<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to merge multiples confing to one config in Expedition Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/expedition-discussions/how-to-merge-multiples-confing-to-one-config/m-p/404227#M3304</link>
    <description>&lt;P&gt;Hi Lychiang,&lt;/P&gt;
&lt;P&gt;What is the process to load and merge the 3 configurations in one project ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;"If you already make three projects , you could export merged config and do load config partial command to load objects and policy one by one in the target firewall" ---- &amp;gt; In this case you are mentioned that is possible migrate each by each project and use the API to send the configuration separate to the PA firewall ?. &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 30 Apr 2021 15:17:50 GMT</pubDate>
    <dc:creator>mss.support</dc:creator>
    <dc:date>2021-04-30T15:17:50Z</dc:date>
    <item>
      <title>How to merge multiples confing to one config</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/how-to-merge-multiples-confing-to-one-config/m-p/404081#M3300</link>
      <description>&lt;P&gt;Hi community,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I need to know if is possible load multiple configuration to merge in one.&lt;/P&gt;
&lt;P&gt;This is the scenario.&lt;/P&gt;
&lt;P&gt;I have 3 Cisco ASA with different config, I need to migrate this&amp;nbsp; 3 different (3 sites) ASA configuration to one PANOS config.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I proceed to create in my expedition 3 projects, one for each ASA firewall or site.&lt;/P&gt;
&lt;P&gt;The question, exist one way to take this 3 configuration and merge in one PANOS ? &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for your comment or suggestions&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Apr 2021 01:54:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/how-to-merge-multiples-confing-to-one-config/m-p/404081#M3300</guid>
      <dc:creator>mss.support</dc:creator>
      <dc:date>2021-04-30T01:54:36Z</dc:date>
    </item>
    <item>
      <title>Re: How to merge multiples confing to one config</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/how-to-merge-multiples-confing-to-one-config/m-p/404219#M3303</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/20785"&gt;@mss.support&lt;/a&gt;&amp;nbsp;Yes, you could import all three of the Cisco ASA configs and merge them to a single base config in one project. &amp;nbsp;If you already make three projects , you could export merged config and do load config partial command to load objects and policy one by one in the target firewall&lt;/P&gt;</description>
      <pubDate>Fri, 30 Apr 2021 14:55:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/how-to-merge-multiples-confing-to-one-config/m-p/404219#M3303</guid>
      <dc:creator>lychiang</dc:creator>
      <dc:date>2021-04-30T14:55:15Z</dc:date>
    </item>
    <item>
      <title>Re: How to merge multiples confing to one config</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/how-to-merge-multiples-confing-to-one-config/m-p/404227#M3304</link>
      <description>&lt;P&gt;Hi Lychiang,&lt;/P&gt;
&lt;P&gt;What is the process to load and merge the 3 configurations in one project ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;"If you already make three projects , you could export merged config and do load config partial command to load objects and policy one by one in the target firewall" ---- &amp;gt; In this case you are mentioned that is possible migrate each by each project and use the API to send the configuration separate to the PA firewall ?. &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Apr 2021 15:17:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/how-to-merge-multiples-confing-to-one-config/m-p/404227#M3304</guid>
      <dc:creator>mss.support</dc:creator>
      <dc:date>2021-04-30T15:17:50Z</dc:date>
    </item>
    <item>
      <title>Re: How to merge multiples confing to one config</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/how-to-merge-multiples-confing-to-one-config/m-p/404290#M3313</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/20785"&gt;@mss.support&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;1 you will zip all three asa config into a zip file&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2. upload your asazip file in the import -&amp;gt; cisco -&amp;gt; upload multiple files&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2021-04-30 at 9.29.04 AM.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/33569i5CBDB97090589479/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Screen Shot 2021-04-30 at 9.29.04 AM.png" alt="Screen Shot 2021-04-30 at 9.29.04 AM.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;3. Upload your PAN-OS config under Import -&amp;gt; Palo Alto -&amp;gt; upload a single file. upload your base config here . it can be either firewal or panorma config depends where your policy going to be managed at.