<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: expedition palo alto device requirement in Expedition Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-palo-alto-device-requirement/m-p/568851#M4862</link>
    <description>&lt;P&gt;hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/215386"&gt;@dpuigdomenec&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thank you for your response, but i'm struggling with the migration of a multi-context ASA since the method you mentioned seems to only create a single Vsys. is there a way to have multiple Vsys? and what configuration should be put into the shared part of PA config, is it the system context of ASA?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank You&lt;/P&gt;</description>
    <pubDate>Thu, 07 Dec 2023 09:11:22 GMT</pubDate>
    <dc:creator>hattia</dc:creator>
    <dc:date>2023-12-07T09:11:22Z</dc:date>
    <item>
      <title>expedition palo alto device requirement</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-palo-alto-device-requirement/m-p/567218#M4855</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;does using the expedition tool require having a palo alto device or can i just export the config as a file and install it on the device later ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2023 14:13:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-palo-alto-device-requirement/m-p/567218#M4855</guid>
      <dc:creator>hattia</dc:creator>
      <dc:date>2023-11-27T14:13:12Z</dc:date>
    </item>
    <item>
      <title>Re: expedition palo alto device requirement</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-palo-alto-device-requirement/m-p/567229#M4856</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you don't need a device for using expedition. As you mentioned, you can import a config that you previously exported.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please note that having a device also integrated in Expedition brings a lot of QoL improvedments. For instance, you can push changes directly to that device etc.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope that helps.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards!&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2023 15:37:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-palo-alto-device-requirement/m-p/567229#M4856</guid>
      <dc:creator>jzbick</dc:creator>
      <dc:date>2023-11-27T15:37:45Z</dc:date>
    </item>
    <item>
      <title>Re: expedition palo alto device requirement</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-palo-alto-device-requirement/m-p/567236#M4857</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks for your response. just to make things clear, i have a multi context ASA i want to migaret to Palo alto.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i installed the expedition VM and uploaded the ASA Configuration. now, i want to export the configuration to palo alto but i currently dont have access to the PA Firewalls. can you provide me with the steps or documentation to get the configuration as a file to later restore it on the PA Firewalls ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks in advance&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2023 16:03:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-palo-alto-device-requirement/m-p/567236#M4857</guid>
      <dc:creator>hattia</dc:creator>
      <dc:date>2023-11-27T16:03:16Z</dc:date>
    </item>
    <item>
      <title>Re: expedition palo alto device requirement</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-palo-alto-device-requirement/m-p/567243#M4858</link>
      <description>&lt;P&gt;Here is a youtube series that covers an ASA case: &lt;A href="https://www.youtube.com/playlist?list=PLD6FJ8WNiIqVez8EBeoyRsnQcKTA5FuZ-" target="_blank"&gt;https://www.youtube.com/playlist?list=PLD6FJ8WNiIqVez8EBeoyRsnQcKTA5FuZ-&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you follow these steps, in the very last section, in the "Export" section you can download the XML file that you can import to your PA Firewall.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope this helps.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2023 16:25:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-palo-alto-device-requirement/m-p/567243#M4858</guid>
      <dc:creator>jzbick</dc:creator>
      <dc:date>2023-11-27T16:25:35Z</dc:date>
    </item>
    <item>
      <title>Re: expedition palo alto device requirement</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-palo-alto-device-requirement/m-p/567245#M4859</link>
      <description>&lt;P&gt;so according to the videos i need a base configuration. where can i get that ?&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2023 16:39:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-palo-alto-device-requirement/m-p/567245#M4859</guid>
      <dc:creator>hattia</dc:creator>
      <dc:date>2023-11-27T16:39:28Z</dc:date>
    </item>
    <item>
      <title>Re: expedition palo alto device requirement</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-palo-alto-device-requirement/m-p/567383#M4860</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/338116"&gt;@hattia&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The base config should be the one you get from you PA device.&lt;/P&gt;
