<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Palo Alto Expedition Tool - Fortigate Configuration Migration in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-expedition-tool-fortigate-configuration-migration/m-p/279735#M75753</link>
    <description>Dear Team, Need to know how to migrate the Fortigate configuration file to Palo Alto Expedition Tool. Please share if any documentation specific to Fortigate to Palo Alto Migration.</description>
    <pubDate>Mon, 29 Jul 2019 13:40:11 GMT</pubDate>
    <dc:creator>ecesureshkumar</dc:creator>
    <dc:date>2019-07-29T13:40:11Z</dc:date>
    <item>
      <title>Palo Alto Expedition Tool - Fortigate Configuration Migration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-expedition-tool-fortigate-configuration-migration/m-p/279735#M75753</link>
      <description>Dear Team, Need to know how to migrate the Fortigate configuration file to Palo Alto Expedition Tool. Please share if any documentation specific to Fortigate to Palo Alto Migration.</description>
      <pubDate>Mon, 29 Jul 2019 13:40:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-expedition-tool-fortigate-configuration-migration/m-p/279735#M75753</guid>
      <dc:creator>ecesureshkumar</dc:creator>
      <dc:date>2019-07-29T13:40:11Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Expedition Tool - Fortigate Configuration Migration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-expedition-tool-fortigate-configuration-migration/m-p/279774#M75766</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Depending on the amount of policies in the Forti device, I always preferred to build everything from scratch. That way everything is already layer 7 and inspected.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/best-practices/9-0/best-practices-for-migrating-to-application-based-policy/best-practices-for-migrating-to-application-based-policy/migrate-a-port-based-policy-to-pan-os-using-expedition.html" target="_blank"&gt;https://docs.paloaltonetworks.com/best-practices/9-0/best-practices-for-migrating-to-application-based-policy/best-practices-for-migrating-to-application-based-policy/migrate-a-port-based-policy-to-pan-os-using-expedition.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jul 2019 15:32:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-expedition-tool-fortigate-configuration-migration/m-p/279774#M75766</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-07-29T15:32:17Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Expedition Tool - Fortigate Configuration Migration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-expedition-tool-fortigate-configuration-migration/m-p/279799#M75770</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/107671"&gt;@ecesureshkumar&lt;/a&gt;&amp;nbsp;I am not aware of Fortigate-specific documentation, but the Expedtion guides are here:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Expedition-Articles/Expedition-Documentation/ta-p/215619" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Expedition-Articles/Expedition-Documentation/ta-p/215619&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jul 2019 16:21:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-expedition-tool-fortigate-configuration-migration/m-p/279799#M75770</guid>
      <dc:creator>BatD</dc:creator>
      <dc:date>2019-07-29T16:21:45Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Expedition Tool - Fortigate Configuration Migration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-expedition-tool-fortigate-configuration-migration/m-p/435321#M96062</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/107671"&gt;@ecesureshkumar&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is a newer Expedition user guide here -&amp;gt; &lt;A href="https://live.paloaltonetworks.com/t5/expedition-articles/expedition-user-guide-v1-2/ta-p/285157" target="_blank" rel="noopener"&gt;https://live.paloaltonetworks.com/t5/expedition-articles/expedition-user-guide-v1-2/ta-p/285157&lt;/A&gt;.&amp;nbsp; It is really good.&amp;nbsp; There are a few things I would like to highlight:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;The 1st PAN-OS configuration imported becomes your base config.&amp;nbsp; It doesn't matter at which step you load it.&amp;nbsp; I prefer to load the Day 1 Configuration on the new firewall, export it and import it into Expedition.&amp;nbsp; In that way, you will have many best practices configured.&lt;/LI&gt;&lt;LI&gt;With regard to cleaning up objects, do the groups first.&amp;nbsp; Then click the green button in the lower right, and more unused member objects may show up.&lt;/LI&gt;&lt;LI&gt;If the config is grayed-out or doesn't show, make sure you select the correct drop downs in the bottom right.&amp;nbsp; Most of the time, you will be working with vsys1.&lt;/LI&gt;&lt;LI&gt;Clicking on the dashboard numbers will automatically enable a filter.&amp;nbsp; Clear filters in the top right.&amp;nbsp; You can also select predefined filters from right-click.&lt;/LI&gt;&lt;LI&gt;Right-click and select Search and Replace to show you where in the config file and object is used.&amp;nbsp; After Search and Replace comes up, you have to check the box next to the object.&lt;/LI&gt;&lt;LI&gt;If the config has ICMP in the security policy, importing the Palo Alto &amp;gt; Snippets &amp;gt; Custom Applications creates ICMP App-IDs.&lt;/LI&gt;&lt;LI&gt;I like to export the XML and load on the firewall.&amp;nbsp; It will replace the entire config.&amp;nbsp; You could also use the API or load config partial.&lt;/LI&gt;&lt;LI&gt;With regard to &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt; 's comment.&amp;nbsp; Expedition can sometimes cause commit errors because of XML syntax errors.&amp;nbsp; I always load these on a lab firewall first to fix the issues before the customer firewall.&amp;nbsp; However, for large configurations, Expedition saves me a LOT of time cleaning unused, duplicate, and invalid objects.&amp;nbsp; The resulting config is SO much better.&amp;nbsp; I prefer using it then doing the config from scratch.&lt;/LI&gt;&lt;LI&gt;The majority of the commit errors are self-explanatory.&amp;nbsp; A very few times (both associated with IPsec) I got commit failures with no warning.&amp;nbsp; This article was useful -&amp;gt; &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PMb2CAG" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PMb2CAG&lt;/A&gt;.&amp;nbsp; You can always delete the offending config piece.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;That's enough for now.&amp;nbsp; I love the tool.&amp;nbsp; If you have issues, send an email to &lt;A href="mailto:fwmigrate@paloaltonetworks.com" target="_blank" rel="noopener"&gt;fwmigrate@paloaltonetworks.com&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Mon, 20 Sep 2021 19:37:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-expedition-tool-fortigate-configuration-migration/m-p/435321#M96062</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2021-09-20T19:37:28Z</dc:date>
    </item>
  </channel>
</rss>

