<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Expedition not importing NAT or security policies from PA-3020s running PAN-OS 9.1 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/expedition-not-importing-nat-or-security-policies-from-pa-3020s/m-p/588127#M117289</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1475401389"&gt;@J.Yarborough&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;One thing that I forgot is that the 1st PANW config file loaded into Expedition is the base config.&amp;nbsp; You could try loading the PA-1420 config 1st then the PA-3020.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
    <pubDate>Tue, 28 May 2024 16:53:57 GMT</pubDate>
    <dc:creator>TomYoung</dc:creator>
    <dc:date>2024-05-28T16:53:57Z</dc:date>
    <item>
      <title>Expedition not importing NAT or security policies from PA-3020s running PAN-OS 9.1</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/expedition-not-importing-nat-or-security-policies-from-pa-3020s/m-p/587914#M117258</link>
      <description>&lt;P&gt;I'm working on a project to upgrade 2 x PA-3020s each with their own configuration into an HA pair of PA-1420s and am having trouble with Expedition. I've tried importing the devices using the API key and also by exporting the running-config.xml file as a superuser and manually importing it into Expedition. Both are giving the same results. My "Project Statistics pane shows 0 Security Rules and 0 Nat Rules, which I think is also making most of my Address objects show up as Ghost. If I open the XML file directly, I see &amp;lt;rulebase&amp;gt; starts on line 4759 and &amp;lt;/rulebase&amp;gt; ends on line 19820 so there are definitely rules. This is happening on both of my PA-3020s when I try to import them.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am not using Panorama, just managing each firewall individually.&amp;nbsp; I've tried to restart the VM and run the version update but I was already on the latest.&amp;nbsp; All services on the dashboard are green (although after a restart I have to click remediate to get the order agent running).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any thoughts? I haven't added the PA-1420s in yet as they are only connected via serial cables at the moment.&amp;nbsp; In fact, I just noticed that pa1XXX isn't even an option under models so I'm not sure if this will work at all.&amp;nbsp; I was really hoping that Expedition would cut a significant amount of time off our config consolidation and migration plan but this isn't looking so great.&lt;/P&gt;</description>
      <pubDate>Fri, 24 May 2024 21:44:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/expedition-not-importing-nat-or-security-policies-from-pa-3020s/m-p/587914#M117258</guid>
      <dc:creator>J.Yarborough</dc:creator>
      <dc:date>2024-05-24T21:44:00Z</dc:date>
    </item>
    <item>
      <title>Re: Expedition not importing NAT or security policies from PA-3020s running PAN-OS 9.1</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/expedition-not-importing-nat-or-security-policies-from-pa-3020s/m-p/587951#M117263</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1475401389"&gt;@J.Yarborough&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does the bottom right drop down say vsys1?&amp;nbsp; Also, is your Expedition up-to-date?&amp;nbsp; Send an email to fwmigrate@paloaltonetworks.com and someone will assist.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Mon, 27 May 2024 00:19:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/expedition-not-importing-nat-or-security-policies-from-pa-3020s/m-p/587951#M117263</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2024-05-27T00:19:02Z</dc:date>
    </item>
    <item>
      <title>Re: Expedition not importing NAT or security policies from PA-3020s running PAN-OS 9.1</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/expedition-not-importing-nat-or-security-policies-from-pa-3020s/m-p/588126#M117288</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/6440"&gt;@Tom&lt;/a&gt;, I've tried switching the options in the bottom right between all/shared/vsys1 and it doesn't seem to help.&amp;nbsp; On the main dashboard view, it only lets me switch between the config files.&amp;nbsp; I've tried both PA-3020s that I've connected, as well as a manual export of the config, but each still shows 0 for Service Groups, Security Rules, Nat Rules, and Application Override Rules.&amp;nbsp; Either way, when I click into Nat Rules for example, it pulls up vsys1 and the message says "Select a vsys with rules".&amp;nbsp; Same message regardless of config or scope.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As for running the latest, I believe so?&amp;nbsp; I did get a popup saying a newer version was available, but when I ran the commands to update it said I was already on the latest.&amp;nbsp; The message might have been right after I rebooted the server or something so it might not have been up all the way or something.&amp;nbsp; My versions are:&lt;BR /&gt;Expedition:&amp;nbsp; 1.2.90&lt;BR /&gt;Spark Dependencies:&amp;nbsp; 0.1.3-h3&lt;BR /&gt;Best Practices:&amp;nbsp; 3.33.0&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'll send an email to the address you mentioned.&amp;nbsp; Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 28 May 2024 16:42:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/expedition-not-importing-nat-or-security-policies-from-pa-3020s/m-p/588126#M117288</guid>
      <dc:creator>J.Yarborough</dc:creator>
      <dc:date>2024-05-28T16:42:01Z</dc:date>
    </item>
    <item>
      <title>Re: Expedition not importing NAT or security policies from PA-3020s running PAN-OS 9.1</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/expedition-not-importing-nat-or-security-policies-from-pa-3020s/m-p/588127#M117289</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1475401389"&gt;@J.Yarborough&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;One thing that I forgot is that the 1st PANW config file loaded into Expedition is the base config.&amp;nbsp; You could try loading the PA-1420 config 1st then the PA-3020.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Tue, 28 May 2024 16:53:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/expedition-not-importing-nat-or-security-policies-from-pa-3020s/m-p/588127#M117289</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2024-05-28T16:53:57Z</dc:date>
    </item>
    <item>
      <title>Re: Expedition not importing NAT or security policies from PA-3020s running PAN-OS 9.1</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/expedition-not-importing-nat-or-security-policies-from-pa-3020s/m-p/588322#M117309</link>
      <description>&lt;P&gt;Well, good news!&amp;nbsp; I cleared out all of my devices and projects to try and start with the PA-1420 but I noticed an upgrade was available (1.2.90 -&amp;gt; 1.2.90.1).&amp;nbsp; I ran the update, added my devices back in, created a project, imported, and it seems to see all my objects now!&lt;/P&gt;</description>
      <pubDate>Wed, 29 May 2024 23:42:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/expedition-not-importing-nat-or-security-policies-from-pa-3020s/m-p/588322#M117309</guid>
      <dc:creator>J.Yarborough</dc:creator>
      <dc:date>2024-05-29T23:42:57Z</dc:date>
    </item>
  </channel>
</rss>

