<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Migration to PAN from Cisco in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/migration-to-pan-from-cisco/m-p/617292#M4995</link>
    <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I am newbie to PAN Firewall. Sorry that I haven't got much experience on Firewalls.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Currently we are in the middle of the migration as from the Cisco ASA with Firepower into PAN 1400 series. Have done some NATs and Security Policies migrations.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;The existing Cisco environment is with two Contexts and some experts assisted us to create two Virtual Routers (VR01 and VR02) to try to cover the setup in Cisco.&lt;/P&gt;&lt;P&gt;VR01 is closer to our internal, and VR02 is more internet facing.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;We also defined a few zones like, internal, priv_dmz, pub_dmz, inet_zone&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Since we have VRs, priv_dmz has one interface in VR01 and one in VR02, pub_dmz also has one interface in VR01 and one in VR02.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I apparently not familiar with the Virtual Routers. So here I got questions about that.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;1. when we are in Cisco, our PAT address was whitelisted by most of the vendors. but during the setup by the experts, they setup the PAT address into pub_dmz-VR02 IP 16.16.16.254, but the IP 16.16.16.252 is the PAT we used in Cisco. Can I change it to use priv_dmz-VR01? Not sure it has any effect on any other things.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;2. we are still using this Cisco VPN and will also migrate to GlobalProtect too. Currently this VPN gateway is mapped to IP 16.16.16.252. So if we keep the Num1 item above, would that affect the GP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;&lt;P&gt;Timothy&lt;/P&gt;</description>
    <pubDate>Wed, 13 Nov 2024 01:33:14 GMT</pubDate>
    <dc:creator>timothy.lau</dc:creator>
    <dc:date>2024-11-13T01:33:14Z</dc:date>
    <item>
      <title>Migration to PAN from Cisco</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/migration-to-pan-from-cisco/m-p/617292#M4995</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I am newbie to PAN Firewall. Sorry that I haven't got much experience on Firewalls.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Currently we are in the middle of the migration as from the Cisco ASA with Firepower into PAN 1400 series. Have done some NATs and Security Policies migrations.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;The existing Cisco environment is with two Contexts and some experts assisted us to create two Virtual Routers (VR01 and VR02) to try to cover the setup in Cisco.&lt;/P&gt;&lt;P&gt;VR01 is closer to our internal, and VR02 is more internet facing.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;We also defined a few zones like, internal, priv_dmz, pub_dmz, inet_zone&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Since we have VRs, priv_dmz has one interface in VR01 and one in VR02, pub_dmz also has one interface in VR01 and one in VR02.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I apparently not familiar with the Virtual Routers. So here I got questions about that.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;1. when we are in Cisco, our PAT address was whitelisted by most of the vendors. but during the setup by the experts, they setup the PAT address into pub_dmz-VR02 IP 16.16.16.254, but the IP 16.16.16.252 is the PAT we used in Cisco. Can I change it to use priv_dmz-VR01? Not sure it has any effect on any other things.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;2. we are still using this Cisco VPN and will also migrate to GlobalProtect too. Currently this VPN gateway is mapped to IP 16.16.16.252. So if we keep the Num1 item above, would that affect the GP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;&lt;P&gt;Timothy&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2024 01:33:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/migration-to-pan-from-cisco/m-p/617292#M4995</guid>
      <dc:creator>timothy.lau</dc:creator>
      <dc:date>2024-11-13T01:33:14Z</dc:date>
    </item>
  </channel>
</rss>

