<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Migration Tool Software from Cisco ASA 5545 to Palo alto 3220 in Expedition Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/expedition-discussions/migration-tool-software-from-cisco-asa-5545-to-palo-alto-3220/m-p/552252#M4659</link>
    <description>&lt;P&gt;Hi Davi,&lt;BR /&gt;While importing xml config file to expedition exported from palo alto firewall which is associated with panorama is not showing stats in dashboard, for example not shoving policy, ae interfaces and routing, in short not showing 99% config except 3 application and 2 physical interfaces.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 02 Aug 2023 20:26:37 GMT</pubDate>
    <dc:creator>Shubhamkumaryadav</dc:creator>
    <dc:date>2023-08-02T20:26:37Z</dc:date>
    <item>
      <title>Migration Tool Software from Cisco ASA 5545 to Palo alto 3220</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/migration-tool-software-from-cisco-asa-5545-to-palo-alto-3220/m-p/551074#M4650</link>
      <description>&lt;P&gt;Hi Folks,&lt;BR /&gt;I read that&amp;nbsp;Migration Tool Software&amp;nbsp;offered free of charge to Palo Alto Networks ACE &lt;BR /&gt;partners, is that true? if yes then what is the process for that and how can i use it?&lt;BR /&gt;&lt;BR /&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jul 2023 10:55:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/migration-tool-software-from-cisco-asa-5545-to-palo-alto-3220/m-p/551074#M4650</guid>
      <dc:creator>Shubhamkumaryadav</dc:creator>
      <dc:date>2023-07-26T10:55:45Z</dc:date>
    </item>
    <item>
      <title>Re: Migration Tool Software from Cisco ASA 5545 to Palo alto 3220</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/migration-tool-software-from-cisco-asa-5545-to-palo-alto-3220/m-p/551082#M4651</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/305757"&gt;@Shubhamkumaryadav&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Expedition is offered free of charge and can help you migrating CISCO ASA and other 3rd parties vendors to Palo Alto Networks NGFW and Panorama.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Furthermore it can help you doing PANOS configuration optimisations like removing unused objects, merge duplicated objects by name, value or both, as well as other predefined useful filters.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you are new in Expedition maybe you would like to join the beta program for Expedition2. Please follow below article for the onboarding process:&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/expedition-articles/introducing-expedition-2-beta/ta-p/542787" target="_blank"&gt;https://live.paloaltonetworks.com/t5/expedition-articles/introducing-expedition-2-beta/ta-p/542787&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also you can take a look at below series of videos using Expedition1 to cover your use case, a complete workflow migration from CISCO to Palo Alto Networks: &lt;A href="https://www.youtube.com/playlist?list=PLD6FJ8WNiIqVez8EBeoyRsnQcKTA5FuZ-" target="_blank"&gt;https://www.youtube.com/playlist?list=PLD6FJ8WNiIqVez8EBeoyRsnQcKTA5FuZ-&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Let me share some other links to get in touch with Expedition.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;3rd party supported vendors:&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/expedition-articles/expedition-supported-3rd-party-vendor-matrix/ta-p/336922" target="_blank"&gt;https://live.paloaltonetworks.com/t5/expedition-articles/expedition-supported-3rd-party-vendor-matrix/ta-p/336922&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Expedition main Live portal:&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/expedition/ct-p/migration_tool" target="_blank"&gt;https://live.paloaltonetworks.com/t5/expedition/ct-p/migration_tool&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;To report any finding or request assistance please send an email to fwmigrate@paloaltonetworks.com&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this information helps you,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regards,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;David&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jul 2023 12:01:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/migration-tool-software-from-cisco-asa-5545-to-palo-alto-3220/m-p/551082#M4651</guid>
      <dc:creator>dpuigdomenec</dc:creator>
      <dc:date>2023-07-26T12:01:43Z</dc:date>
    </item>
    <item>
      <title>Re: Migration Tool Software from Cisco ASA 5545 to Palo alto 3220</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/migration-tool-software-from-cisco-asa-5545-to-palo-alto-3220/m-p/552252#M4659</link>
      <description>&lt;P&gt;Hi Davi,&lt;BR /&gt;While importing xml config file to expedition exported from palo alto firewall which is associated with panorama is not showing stats in dashboard, for example not shoving policy, ae interfaces and routing, in short not showing 99% config except 3 application and 2 physical interfaces.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2023 20:26:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/migration-tool-software-from-cisco-asa-5545-to-palo-alto-3220/m-p/552252#M4659</guid>
      <dc:creator>Shubhamkumaryadav</dc:creator>