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;4.&amp;nbsp; You will need to fix all the red number showing in the dashboard for each of the cisco asa file , you can switch the context located at the right bottom corner to get to each of the ciscoasa config and make modification for each of the ciscoasa config&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2021-04-30 at 9.38.41 AM.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/33570iC2BB0AE0C2394EEA/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Screen Shot 2021-04-30 at 9.38.41 AM.png" alt="Screen Shot 2021-04-30 at 9.38.41 AM.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;5.&amp;nbsp; Since you are merging three ciscoasa firewall into one palo alto firewall, you will need to review which network interfaces you would like to migrate to the palo alto network, if there are not many interfaces, you can build the interfaces and zone on the firewall directly, please make sure the zone name needs to match the zone name in the policy.&amp;nbsp; If there are a lot of interfaces you would like to keep from ciscoasa config, you will need to fix the interface configurations under each cisocasa config, make sure you rename each of the interfaces to PAN-OS naming conventions and each of the configs do not have duplicated interface names, also you might only need one VR depends on your use case. When you ready to merge the source and base configs, you can go to "Export" -&amp;gt; " Mapping" -&amp;gt; if you need to merge the network interface, you will first start with ciscoasa1 config, check all checkbox under "network", drag and drop them to "network" section onto the right side base config&lt;STRONG&gt; (If you already built interfaces and zone on the firewall, you do not need to merge the network configuration )&lt;/STRONG&gt; for policy and objects, under vsys1, drag and drop them to the right side vsys 1, continue for ciscoasa2 and ciscoas3&amp;nbsp;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2021-04-30 at 9.29.33 AM.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/33571i35B86614FBD33748/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Screen Shot 2021-04-30 at 9.29.33 AM.png" alt="Screen Shot 2021-04-30 at 9.29.33 AM.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;6. Once you finished drag and drop, you should see configuration from 3 ciscoasa moved to base config as below :&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2021-04-30 at 9.30.27 AM.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/33572iBE85AB4F545CD33D/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Screen Shot 2021-04-30 at 9.30.27 AM.png" alt="Screen Shot 2021-04-30 at 9.30.27 AM.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;7. You can then click on "Merge" to merge the config&amp;nbsp;&lt;/P&gt;
&lt;P&gt;8. Once the merge is done, you can then click "Generate XML and set output" to download the merged xml file.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2021-04-30 at 9.55.06 AM.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/33573iFC2DF52E512D058F/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Screen Shot 2021-04-30 at 9.55.06 AM.png" alt="Screen Shot 2021-04-30 at 9.55.06 AM.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;9 You could then load the config using "load config partial" or if you have direct access between expedition and firewall, you can then do an API calls from expedition to firewall to push the configuration over.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Fri, 30 Apr 2021 17:03:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/how-to-merge-multiples-confing-to-one-config/m-p/404290#M3313</guid>
      <dc:creator>lychiang</dc:creator>
      <dc:date>2021-04-30T17:03:01Z</dc:date>
    </item>
    <item>
      <title>Re: How to merge multiples confing to one config</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/how-to-merge-multiples-confing-to-one-config/m-p/404301#M3318</link>
      <description>&lt;P&gt;Hi Lychiang&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;First thanks a lot for the info and process load and merge in one config.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;About interfaces,&lt;/P&gt;
&lt;P&gt;Yes, In this case the asa configs have the following interfaces.&lt;/P&gt;
&lt;P&gt;I have one config with the following interface config.&lt;/P&gt;
&lt;P&gt;interface GigabitEthernet0/0&lt;BR /&gt;interface GigabitEthernet0/1 with 8 subinterfaces&lt;BR /&gt;interface GigabitEthernet0/2 &lt;/P&gt;
&lt;P&gt;interface GigabitEthernet0/3 with 9 subinterfaces&lt;/P&gt;
&lt;P&gt;interface GigabitEthernet1/1&lt;/P&gt;
&lt;P&gt;interface GigabitEthernet1/2&lt;/P&gt;
&lt;P&gt;interface GigabitEthernet1/3&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;other with 3 subinterfaces&lt;/P&gt;
