<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Expedition API when migrating Checkpoint to VSYS - zone issues in Expedition Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-api-when-migrating-checkpoint-to-vsys-zone-issues/m-p/240320#M814</link>
    <description>&lt;P&gt;Have you send the&amp;nbsp;Interfaces first?&lt;/P&gt;</description>
    <pubDate>Mon, 19 Nov 2018 14:07:03 GMT</pubDate>
    <dc:creator>alestevez</dc:creator>
    <dc:date>2018-11-19T14:07:03Z</dc:date>
    <item>
      <title>Expedition API when migrating Checkpoint to VSYS - zone issues</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-api-when-migrating-checkpoint-to-vsys-zone-issues/m-p/235476#M647</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm having a project for migrating several Checkpoint clusters to Palo Alto Vsys.&lt;/P&gt;
&lt;P&gt;I'm using Expedition version: 1.0.106 (the issue also resides in earlier versions).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm hitting&amp;nbsp;an issue when migrating the zones.&lt;/P&gt;
&lt;P&gt;1.Interfaces, virtual router and zones will be directly configured on the related gateway using API.&lt;/P&gt;
&lt;P&gt;2.Security policy and NAT will be loaded into the Panorama's specific devicegroup.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The issues is at stage 1.&lt;/P&gt;
&lt;P&gt;&amp;gt;migrating and configuring the interfaces using API works fine.&lt;/P&gt;
&lt;P&gt;&amp;gt;migrating and configuring the VR using the API works fine.&lt;/P&gt;
&lt;P&gt;&amp;gt;However the migration of zones isn't working at all.&lt;/P&gt;
&lt;P&gt;The zones (L3) has an interface associated which is also migrated and for which the creation (by API) worked out fine.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The API error output:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;{"6":{"device":"UTRFWONE5","status":"fail","text":"&amp;lt;msg&amp;gt;&amp;lt;line&amp;gt;&amp;lt;![CDATA[ zone -&amp;gt; Zone27 -&amp;gt; network -&amp;gt; layer3 \\'ae2.313\\' is not a valid reference]]&amp;gt;&amp;lt;\/line&amp;gt;&amp;lt;line&amp;gt;&amp;lt;![CDATA[ zone -&amp;gt; Zone27 -&amp;gt; network -&amp;gt; layer3 is invalid]]&amp;gt;&amp;lt;\/line&amp;gt;&amp;lt;\/msg&amp;gt;","date":"2018-10-16 05:51:22"}}&lt;/P&gt;
&lt;P&gt;I confirm in the situation above the interface: ae2.313 has been successfully configured using API.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;=&amp;gt; Only when you detach all interfaces from ALL zones, export the config - merge - generate API cmds - send API cmds the zones are created.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Couple remarks:&lt;/P&gt;
&lt;P&gt;-Interfaces can be mapped (manually) to the correct VSYS&lt;SPAN&gt;&amp;nbsp;in the Expedition tool.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;-Virtual routers cannot be mapped to a VSYS in the Expedition tool.&lt;/P&gt;
&lt;P&gt;-Zones cannot be mapped to a VSYS&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;in the Expedition tool, but within the zone view you can select an extra column: vsys.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;.... but it cannot be edited?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Would be good to have a solution on this one....&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks a lot,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Filip Elsen&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="API calls" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17166i115CA5459408B52A/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Expedition_API calls.PNG" alt="API calls" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;API calls&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Config merge" style="width: 504px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17165i0168FC468CE4F441/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Expedition_Merge.PNG" alt="Config merge" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Config merge&lt;/span&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Oct 2018 12:46:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-api-when-migrating-checkpoint-to-vsys-zone-issues/m-p/235476#M647</guid>
      <dc:creator>FilipElsen.Proximus</dc:creator>
      <dc:date>2018-10-16T12:46:59Z</dc:date>
    </item>
    <item>
      <title>Re: Expedition API when migrating Checkpoint to VSYS - zone issues</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-api-when-migrating-checkpoint-to-vsys-zone-issues/m-p/236184#M675</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Im not sure if I understand the problem....&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have you clicked on MERGE after the drag and drop?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Then from the PANOS config you can go to DEVICE - VIRTUAL SYSTEM and attach the VR&amp;nbsp;and Interfaces there. The same from the Zones itself you can assign to the VSYS...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What is exactly the problem you are facing?&lt;/P&gt;</description>
