<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA migration to PA in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/asa-migration-to-pa/m-p/535575#M110159</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;If the PAN's are running newer code, etc, they will learn and suggest applications to the policies as you input them.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
    <pubDate>Thu, 23 Mar 2023 15:12:11 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2023-03-23T15:12:11Z</dc:date>
    <item>
      <title>ASA migration to PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/asa-migration-to-pa/m-p/535547#M110157</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;
&lt;P&gt;We want to migrate our firewalls from cisco ASA to Palo Alto. Instead of performing hot cutover, we are thinking the other option by connecting them inline to existing firewalls so that it will just monitor all policy and etc, which will help us to fix any of the configurations so that we can remove the existing firewalls without any major issue. Please suggest a way to deploy or share if there is any documentation relate to it.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Mar 2023 13:30:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/asa-migration-to-pa/m-p/535547#M110157</guid>
      <dc:creator>Bkrishnamoorthy</dc:creator>
      <dc:date>2023-03-23T13:30:27Z</dc:date>
    </item>
    <item>
      <title>Re: ASA migration to PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/asa-migration-to-pa/m-p/535562#M110158</link>
      <description>&lt;P&gt;If you want to put Palos inline then it's interfaces need to be in virtual-wire mode for that period.&lt;/P&gt;
&lt;P&gt;It allows to capture traffic and reverse engineer what policies need to be configured but it is way easier to migrate like-to-like to be sure everything is working after migration and then tune policies as needed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Mar 2023 14:40:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/asa-migration-to-pa/m-p/535562#M110158</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-03-23T14:40:57Z</dc:date>
    </item>
    <item>
      <title>Re: ASA migration to PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/asa-migration-to-pa/m-p/535575#M110159</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;If the PAN's are running newer code, etc, they will learn and suggest applications to the policies as you input them.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Thu, 23 Mar 2023 15:12:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/asa-migration-to-pa/m-p/535575#M110159</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2023-03-23T15:12:11Z</dc:date>
    </item>
    <item>
      <title>Re: ASA migration to PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/asa-migration-to-pa/m-p/535578#M110160</link>
      <description>&lt;P&gt;Yes&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt;&amp;nbsp; Intially i thought the same of doing like-to-like migration, but we won't have any user for UAT during maintenance window, only they will be available in the next morning. Since we have some hundred of policies, if many are impacted it would be a nightmare. In order avoid that i looking for virrual wire option, is there migration document available?&lt;/P&gt;</description>
      <pubDate>Thu, 23 Mar 2023 16:12:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/asa-migration-to-pa/m-p/535578#M110160</guid>
      <dc:creator>Bkrishnamoorthy</dc:creator>
      <dc:date>2023-03-23T16:12:39Z</dc:date>
    </item>
    <item>
      <title>Re: ASA migration to PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/asa-migration-to-pa/m-p/535579#M110161</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;It's a PA 5420 model and so we would run a latest code.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Mar 2023 16:13:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/asa-migration-to-pa/m-p/535579#M110161</guid>
      <dc:creator>Bkrishnamoorthy</dc:creator>
      <dc:date>2023-03-23T16:13:35Z</dc:date>
    </item>
    <item>
      <title>Re: ASA migration to PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/asa-migration-to-pa/m-p/535580#M110162</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I also want to point out that there is the 'Expedition' tool for migrating configurations from another platform to Palo Alto. I have not used it before, however others have stated that it worked fairly well. Also I would suggesting on leaning on your sales engineer to help out, etc.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/expedition/ct-p/migration_tool" target="_blank"&gt;https://live.paloaltonetworks.com/t5/expedition/ct-p/migration_tool&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Thu, 23 Mar 2023 16:22:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/asa-migration-to-pa/m-p/535580#M110162</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2023-03-23T16:22:03Z</dc:date>
    </item>
    <item>
      <title>Re: ASA migration to PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/asa-migration-to-pa/m-p/535587#M110163</link>
      <description>&lt;P&gt;Expedition is very nice tool but depending of ASA config it needs manual review and not everything is migrated over.&lt;/P&gt;
&lt;P&gt;Unless customer is ok to fix any upcoming issues morning after migration I would definitely expect customer side UAT testing right after failover.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Mar 2023 16:50:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/asa-migration-to-pa/m-p/535587#M110163</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-03-23T16:50:44Z</dc:date>
    </item>
    <item>
      <title>Re: ASA migration to PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/asa-migration-to-pa/m-p/541222#M110954</link>
      <description>&lt;P&gt;Is there any sample configuration to set it up for inline , so that i can review the polices and fix them.&lt;/P&gt;</description>
      <pubDate>Fri, 05 May 2023 12:51:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/asa-migration-to-pa/m-p/541222#M110954</guid>
      <dc:creator>Bkrishnamoorthy</dc:creator>
      <dc:date>2023-05-05T12:51:24Z</dc:date>
    </item>
    <item>
      <title>Re: ASA migration to PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/asa-migration-to-pa/m-p/541254#M110956</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;So the inline method, you will want to do the following:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Create a virtual wire, vwire, ie port 1 and 2
&lt;OL&gt;
&lt;LI&gt;1 will be from the PAN to the ASA and 2 will be from the PAN to the internal switch&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;LI&gt;Create a Allow ALL policy between the two zones
&lt;OL&gt;
&lt;LI&gt;Then make sure to keep that Allow ALL policy at the bottom, eg last policy&lt;/LI&gt;
&lt;LI&gt;Create any policies for the traffic that are specific above the policy so that it will get hit first.&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Hope that makes sense.&lt;/P&gt;</description>
      <pubDate>Fri, 05 May 2023 14:37:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/asa-migration-to-pa/m-p/541254#M110956</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2023-05-05T14:37:26Z</dc:date>
    </item>
    <item>
      <title>Re: ASA migration to PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/asa-migration-to-pa/m-p/541263#M110958</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp; Thanks for your input.&lt;/P&gt;</description>
      <pubDate>Fri, 05 May 2023 14:56:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/asa-migration-to-pa/m-p/541263#M110958</guid>
      <dc:creator>Bkrishnamoorthy</dc:creator>
      <dc:date>2023-05-05T14:56:18Z</dc:date>
    </item>
  </channel>
</rss>