&lt;P&gt;and other with one Gigaethernet with 4 subinterface and one gigaethernet.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Apr 2021 18:04:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/how-to-merge-multiples-confing-to-one-config/m-p/404301#M3318</guid>
      <dc:creator>mss.support</dc:creator>
      <dc:date>2021-04-30T18:04:27Z</dc:date>
    </item>
    <item>
      <title>Re: How to merge multiples confing to one config</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/how-to-merge-multiples-confing-to-one-config/m-p/404303#M3319</link>
      <description>&lt;P&gt;So if you need to keep those interfaces, you can click "remap interface" to remap them to PAN-OS naming convention.&amp;nbsp; as long the interface name does not duplicate between three ciscoasa configs , you are able to merge without a problem.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Apr 2021 18:30:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/how-to-merge-multiples-confing-to-one-config/m-p/404303#M3319</guid>
      <dc:creator>lychiang</dc:creator>
      <dc:date>2021-04-30T18:30:12Z</dc:date>
    </item>
    <item>
      <title>Re: How to merge multiples confing to one config</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/how-to-merge-multiples-confing-to-one-config/m-p/404341#M3324</link>
      <description>&lt;P&gt;Great,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sorry, sorry last question,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have this warning. I filter but I cannot see the PING object,&amp;nbsp; or echo or ICMP. Do you know what is this.&lt;/P&gt;
&lt;P&gt;Security RuleID [111] is using an object-group [PING] but both SourcePort and Service are filled. [access-list swift_access_in extended permit icmp host x.x.x.x x.x.x.x 255.255.255.254 object-group PING]&lt;BR /&gt;&lt;BR /&gt;Security RuleID [352] is using an object-group [echo-trace] but both SourcePort and Service are filled. [access-list outside_in extended permit icmp object-group vlan101-mgmt-net x.x.x.x 255.255.255.0 object-group echo-trace]&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Security RuleID [606] is using an object-group [PING] but both SourcePort and Service are filled. [access-list dmz-nyc_in extended permit icmp host x.x.x.x host x.x.x.x object-group PING]&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best Regards&lt;/P&gt;
&lt;P&gt;Andres&lt;/P&gt;</description>
      <pubDate>Fri, 30 Apr 2021 22:01:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/how-to-merge-multiples-confing-to-one-config/m-p/404341#M3324</guid>
      <dc:creator>mss.support</dc:creator>
      <dc:date>2021-04-30T22:01:40Z</dc:date>
    </item>
    <item>
      <title>Re: How to merge multiples confing to one config</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/how-to-merge-multiples-confing-to-one-config/m-p/404342#M3325</link>
      <description>&lt;P&gt;Hi&lt;BR /&gt;Related to interfaces, the vlans are different in all 3 asa configs.&lt;BR /&gt;In case in the asas use the same interfaces , for example. In two asa using the Gigaethernet0/1 but different vlans.&lt;BR /&gt;I was think remap that ,. for example.&lt;BR /&gt;In one site change the gigaethernet by ethernet1/1 with your subinterfaces. But with other asa remap with etherner1/3 with yours subinterfaces. That works ?&lt;/P&gt;
&lt;P&gt;Again I really really appreciate your help with all your messages.&lt;/P&gt;
&lt;P&gt;Best Regards&lt;/P&gt;
&lt;P&gt;Andres&lt;/P&gt;</description>
      <pubDate>Fri, 30 Apr 2021 22:11:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/how-to-merge-multiples-confing-to-one-config/m-p/404342#M3325</guid>
      <dc:creator>mss.support</dc:creator>
      <dc:date>2021-04-30T22:11:36Z</dc:date>
    </item>
    <item>
      <title>Re: How to merge multiples confing to one config</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/how-to-merge-multiples-confing-to-one-config/m-p/404350#M3326</link>
      <description>&lt;P&gt;For&amp;nbsp;&lt;SPAN&gt;object-group PING , if you filter address group object contains “PING” you should find it&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;expedition only support remap to layer 3 interface , for vlan interface you will need to recreate the interface .&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Apr 2021 22:57:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/how-to-merge-multiples-confing-to-one-config/m-p/404350#M3326</guid>
      <dc:creator>lychiang</dc:creator>
      <dc:date>2021-04-30T22:57:55Z</dc:date>
    </item>
    <item>
      <title>Re: How to merge multiples confing to one config</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/how-to-merge-multiples-confing-to-one-config/m-p/404384#M3327</link>
      <description>&lt;P&gt;Again Thanks a lot for all your help !!!!!.&lt;/P&gt;</description>
      <pubDate>Sat, 01 May 2021 17:24:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/how-to-merge-multiples-confing-to-one-config/m-p/404384#M3327</guid>
      <dc:creator>mss.support</dc:creator>
      <dc:date>2021-05-01T17:24:11Z</dc:date>
    </item>
  </channel>
</rss>