      <dc:date>2023-08-02T20:26:37Z</dc:date>
    </item>
    <item>
      <title>Re: Migration Tool Software from Cisco ASA 5545 to Palo alto 3220</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/migration-tool-software-from-cisco-asa-5545-to-palo-alto-3220/m-p/552254#M4661</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/305757"&gt;@Shubhamkumaryadav&lt;/a&gt;&amp;nbsp;Could it be your policy and objects are defined in panorama , if that's the case, you should import panorama running-config to Expedition.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2023 20:43:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/migration-tool-software-from-cisco-asa-5545-to-palo-alto-3220/m-p/552254#M4661</guid>
      <dc:creator>lychiang</dc:creator>
      <dc:date>2023-08-02T20:43:28Z</dc:date>
    </item>
    <item>
      <title>Re: Migration Tool Software from Cisco ASA 5545 to Palo alto 3220</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/migration-tool-software-from-cisco-asa-5545-to-palo-alto-3220/m-p/552298#M4662</link>
      <description>&lt;P&gt;Hi Dpuigdomenec,&lt;/P&gt;
&lt;P&gt;I have mirgrade police from ASA 5525 to PaloAlto. But there are some policies that have the same Source Zone and Destination Zone fields or are left blank. Does Expedition have a feature to modify such cases?&lt;/P&gt;</description>
      <pubDate>Thu, 03 Aug 2023 04:12:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/migration-tool-software-from-cisco-asa-5545-to-palo-alto-3220/m-p/552298#M4662</guid>
      <dc:creator>lxuanquynh</dc:creator>
      <dc:date>2023-08-03T04:12:54Z</dc:date>
    </item>
    <item>
      <title>Re: Migration Tool Software from Cisco ASA 5545 to Palo alto 3220</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/migration-tool-software-from-cisco-asa-5545-to-palo-alto-3220/m-p/552348#M4663</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/294593"&gt;@lxuanquynh&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Expedition could run an autozone on NAT and Security Rules for you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;First please make sure you Network is properly defined, that means review your interfaces are properly defined and have a zone assigned, also your VR has a default static route. Having a default static route is a must to execute the autozone assign.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Once all this information is fine create an snapshot of the project so at any time you can go back to this specific project status.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Then execute below steps:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. Go to Security Rules grid,&lt;/P&gt;
&lt;P&gt;2. Select one rule or all, but for testing purposes I will suggest select first some controlled rules,&lt;/P&gt;
&lt;P&gt;3. Click on right mouse button and select autozone assign.&lt;/P&gt;
&lt;P&gt;4. Select your template (Network information) and your VR to use&lt;/P&gt;
&lt;P&gt;5. Select the scope of the executions; selected rules or all rules&lt;/P&gt;
&lt;P&gt;6. Select if you want to calculate source zones and destination zones&lt;/P&gt;
&lt;P&gt;7. Select if you want to apply NAT rules information for destination zones.&lt;/P&gt;
&lt;P&gt;8. Click on calculate&amp;nbsp;&lt;/P&gt;
&lt;P&gt;9. Wait for the process to finish&lt;/P&gt;
&lt;P&gt;10. Review tab Monitor to check for some warning on the process&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Note: The same process could be executed on NAT rules. Take into account that as Palo Alto Networks only allows having 1 zone on the to (destination) zone for NAT rules, when Expedition detects that the NAT rule needs having more than one to zone, then it clones the NAT rule for every to zone needed, increasing the number of NAT rules than originally were migrated.&lt;BR /&gt;&lt;BR /&gt;If you identify some finding please open a TAC case including your original configuration and share the TAC case number with us using the email fwmigrate &amp;lt;fwmigrate@paloaltonetworks.com&amp;gt;. We will be happy to assist you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this information helps you,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;David&lt;/P&gt;</description>
      <pubDate>Thu, 03 Aug 2023 07:05:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/migration-tool-software-from-cisco-asa-5545-to-palo-alto-3220/m-p/552348#M4663</guid>
      <dc:creator>dpuigdomenec</dc:creator>
      <dc:date>2023-08-03T07:05:29Z</dc:date>
    </item>
    <item>
      <title>Re: Migration Tool Software from Cisco ASA 5545 to Palo alto 3220</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/migration-tool-software-from-cisco-asa-5545-to-palo-alto-3220/m-p/552362#M4664</link>
      <description>&lt;P&gt;Thanks for support Dpuigdomenec,&lt;/P&gt;
&lt;P&gt;I will try and respond.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Aug 2023 08:14:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/migration-tool-software-from-cisco-asa-5545-to-palo-alto-3220/m-p/552362#M4664</guid>
      <dc:creator>lxuanquynh</dc:creator>
      <dc:date>2023-08-03T08:14:52Z</dc:date>
    </item>
    <item>
