;- You got 4 objects “1.1.1.1” that are used, this is normal as they might belong to a Domain type object on Checkpoint, you need to find the value of this object with the customer and replace the 1.1.1.1.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;U&gt;So, what was the issue?&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;As per my findings, the customer was pulling the configuration from the console (CLI) with wrong parameters. Customer was pulling the right Security Rule set from the right Firewall/gateway but was pulling the NAT rules set from another firewall gateway.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;The result of this of course were inconstancies on the loaded configuration to expedition, lots of missing groups, objects, NATs etc.&lt;/P&gt;
&lt;P&gt;This usually happens when we use Copy and paste and rush without seen the exact details of the command.&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;The second problem I need to Share with Albert.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;- We did follow the process lay on the guide to migrate R80. The breaking down of the “.jason” as per limits 400 for security rules-set and 500 for NAT rules-set did not work on Expedition.&lt;/P&gt;
&lt;P&gt;- I had to ask the customer to create a single “.jason” file for security rules-set and a single file for NAT rules-set.&lt;/P&gt;
&lt;P&gt;- Expedition took it and load it fine.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That is all I have on this, please let me know if any comments.&lt;/P&gt;
&lt;P&gt;I will update the Blog Paul created with the solution found. Thank you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;---------------- Alex LLabres&amp;nbsp;&lt;BR /&gt; &lt;BR /&gt; &lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 May 2018 15:57:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/issues-getting-a-checkpoint-r80-config-to-load-into-the/m-p/215965#M23</guid>
      <dc:creator>plingeman</dc:creator>
      <dc:date>2018-05-30T15:57:51Z</dc:date>
    </item>
    <item>
      <title>Re: Issues getting a Checkpoint R80 config to load into the Migration tool.</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/issues-getting-a-checkpoint-r80-config-to-load-into-the/m-p/215978#M25</link>
      <description>&lt;P&gt;where you checking the zip file didnt have any folder inside? It must be zipped with&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;zip rules.zip *&lt;/PRE&gt;
&lt;P&gt;In that folder should be all the .json files plus a file called "order" within it the list in order of the json files like&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;rules_0_400.json
rules_401_650.json&lt;/PRE&gt;
&lt;P&gt;If you used MacOS probably will create a folder inside an invalide the zip file for Expedition&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Remember to do it from cli to ensure no folder is created inside the ZIP.&lt;/P&gt;</description>
      <pubDate>Wed, 30 May 2018 17:51:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/issues-getting-a-checkpoint-r80-config-to-load-into-the/m-p/215978#M25</guid>
      <dc:creator>alestevez</dc:creator>
      <dc:date>2018-05-30T17:51:35Z</dc:date>
    </item>
    <item>
      <title>Re: Issues getting a Checkpoint R80 config to load into the Migration tool.</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/issues-getting-a-checkpoint-r80-config-to-load-into-the/m-p/216140#M46</link>
      <description>&lt;P&gt;There where 2 issues on this case:&lt;BR /&gt;-----------------------------------------&lt;/P&gt;
&lt;P&gt;1) The issue initially was pulling the information from the correct Checkpoint Security Gateway/Firewall BUT by mistake they where pulling the NAT coonfiguration from the wrong Source (Diffrerent Firewall) using the guide command below:&lt;/P&gt;
&lt;P&gt;The correct Security rules firewall set is : "Internet Security"&lt;/P&gt;
