<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic User ID and Expedition in Expedition Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/expedition-discussions/user-id-and-expedition/m-p/531463#M4442</link>
    <description>&lt;P&gt;I am doing a migration from ASA. All seems to be ok in Expedition so far. However the Objects &amp;lt; User ID tab is blank and mentions something about API. There is also a Plugins &amp;lt; User ID section which is also blank.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The ASA config has lots of user id dependencies built into the rules/policies. I have not been able to find any documentation that goes deep enough into the current version of Expedition to be worthwhile and nothing out there that I have found talks about the User ID function within Expedition.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The customer is concerned that the policies aren't migrating over with a 1:1 ruleset using User ID against their Active Directory environment like the rules did on their ASA. In the end we will have over 10k rules so going back into panorama and adding the user id component to every rule is not an option.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have taken the step of adding all of the AD Groups in the Group Mappings section of the Panorama that are referenced in the ASA config.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can anyone help provide a "how to" on migrations from ASA to PAN when the ASA rules already have and must keep the User ID variable in them?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 16 Feb 2023 19:12:42 GMT</pubDate>
    <dc:creator>micharr</dc:creator>
    <dc:date>2023-02-16T19:12:42Z</dc:date>
    <item>
      <title>User ID and Expedition</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/user-id-and-expedition/m-p/531463#M4442</link>
      <description>&lt;P&gt;I am doing a migration from ASA. All seems to be ok in Expedition so far. However the Objects &amp;lt; User ID tab is blank and mentions something about API. There is also a Plugins &amp;lt; User ID section which is also blank.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The ASA config has lots of user id dependencies built into the rules/policies. I have not been able to find any documentation that goes deep enough into the current version of Expedition to be worthwhile and nothing out there that I have found talks about the User ID function within Expedition.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The customer is concerned that the policies aren't migrating over with a 1:1 ruleset using User ID against their Active Directory environment like the rules did on their ASA. In the end we will have over 10k rules so going back into panorama and adding the user id component to every rule is not an option.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have taken the step of adding all of the AD Groups in the Group Mappings section of the Panorama that are referenced in the ASA config.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can anyone help provide a "how to" on migrations from ASA to PAN when the ASA rules already have and must keep the User ID variable in them?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Feb 2023 19:12:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/user-id-and-expedition/m-p/531463#M4442</guid>
      <dc:creator>micharr</dc:creator>
      <dc:date>2023-02-16T19:12:42Z</dc:date>
    </item>
    <item>
      <title>Re: User ID and Expedition</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/user-id-and-expedition/m-p/531478#M4444</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/189507"&gt;@micharr&lt;/a&gt;&amp;nbsp;User-ID migration from ciscoasa is not supported by Expedition.&amp;nbsp; Please see supported objects :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/expedition-articles/expedition-supported-3rd-party-vendor-matrix/ta-p/336922" target="_blank"&gt;https://live.paloaltonetworks.com/t5/expedition-articles/expedition-supported-3rd-party-vendor-matrix/ta-p/336922&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Feb 2023 21:49:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/user-id-and-expedition/m-p/531478#M4444</guid>
      <dc:creator>lychiang</dc:creator>
      <dc:date>2023-02-16T21:49:30Z</dc:date>
    </item>
    <item>
      <title>Re: User ID and Expedition</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/user-id-and-expedition/m-p/615870#M5185</link>
      <description>&lt;P&gt;I am working on a palo fw to panorama migration which includes user id. I can see the user ids in the policies of expedition but i cant seem to find where the group mappings are. Is user id not fullly supported on expedition?&lt;/P&gt;</description>
      <pubDate>Thu, 31 Oct 2024 13:55:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/user-id-and-expedition/m-p/615870#M5185</guid>
      <dc:creator>PktBlocker</dc:creator>
      <dc:date>2024-10-31T13:55:09Z</dc:date>
    </item>
    <item>
      <title>Re: User ID and Expedition</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/user-id-and-expedition/m-p/615872#M5186</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/38307"&gt;@PktBlocker&lt;/a&gt;&amp;nbsp;for Palo Alto Networks Firewall migration to panorama, you do not need to use Expedition,&amp;nbsp; You can refer below for detailed, if you ran into any issues, you can open a TAC case, TAC should be able to help you out.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/panorama/11-0/panorama-admin/manage-firewalls/transition-a-firewall-to-panorama-management/migrate-a-firewall-to-panorama-management" target="_blank"&gt;https://docs.paloaltonetworks.com/panorama/11-0/panorama-admin/manage-firewalls/transition-a-firewall-to-panorama-management/migrate-a-firewall-to-panorama-management&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 31 Oct 2024 15:39:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/user-id-and-expedition/m-p/615872#M5186</guid>
      <dc:creator>lychiang</dc:creator>
      <dc:date>2024-10-31T15:39:09Z</dc:date>
    </item>
    <item>
      <title>Re: User ID and Expedition</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/user-id-and-expedition/m-p/615874#M5187</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/38629"&gt;@lychiang&lt;/a&gt;&amp;nbsp;a few reason iam going to use expedition verses direct on the panorama.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1: I dont want to manage these particular firewalls, there will be a different set that the policies will go on.&lt;/P&gt;
&lt;P&gt;2: This is an acquisition so we usually just pull the policies/nats/routes and integrate them into our panorama templates and security profiles but in this cause they were heavy on the user id feature.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is this not the best way to do this when migrating a palo to palo?&lt;/P&gt;</description>
      <pubDate>Thu, 31 Oct 2024 15:51:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/user-id-and-expedition/m-p/615874#M5187</guid>
      <dc:creator>PktBlocker</dc:creator>
      <dc:date>2024-10-31T15:51:55Z</dc:date>
    </item>
  </channel>
</rss>