      <title>Re: Migration Tool Software from Cisco ASA 5545 to Palo alto 3220</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/migration-tool-software-from-cisco-asa-5545-to-palo-alto-3220/m-p/552557#M4665</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/38629"&gt;@lychiang&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;AS you suggested tried xml config exported from panorama for particular device group and template stack but again after importing to expedition but after that i see nothing in policy and vpn and network config.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Aug 2023 08:50:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/migration-tool-software-from-cisco-asa-5545-to-palo-alto-3220/m-p/552557#M4665</guid>
      <dc:creator>Shubhamkumaryadav</dc:creator>
      <dc:date>2023-08-04T08:50:26Z</dc:date>
    </item>
    <item>
      <title>Re: Migration Tool Software from Cisco ASA 5545 to Palo alto 3220</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/migration-tool-software-from-cisco-asa-5545-to-palo-alto-3220/m-p/552625#M4666</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/305757"&gt;@Shubhamkumaryadav&lt;/a&gt;&amp;nbsp;When you export the config from panorama, please export the whole running-config without selecting device group or template, Expedition only reads whole running-config not partial.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Aug 2023 15:50:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/migration-tool-software-from-cisco-asa-5545-to-palo-alto-3220/m-p/552625#M4666</guid>
      <dc:creator>lychiang</dc:creator>
      <dc:date>2023-08-04T15:50:25Z</dc:date>
    </item>
    <item>
      <title>Re: Migration Tool Software from Cisco ASA 5545 to Palo alto 3220</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/migration-tool-software-from-cisco-asa-5545-to-palo-alto-3220/m-p/552686#M4667</link>
      <description>&lt;P&gt;HI&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/38629"&gt;@lychiang&lt;/a&gt;&amp;nbsp;I Have 21 firewall in panorama if i export whole config then how would i migrate rules from ASA to specific palo alto firewall? that is why i am selecting device group, template and template stack should be enough right?&amp;nbsp;also checked this xml file in browser is has all config which i need but when i import to expedition its does not come with any value to dashboard.&lt;/P&gt;</description>
      <pubDate>Sat, 05 Aug 2023 18:03:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/migration-tool-software-from-cisco-asa-5545-to-palo-alto-3220/m-p/552686#M4667</guid>
      <dc:creator>Shubhamkumaryadav</dc:creator>
      <dc:date>2023-08-05T18:03:30Z</dc:date>
    </item>
    <item>
      <title>Re: Migration Tool Software from Cisco ASA 5545 to Palo alto 3220</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/migration-tool-software-from-cisco-asa-5545-to-palo-alto-3220/m-p/552795#M4668</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/305757"&gt;@Shubhamkumaryadav&lt;/a&gt;&amp;nbsp;It is is important to create a new device group and new template in panorama for your ciscoasa migration before you export the whole running config file out, so when you merge the ciscoasa and panorama config, you only merge the ciscoasa migrated config to the new device group and template , that way ,when you load the config on panorama, you can&amp;nbsp; load the new device group and template from the exported expedition config. Hope this clear.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Aug 2023 15:23:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/migration-tool-software-from-cisco-asa-5545-to-palo-alto-3220/m-p/552795#M4668</guid>
      <dc:creator>lychiang</dc:creator>
      <dc:date>2023-08-07T15:23:59Z</dc:date>
    </item>
    <item>
      <title>Re: Migration Tool Software from Cisco ASA 5545 to Palo alto 3220</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/migration-tool-software-from-cisco-asa-5545-to-palo-alto-3220/m-p/552886#M4672</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/38629"&gt;@lychiang&lt;/a&gt;, So basically you are saying i should export full funning config from panorama which includes 21 filrewalls and newly created device group and template, after that import this to expedition and merge the ASA cinfg&amp;nbsp;&lt;SPAN&gt;to the new device group and template, and then load back to panorama, this time it will have 21 firewall config plus ASA config in the form of newly device group and template right ? what about template stack should create this stack after that?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Aug 2023 07:49:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/migration-tool-software-from-cisco-asa-5545-to-palo-alto-3220/m-p/552886#M4672</guid>
      <dc:creator>Shubhamkumaryadav</dc:creator>
      <dc:date>2023-08-08T07:49:15Z</dc:date>
    </item>
    <item>
      <title>Re: Migration Tool Software from Cisco ASA 5545 to Palo alto 3220</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/migration-tool-software-from-cisco-asa-5545-to-palo-alto-3220/m-p/552956#M4673</link>
      <description>&lt;P&gt;Yes, you can create template stack after you import the new template back.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Aug 2023 15:13:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/migration-tool-software-from-cisco-asa-5545-to-palo-alto-3220/m-p/552956#M4673</guid>
      <dc:creator>lychiang</dc:creator>
      <dc:date>2023-08-08T15:13:29Z</dc:date>
    </item>
  </channel>
</rss>

