<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Correct invalid services in Expedition in Expedition Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/expedition-discussions/correct-invalid-services-in-expedition/m-p/519275#M4240</link>
    <description>&lt;P&gt;Thanks &lt;SPAN class="UserName lia-user-name lia-user-rank-L5-Sessionator lia-component-message-view-widget-author-username"&gt;&lt;A id="link_19" class="lia-link-navigation lia-page-link lia-user-name-link" href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/38629" target="_self" aria-label="View Profile of lychiang"&gt;&lt;SPAN class=""&gt;lychiang,&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-L5-Sessionator lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;I was not familiar with default objects in the ASA until now. &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-L5-Sessionator lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;One must perform a "show run all" on an ASA to see the default objects, which is where I found the default GRE object, as well as the default "echo" object. &lt;BR /&gt;&lt;BR /&gt;The last piece I am uncertain about which &lt;SPAN class="UserName lia-user-name lia-user-rank-L1-Bithead lia-component-message-view-widget-author-username"&gt;&lt;A id="link_7" class="lia-link-navigation lia-page-link lia-user-name-link" href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/169335" target="_self" aria-label="View Profile of AK74"&gt;AK74&lt;/A&gt;&lt;/SPAN&gt; also asked, is why the used service object for ICMP was renamed to "discard".&lt;BR /&gt;The service object configured in the ASA is just called "icmp". Not critical as we'll rename it anyway, but I'm still curious. &lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 26 Oct 2022 17:36:30 GMT</pubDate>
    <dc:creator>Ifixtheinternet</dc:creator>
    <dc:date>2022-10-26T17:36:30Z</dc:date>
    <item>
      <title>Correct invalid services in Expedition</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/correct-invalid-services-in-expedition/m-p/507888#M4064</link>
      <description>&lt;P&gt;Hello there,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I am currently migrating my ASA 5585 to a Palo 5260 using Expedition tool. Everything on the dashboard has been rectified, except for few services that shows "invalid" and used .&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've noticed that Expedition has replaced "icmp" service in ASA to "discard"&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does anyone know why is that ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also, there're some invalid services such as (icmp-echo. icmp-echo-reply) but when I try to search/locate them, I don't see them under security policy but they're used in Object groups as shown below So, basically I need to convert them to Ping application as if they were used in security policy ?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AK74_0-1656972005482.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/42132i23D037E93CCFAD69/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="AK74_0-1656972005482.png" alt="AK74_0-1656972005482.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Finally, I've got "esp" as invalid service but again it's located in an object group. So, how to correct it? replace it with an application (ipsec-esp) or service ?&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jul 2022 23:17:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/correct-invalid-services-in-expedition/m-p/507888#M4064</guid>
      <dc:creator>AK74</dc:creator>
      <dc:date>2022-07-04T23:17:14Z</dc:date>
    </item>
    <item>
      <title>Re: Correct invalid services in Expedition</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/correct-invalid-services-in-expedition/m-p/519261#M4237</link>
      <description>&lt;P&gt;I have the same problem and question. &lt;/P&gt;
&lt;P&gt;In addition to those, I also have a service object showing up for "GRE", but there is no object in my ASA configured for GRE, or port 47, either individually or within any port range. So I'm not sure where that came from. &lt;BR /&gt;They show unused, but I'd still like to understand why they were generated. &lt;BR /&gt;I'm wondering if there's any way to display in Expedition what object / config line in the ASA that Expedition referred to in order to create the objects. &lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="3_Invalid_Service_objects_5585i.png" style="width: 960px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/44900iBDEB08DCD9AEE5FA/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="3_Invalid_Service_objects_5585i.png" alt="3_Invalid_Service_objects_5585i.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Oct 2022 16:27:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/correct-invalid-services-in-expedition/m-p/519261#M4237</guid>
      <dc:creator>Ifixtheinternet</dc:creator>
      <dc:date>2022-10-26T16:27:29Z</dc:date>
    </item>
    <item>
      <title>Re: Correct invalid services in Expedition</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/correct-invalid-services-in-expedition/m-p/519265#M4238</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/236599"&gt;@Ifixtheinternet&lt;/a&gt;&amp;nbsp;Those are default service protocol from your cisco asa config, if it's red dot , means it's not being used in any group object or policies.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Oct 2022 16:34:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/correct-invalid-services-in-expedition/m-p/519265#M4238</guid>
      <dc:creator>lychiang</dc:creator>
      <dc:date>2022-10-26T16:34:42Z</dc:date>
    </item>
    <item>
      <title>Re: Correct invalid services in Expedition</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/correct-invalid-services-in-expedition/m-p/519275#M4240</link>
      <description>&lt;P&gt;Thanks &lt;SPAN class="UserName lia-user-name lia-user-rank-L5-Sessionator lia-component-message-view-widget-author-username"&gt;&lt;A id="link_19" class="lia-link-navigation lia-page-link lia-user-name-link" href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/38629" target="_self" aria-label="View Profile of lychiang"&gt;&lt;SPAN class=""&gt;lychiang,&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-L5-Sessionator lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;I was not familiar with default objects in the ASA until now. &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-L5-Sessionator lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;One must perform a "show run all" on an ASA to see the default objects, which is where I found the default GRE object, as well as the default "echo" object. &lt;BR /&gt;&lt;BR /&gt;The last piece I am uncertain about which &lt;SPAN class="UserName lia-user-name lia-user-rank-L1-Bithead lia-component-message-view-widget-author-username"&gt;&lt;A id="link_7" class="lia-link-navigation lia-page-link lia-user-name-link" href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/169335" target="_self" aria-label="View Profile of AK74"&gt;AK74&lt;/A&gt;&lt;/SPAN&gt; also asked, is why the used service object for ICMP was renamed to "discard".&lt;BR /&gt;The service object configured in the ASA is just called "icmp". Not critical as we'll rename it anyway, but I'm still curious. &lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Oct 2022 17:36:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/correct-invalid-services-in-expedition/m-p/519275#M4240</guid>
      <dc:creator>Ifixtheinternet</dc:creator>
      <dc:date>2022-10-26T17:36:30Z</dc:date>
    </item>
    <item>
      <title>Re: Correct invalid services in Expedition</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/correct-invalid-services-in-expedition/m-p/519297#M4241</link>
      <description>&lt;P&gt;What version of Expedition tool are you using ?&lt;/P&gt;</description>
      <pubDate>Wed, 26 Oct 2022 22:45:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/correct-invalid-services-in-expedition/m-p/519297#M4241</guid>
      <dc:creator>AK74</dc:creator>
      <dc:date>2022-10-26T22:45:40Z</dc:date>
    </item>
  </channel>
</rss>

