<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Migrate Security Rules in multiple device groups with Expedition in Expedition Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/expedition-discussions/migrate-security-rules-in-multiple-device-groups-with-expedition/m-p/330200#M2612</link>
    <description>&lt;P&gt;Hi Jean-Bruno,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If the security policy is shared by all device group, you can moved them to shared in Expedition. If they are not shared, you could try export the merged config from Expedition and perform "load config partial" in Panorama CLI to load the security policy to the corresponding device groups&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-cli-quick-start/use-the-cli/load-configurations/load-a-partial-configuration" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-cli-quick-start/use-the-cli/load-configurations/load-a-partial-configuration&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;or&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;use the below move rules function in Panorama GUI to move rules from one device group to another device group&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/panorama/9-0/panorama-admin/manage-firewalls/manage-device-groups/move-or-clone-a-policy-rule-or-object-to-a-different-device-group.html" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/panorama/9-0/panorama-admin/manage-firewalls/manage-device-groups/move-or-clone-a-policy-rule-or-object-to-a-different-device-group.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps!&lt;/P&gt;</description>
    <pubDate>Thu, 28 May 2020 03:45:09 GMT</pubDate>
    <dc:creator>lychiang</dc:creator>
    <dc:date>2020-05-28T03:45:09Z</dc:date>
    <item>
      <title>Migrate Security Rules in multiple device groups with Expedition</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/migrate-security-rules-in-multiple-device-groups-with-expedition/m-p/330156#M2609</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a policy rule imported from a Juniper with one Vsys.&lt;/P&gt;
&lt;P&gt;I'd like to split the rules and migrate them in different Device Group (Multiple VSYS) in a Panorama&lt;/P&gt;
&lt;P&gt;It seems that Expedition only give the possibilty to export the rules in one Device group in the Mapping tab. So if rules belong to multiple device, the only solution i ve found is to move the security policies to one Device group&amp;nbsp; and then to move them with Panorama console in the other Device groups.&lt;/P&gt;
&lt;P&gt;Is there a trick to get more granularity in the Device group Export?&lt;/P&gt;
&lt;P&gt;Thanks for your help&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 May 2020 20:15:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/migrate-security-rules-in-multiple-device-groups-with-expedition/m-p/330156#M2609</guid>
      <dc:creator>Jean-Bruno</dc:creator>
      <dc:date>2020-05-27T20:15:13Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate Security Rules in multiple device groups with Expedition</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/migrate-security-rules-in-multiple-device-groups-with-expedition/m-p/330200#M2612</link>
      <description>&lt;P&gt;Hi Jean-Bruno,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If the security policy is shared by all device group, you can moved them to shared in Expedition. If they are not shared, you could try export the merged config from Expedition and perform "load config partial" in Panorama CLI to load the security policy to the corresponding device groups&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-cli-quick-start/use-the-cli/load-configurations/load-a-partial-configuration" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-cli-quick-start/use-the-cli/load-configurations/load-a-partial-configuration&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;or&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;use the below move rules function in Panorama GUI to move rules from one device group to another device group&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/panorama/9-0/panorama-admin/manage-firewalls/manage-device-groups/move-or-clone-a-policy-rule-or-object-to-a-different-device-group.html" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/panorama/9-0/panorama-admin/manage-firewalls/manage-device-groups/move-or-clone-a-policy-rule-or-object-to-a-different-device-group.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps!&lt;/P&gt;</description>
      <pubDate>Thu, 28 May 2020 03:45:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/migrate-security-rules-in-multiple-device-groups-with-expedition/m-p/330200#M2612</guid>
      <dc:creator>lychiang</dc:creator>
      <dc:date>2020-05-28T03:45:09Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate Security Rules in multiple device groups with Expedition</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/migrate-security-rules-in-multiple-device-groups-with-expedition/m-p/330373#M2617</link>
      <description>&lt;P&gt;&amp;nbsp;i thought there was a button somewhere to move rule among DG in Expedition. Maybe a feature to add?;)&lt;/P&gt;
&lt;P&gt;I'll move the rules manually then from Panorama GUI.&lt;/P&gt;
&lt;P&gt;Thank for your reply&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 May 2020 17:45:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/migrate-security-rules-in-multiple-device-groups-with-expedition/m-p/330373#M2617</guid>
      <dc:creator>Jean-Bruno</dc:creator>
      <dc:date>2020-05-28T17:45:50Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate Security Rules in multiple device groups with Expedition</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/migrate-security-rules-in-multiple-device-groups-with-expedition/m-p/330384#M2618</link>
      <description>&lt;P&gt;There is a function in export tab if you are converting from multi-vsys or multiple firewalls to multiple device groups, where you can drag and drop the left side's security policy from different vsys&amp;nbsp; to the&amp;nbsp; corresponding device groups on the right side and merge the config. But In your scenario , you are converting from single vsys to multiple device groups, so you won't be able to drag and drop the security policy to different device groups.&amp;nbsp; Please see attached screenshot:&lt;/P&gt;</description>
      <pubDate>Thu, 28 May 2020 18:26:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/migrate-security-rules-in-multiple-device-groups-with-expedition/m-p/330384#M2618</guid>
      <dc:creator>lychiang</dc:creator>
      <dc:date>2020-05-28T18:26:29Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate Security Rules in multiple device groups with Expedition</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/migrate-security-rules-in-multiple-device-groups-with-expedition/m-p/330389#M2619</link>
      <description>&lt;P&gt;Yes i agree, but there is no way to clone the rules from one device group to another in Expedition.&lt;/P&gt;
&lt;P&gt;And when it is dragged to the right, left content gets empty. So no real solution in my scenario. Panorama GUI is the way to go&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 28 May 2020 18:42:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/migrate-security-rules-in-multiple-device-groups-with-expedition/m-p/330389#M2619</guid>
      <dc:creator>Jean-Bruno</dc:creator>
      <dc:date>2020-05-28T18:42:30Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate Security Rules in multiple device groups with Expedition</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/migrate-security-rules-in-multiple-device-groups-with-expedition/m-p/331633#M2644</link>
      <description>&lt;P&gt;You are right. We have an option to move a rule to Shared, but we did not implement a feature to move/clone a rule between different DGs/VSys.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We will take note of this need and add it to our list of functionalities we would like to provide in Expedition 2.0, which it is currently under development.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jun 2020 14:45:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/migrate-security-rules-in-multiple-device-groups-with-expedition/m-p/331633#M2644</guid>
      <dc:creator>dgildelaig</dc:creator>
      <dc:date>2020-06-04T14:45:21Z</dc:date>
    </item>
  </channel>
</rss>