      <pubDate>Fri, 19 Oct 2018 13:59:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-api-when-migrating-checkpoint-to-vsys-zone-issues/m-p/236184#M675</guid>
      <dc:creator>alestevez</dc:creator>
      <dc:date>2018-10-19T13:59:16Z</dc:date>
    </item>
    <item>
      <title>Re: Expedition API when migrating Checkpoint to VSYS - zone issues</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-api-when-migrating-checkpoint-to-vsys-zone-issues/m-p/236187#M677</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes, the config has been merged.&lt;/P&gt;
&lt;P&gt;The issue is that when using the API to sent the network config towards the gateway (Pa5250), the subinterfaces, virtual router and routes get created, but the zones not.&lt;/P&gt;
&lt;P&gt;The zones only get pushed towards the gateway if all interfaces are detached from it, prior to performing a merge.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regards,&lt;/P&gt;
&lt;P&gt;Filip&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Oct 2018 14:04:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-api-when-migrating-checkpoint-to-vsys-zone-issues/m-p/236187#M677</guid>
      <dc:creator>FilipElsen.Proximus</dc:creator>
      <dc:date>2018-10-19T14:04:58Z</dc:date>
    </item>
    <item>
      <title>Re: Expedition API when migrating Checkpoint to VSYS - zone issues</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-api-when-migrating-checkpoint-to-vsys-zone-issues/m-p/240301#M811</link>
      <description>&lt;P&gt;Hi, any update on this one?&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Nov 2018 12:28:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-api-when-migrating-checkpoint-to-vsys-zone-issues/m-p/240301#M811</guid>
      <dc:creator>FilipElsen.Proximus</dc:creator>
      <dc:date>2018-11-19T12:28:36Z</dc:date>
    </item>
    <item>
      <title>Re: Expedition API when migrating Checkpoint to VSYS - zone issues</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-api-when-migrating-checkpoint-to-vsys-zone-issues/m-p/240302#M812</link>
      <description>&lt;P&gt;Interfaces are correcly created on the gateway using the API.&lt;/P&gt;
&lt;P&gt;Routes are correctly created on the gateway using the API.&lt;/P&gt;
&lt;P&gt;For every zone within the configuration, I'm receiving the output as shown below:&lt;/P&gt;
&lt;P&gt;The API error output:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;{"6":{"device":"UTRFWONE5","status":"fail","text":"&amp;lt;msg&amp;gt;&amp;lt;line&amp;gt;&amp;lt;![CDATA[ zone -&amp;gt; Zone27 -&amp;gt; network -&amp;gt; layer3 \\'ae2.313\\' is not a valid reference]]&amp;gt;&amp;lt;\/line&amp;gt;&amp;lt;line&amp;gt;&amp;lt;![CDATA[ zone -&amp;gt; Zone27 -&amp;gt; network -&amp;gt; layer3 is invalid]]&amp;gt;&amp;lt;\/line&amp;gt;&amp;lt;\/msg&amp;gt;","date":"2018-10-16 05:51:22"}}&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;All interfaces are L3, created earlier and have a correct ipv4 associated.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Nov 2018 12:32:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-api-when-migrating-checkpoint-to-vsys-zone-issues/m-p/240302#M812</guid>
      <dc:creator>FilipElsen.Proximus</dc:creator>
      <dc:date>2018-11-19T12:32:51Z</dc:date>
    </item>
    <item>
      <title>Re: Expedition API when migrating Checkpoint to VSYS - zone issues</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-api-when-migrating-checkpoint-to-vsys-zone-issues/m-p/240320#M814</link>
      <description>&lt;P&gt;Have you send the&amp;nbsp;Interfaces first?&lt;/P&gt;</description>
      <pubDate>Mon, 19 Nov 2018 14:07:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-api-when-migrating-checkpoint-to-vsys-zone-issues/m-p/240320#M814</guid>
      <dc:creator>alestevez</dc:creator>
      <dc:date>2018-11-19T14:07:03Z</dc:date>
    </item>
    <item>
      <title>Re: Expedition API when migrating Checkpoint to VSYS - zone issues</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-api-when-migrating-checkpoint-to-vsys-zone-issues/m-p/242488#M888</link>
      <description>&lt;P&gt;Yes, sure. These are created using API.&lt;/P&gt;
&lt;P&gt;Only the zone(s) - all of them - are causing issues.&lt;/P&gt;
&lt;P&gt;Has this been validated, tested?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks a lot,&lt;/P&gt;
&lt;P&gt;Filip&lt;/P&gt;</description>
      <pubDate>Fri, 07 Dec 2018 08:45:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-api-when-migrating-checkpoint-to-vsys-zone-issues/m-p/242488#M888</guid>
      <dc:creator>FilipElsen.Proximus</dc:creator>
      <dc:date>2018-12-07T08:45:27Z</dc:date>
    </item>
    <item>
      <title>Re: Expedition API when migrating Checkpoint to VSYS - zone issues</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-api-when-migrating-checkpoint-to-vsys-zone-issues/m-p/242673#M892</link>