&lt;P&gt;mgmt_cli show access-rulebase offset 0 limit 400 name "Internet Security" details-level "full" use-object-dictionary true --format json &amp;gt; RuleSet_0_400.json&lt;BR /&gt;mgmt_cli show access-rulebase offset 401 limit 400 name "Internet Security" details-level "full" use-object-dictionary true --format json &amp;gt; RuleSet_401_800.json&lt;BR /&gt;mgmt_cli show access-rulebase offset 801 limit 400 name "Internet Security" details-level "full" use-object-dictionary true --format json &amp;gt; RuleSet_801_1200.json&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;U&gt;giving the files :&lt;/U&gt;&lt;BR /&gt;RuleSet_0_400.json&lt;BR /&gt;RuleSet_401_800.json&lt;BR /&gt;RuleSet_801_1200.json&lt;/P&gt;
&lt;P&gt;we ZIP them into -&amp;gt; RuleSet_Security.zip&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;The NATs where pulled from the wrong Firewall&lt;/STRONG&gt;&lt;BR /&gt;mgmt_cli show nat-rulebase offset 0 limit 500 package "Bill_Fw" details-level "full" use-object-dictionary true --format json &amp;gt; NATRuleSet_0_500.json&lt;BR /&gt;mgmt_cli show nat-rulebase offset 501 limit 500 package "Bill_Fw" details-level "full" use-object-dictionary true --format json &amp;gt; NATRuleSet_501_1000.json&lt;BR /&gt;mgmt_cli show nat-rulebase offset 1001 limit 500 package "Bill_Fw" details-level "full" use-object-dictionary true --format json &amp;gt; NATRuleSet_1001_1500.json&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;U&gt;giving files:&lt;/U&gt;&lt;BR /&gt;NATRuleSet_0_500.json&lt;BR /&gt;NATRuleSet_501_1000.json&lt;BR /&gt;NATRuleSet_1001_1500.json&lt;/P&gt;
&lt;P&gt;We zip the files into -&amp;gt; NATRuleSet.zip&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;The correct NAT rules set firewall set is : "Internet NAT" they used "Bill_FW" the load nto the migration tool Expedition of course was wrong and with inconcistancies.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;2) the sexonf issue was that Expedition was not taking the ZIP files correctly. It was loading all the .json files from the Security ZIP File but only loading the NAT first file and ignoring the other 3 files on the .zip.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The solution:&lt;BR /&gt;----------------&lt;/P&gt;
&lt;P&gt;to load all the R80 configuration in this particular case:&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;- Asked the customer to run the command for the entire configuration as per example below:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;mgmt_cli show access-rulebase offset 0 limit 1000 name "Internet Security" details-level "full" use-object-dictionary true --format json &amp;gt; RuleSet_0_100.json&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;U&gt;giving 1 security jason File:&lt;/U&gt;&lt;BR /&gt;RuleSet_0_1000.json&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;mgmt_cli show nat-rulebase offset 0 limit 1500 package "Internet NAT" details-level "full" use-object-dictionary true --format json &amp;gt; NATRuleSet_0_1500.json&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;U&gt;giving 1 NAT Jason file:&lt;/U&gt;&lt;BR /&gt;NATRuleSet_0_1500.json&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Then, the Expedition load was clean and ready to work on the migration tool.&lt;/P&gt;
&lt;P&gt;Regards,&lt;BR /&gt;Alex&lt;BR /&gt;-&lt;/P&gt;</description>
      <pubDate>Thu, 31 May 2018 17:30:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/issues-getting-a-checkpoint-r80-config-to-load-into-the/m-p/216140#M46</guid>
      <dc:creator>allabres</dc:creator>
      <dc:date>2018-05-31T17:30:24Z</dc:date>
    </item>
    <item>
      <title>Re: Issues getting a Checkpoint R80 config to load into the Migration tool.</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/issues-getting-a-checkpoint-r80-config-to-load-into-the/m-p/216142#M48</link>
      <description>&lt;P&gt;Where is the "order" file?&lt;/P&gt;</description>
      <pubDate>Thu, 31 May 2018 17:33:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/issues-getting-a-checkpoint-r80-config-to-load-into-the/m-p/216142#M48</guid>
      <dc:creator>alestevez</dc:creator>
      <dc:date>2018-05-31T17:33:17Z</dc:date>
    </item>
  </channel>
</rss>