&lt;P&gt;If you don't have access to it, you can create a dummy empty configuration using the iron-skilled option.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Steps:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- Login to Expedition&lt;/P&gt;
&lt;P&gt;- Go to Project and select your project&lt;/P&gt;
&lt;P&gt;- Go to Import and select Palo Alto&lt;/P&gt;
&lt;P&gt;- Go to Iron-Skilled fullfil the required information and click on Generate and Import&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The result will be an empty configuration you can use to play and drag and drop your migrated objects.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regards,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;David&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Nov 2023 11:43:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-palo-alto-device-requirement/m-p/567383#M4860</guid>
      <dc:creator>dpuigdomenec</dc:creator>
      <dc:date>2023-11-28T11:43:04Z</dc:date>
    </item>
    <item>
      <title>Re: expedition palo alto device requirement</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-palo-alto-device-requirement/m-p/568851#M4862</link>
      <description>&lt;P&gt;hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/215386"&gt;@dpuigdomenec&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thank you for your response, but i'm struggling with the migration of a multi-context ASA since the method you mentioned seems to only create a single Vsys. is there a way to have multiple Vsys? and what configuration should be put into the shared part of PA config, is it the system context of ASA?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank You&lt;/P&gt;</description>
      <pubDate>Thu, 07 Dec 2023 09:11:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-palo-alto-device-requirement/m-p/568851#M4862</guid>
      <dc:creator>hattia</dc:creator>
      <dc:date>2023-12-07T09:11:22Z</dc:date>
    </item>
    <item>
      <title>Re: expedition palo alto device requirement</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-palo-alto-device-requirement/m-p/568901#M4863</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/338116"&gt;@hattia&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you have access to your panOS device and can export an empty multi vsys config from there? You could use this as your base configuration.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the meantime, I will check internally how to achieve it alternatively.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Dec 2023 15:48:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-palo-alto-device-requirement/m-p/568901#M4863</guid>
      <dc:creator>jzbick</dc:creator>
      <dc:date>2023-12-07T15:48:27Z</dc:date>
    </item>
    <item>
      <title>Re: expedition palo alto device requirement</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-palo-alto-device-requirement/m-p/569022#M4864</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/338116"&gt;@hattia&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;DIV class="p-rich_text_section"&gt;Currently Expedition1 / Expedition2 is only generating one vsys when importing an ASA file. So split that into different vsys in&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="c-mrkdwn__highlight"&gt;Expedition&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;could be complicated. Also you will need to have the vsys/DG defined on your base configuration on your device first. Expedition does not allow you to define a new vsys/DG.&lt;/DIV&gt;
&lt;DIV class="p-rich_text_section"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="p-rich_text_section"&gt;When importing an ASA config we use the “access-group access_list_name in interface interface_name” to only import those rules referenced by the access_list_name and put them on vsys1. A way it came to my mind is to do different imports with only having active the desired access-group by each vsys.&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="p-rich_text_section"&gt;&lt;SPAN&gt;The result will be having as many as source files on&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="c-mrkdwn__highlight"&gt;Expedition&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN&gt;as vsys you need to migrate, so you can use the drag and drop from each source to the desired vsys and later do the merge. &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="p-rich_text_section"&gt;&lt;SPAN&gt;&lt;SPAN&gt;Take into account to g&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;o to Dashboard and fix duplicates as well as check the network as could have duplicated interfaces, vr…&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="p-rich_text_section"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="p-rich_text_section"&gt;&lt;SPAN&gt;Hope this helps,&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="p-rich_text_section"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="p-rich_text_section"&gt;&lt;SPAN&gt;David&lt;/SPAN&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 08 Dec 2023 10:10:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-palo-alto-device-requirement/m-p/569022#M4864</guid>
      <dc:creator>dpuigdomenec</dc:creator>
      <dc:date>2023-12-08T10:10:41Z</dc:date>
    </item>
  </channel>
</rss>