      <description>&lt;P&gt;I was able to recreate your issue and will file a report for review:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Workaround - to send the config via API calls to Panorama&lt;/P&gt;
&lt;P&gt;-send the interfaces, ethernet and aggregate interfaces first&lt;/P&gt;
&lt;P&gt;-send the zones (remove the AE interface first from the zone)&lt;/P&gt;
&lt;P&gt;-on panorama edit the zone and add the AE as a member&lt;/P&gt;</description>
      <pubDate>Mon, 10 Dec 2018 01:43:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-api-when-migrating-checkpoint-to-vsys-zone-issues/m-p/242673#M892</guid>
      <dc:creator>sjanita</dc:creator>
      <dc:date>2018-12-10T01:43:02Z</dc:date>
    </item>
    <item>
      <title>Re: Expedition API when migrating Checkpoint to VSYS - zone issues</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-api-when-migrating-checkpoint-to-vsys-zone-issues/m-p/242678#M893</link>
      <description>&lt;P&gt;after more testing and debugging found the issue is with PanOS and not with the API request being generated by Expedition.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This only applies to AE interfaces being added to a security zone.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Workaround:&lt;/P&gt;
&lt;P&gt;Assumption is that the AE configuration has been completed in Expedition&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From the API output manager&lt;/P&gt;
&lt;P&gt;-send the interfaces&lt;/P&gt;
&lt;P&gt;-send the virtual router&lt;/P&gt;
&lt;P&gt;-remove the AE from the security zone&lt;/P&gt;
&lt;P&gt;-send the zone&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Transition to Panorama and add the AE to the appropriate security zone&lt;/P&gt;</description>
      <pubDate>Mon, 10 Dec 2018 03:53:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-api-when-migrating-checkpoint-to-vsys-zone-issues/m-p/242678#M893</guid>
      <dc:creator>sjanita</dc:creator>
      <dc:date>2018-12-10T03:53:48Z</dc:date>
    </item>
    <item>
      <title>Re: Expedition API when migrating Checkpoint to VSYS - zone issues</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-api-when-migrating-checkpoint-to-vsys-zone-issues/m-p/248440#M1094</link>
      <description>&lt;P&gt;Thanks for the update.&lt;/P&gt;
&lt;P&gt;I'll try the proposed steps and will come back asap.&lt;/P&gt;
&lt;P&gt;What's the ETA?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks a lot,&lt;/P&gt;
&lt;P&gt;Filip&lt;/P&gt;</description>
      <pubDate>Fri, 01 Feb 2019 12:05:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-api-when-migrating-checkpoint-to-vsys-zone-issues/m-p/248440#M1094</guid>
      <dc:creator>FilipElsen.Proximus</dc:creator>
      <dc:date>2019-02-01T12:05:56Z</dc:date>
    </item>
    <item>
      <title>Re: Expedition API when migrating Checkpoint to VSYS - zone issues</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-api-when-migrating-checkpoint-to-vsys-zone-issues/m-p/249421#M1120</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've just tested the proposed approach using API:&lt;/P&gt;
&lt;P&gt;From the API output manager&lt;/P&gt;
&lt;P&gt;-send the interfaces&lt;/P&gt;
&lt;P&gt;-send the virtual router&lt;/P&gt;
&lt;P&gt;-remove the AE from the security zone&lt;/P&gt;
&lt;P&gt;-send the zone&lt;/P&gt;
&lt;P&gt;=&amp;gt; This is working indeed.&lt;/P&gt;
&lt;P&gt;As mentioned, the Interface / Zone mapping&amp;nbsp;is required to be performed manually when the config is loaded onto the device.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After&amp;nbsp;the config was loaded via API (subint, vrouter and zone) I tried to get around the "zone to interface mapping" by:&lt;/P&gt;
&lt;P&gt;-Performing a commint on the FW&lt;/P&gt;
&lt;P&gt;-Re-import the device running config into Expedition&lt;/P&gt;
&lt;P&gt;-Loading the project configuration with the (pre-zone cleanings / thus containing the zone &amp;amp; interface mappings)&lt;/P&gt;
&lt;P&gt;-Export and Merge &lt;U&gt;only&lt;/U&gt; the zone config. (the rest is already onn the device, only the zone to interface mapping is missing).&lt;/P&gt;
&lt;P&gt;-Generate the API commands&lt;/P&gt;
&lt;P&gt;-....but it fails in the same way.&lt;/P&gt;
&lt;P&gt;{"21":{"device":"UTRFWONE5","status":"fail","text":"&amp;lt;msg&amp;gt;&amp;lt;line&amp;gt;&amp;lt;![CDATA[ zone -&amp;gt; Zone27 -&amp;gt; network -&amp;gt; layer3 \\'ae2.313\\' is not a valid reference]]&amp;gt;&amp;lt;\/line&amp;gt;&amp;lt;line&amp;gt;&amp;lt;![CDATA[ zone -&amp;gt; Zone27 -&amp;gt; network -&amp;gt; layer3 is invalid]]&amp;gt;&amp;lt;\/line&amp;gt;&amp;lt;\/msg&amp;gt;","date":"2019-02-08 04:07:35"}}&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regards,&lt;/P&gt;
&lt;P&gt;Filip&lt;/P&gt;</description>
      <pubDate>Fri, 08 Feb 2019 10:16:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-api-when-migrating-checkpoint-to-vsys-zone-issues/m-p/249421#M1120</guid>
      <dc:creator>FilipElsen.Proximus</dc:creator>
      <dc:date>2019-02-08T10:16:33Z</dc:date>
    </item>
  </channel>
</rss>

