<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Interface is showing invalid after migrating from cisco asa firewall in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/interface-is-showing-invalid-after-migrating-from-cisco-asa/m-p/357936#M87827</link>
    <description>&lt;P&gt;It appears to me, that the the PANW FW may already have interfaces that exist&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;OR&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The migration utility that you used created what would be duplicate entries within the XML.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If this is the issue, then you will need to carefully edit the XML and load in a clean config.&lt;/P&gt;
&lt;P&gt;Welcome to Professional Services!&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":face_with_tongue:"&gt;😛&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 21 Oct 2020 19:32:26 GMT</pubDate>
    <dc:creator>S.Cantwell</dc:creator>
    <dc:date>2020-10-21T19:32:26Z</dc:date>
    <item>
      <title>Interface is showing invalid after migrating from cisco asa firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/interface-is-showing-invalid-after-migrating-from-cisco-asa/m-p/357745#M87807</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have migrated the Cisco ASA firewall backup to PA NGFW.&lt;/P&gt;&lt;P&gt;After importing the backup, the validation error showing the interface is already in use.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="OsamaKhan_0-1603287621399.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/28317i88F6FD324F5DBF4D/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="OsamaKhan_0-1603287621399.png" alt="OsamaKhan_0-1603287621399.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;can anybody, help me how to resolve this issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Oct 2020 13:49:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/interface-is-showing-invalid-after-migrating-from-cisco-asa/m-p/357745#M87807</guid>
      <dc:creator>OsamaKhan</dc:creator>
      <dc:date>2020-10-21T13:49:22Z</dc:date>
    </item>
    <item>
      <title>Re: Interface is showing invalid after migrating from cisco asa firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/interface-is-showing-invalid-after-migrating-from-cisco-asa/m-p/357936#M87827</link>
      <description>&lt;P&gt;It appears to me, that the the PANW FW may already have interfaces that exist&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;OR&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The migration utility that you used created what would be duplicate entries within the XML.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If this is the issue, then you will need to carefully edit the XML and load in a clean config.&lt;/P&gt;
&lt;P&gt;Welcome to Professional Services!&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":face_with_tongue:"&gt;😛&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Oct 2020 19:32:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/interface-is-showing-invalid-after-migrating-from-cisco-asa/m-p/357936#M87827</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2020-10-21T19:32:26Z</dc:date>
    </item>
    <item>
      <title>Re: Interface is showing invalid after migrating from cisco asa firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/interface-is-showing-invalid-after-migrating-from-cisco-asa/m-p/358022#M87833</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/113304"&gt;@S.Cantwell&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it possible to remove duplicate entries from XML?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you share KB article or guide to resolve it&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Oct 2020 05:36:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/interface-is-showing-invalid-after-migrating-from-cisco-asa/m-p/358022#M87833</guid>
      <dc:creator>OsamaKhan</dc:creator>
      <dc:date>2020-10-22T05:36:02Z</dc:date>
    </item>
    <item>
      <title>Re: Interface is showing invalid after migrating from cisco asa firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/interface-is-showing-invalid-after-migrating-from-cisco-asa/m-p/358314#M87870</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Yes you can change the XML, however be cautious as to what you are editing in/out. Did you use the import tool, expedition? I always prefer to build my firewall from scratch so I become familiar with the new config and make sure I dont transfer any old policies/configs that are no longer valid. But I understand if its a big config that is not possible. It does seem that the import is attempting to create new interfaces and it should not.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/products/secure-the-network/next-generation-firewall/migration-tool" target="_blank"&gt;https://www.paloaltonetworks.com/products/secure-the-network/next-generation-firewall/migration-tool&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Thu, 22 Oct 2020 22:15:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/interface-is-showing-invalid-after-migrating-from-cisco-asa/m-p/358314#M87870</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2020-10-22T22:15:47Z</dc:date>
    </item>
    <item>
      <title>Re: Interface is showing invalid after migrating from cisco asa firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/interface-is-showing-invalid-after-migrating-from-cisco-asa/m-p/358732#M87913</link>
      <description>&lt;P&gt;Hello again.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I thought this group already explained, but let's try again.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Open the xml with an editor like Notepad++&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Search for all instances of your interfaces&lt;/P&gt;
&lt;P&gt;When you open the xml, you will probably find duplicate entries.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For the sake of example... I will only use ethernet1/1&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;lt;devices&amp;gt;&lt;BR /&gt;&amp;lt;entry name="localhost.localdomain"&amp;gt;&lt;BR /&gt;&amp;lt;network&amp;gt;&lt;BR /&gt;&amp;lt;interface&amp;gt;&lt;BR /&gt;&amp;lt;ethernet&amp;gt;&lt;BR /&gt;&amp;lt;entry name="ethernet1/1"&amp;gt;&lt;BR /&gt;&amp;lt;layer3&amp;gt;&lt;BR /&gt;&amp;lt;ndp-proxy&amp;gt;&lt;BR /&gt;&amp;lt;enabled&amp;gt;no&amp;lt;/enabled&amp;gt;&lt;BR /&gt;&amp;lt;/ndp-proxy&amp;gt;&lt;BR /&gt;&amp;lt;ip&amp;gt;&lt;BR /&gt;&amp;lt;entry name="172.26.0.1/16"/&amp;gt;&lt;BR /&gt;&amp;lt;/ip&amp;gt;&lt;BR /&gt;&amp;lt;lldp&amp;gt;&lt;BR /&gt;&amp;lt;enable&amp;gt;no&amp;lt;/enable&amp;gt;&lt;BR /&gt;&amp;lt;/lldp&amp;gt;&lt;BR /&gt;&amp;lt;/layer3&amp;gt;&lt;BR /&gt;&amp;lt;/entry&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The above if the config for ethernet1/1....&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Having a single instance of Ethernet1/1 is correct.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But, if you look in your config.. you may have a 2nd instance&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;lt;devices&amp;gt;&lt;BR /&gt;&amp;lt;entry name="localhost.localdomain"&amp;gt;&lt;BR /&gt;&amp;lt;network&amp;gt;&lt;BR /&gt;&amp;lt;interface&amp;gt;&lt;BR /&gt;&amp;lt;ethernet&amp;gt;&lt;BR /&gt;&amp;lt;entry name="ethernet1/1"&amp;gt;&lt;BR /&gt;&amp;lt;layer3&amp;gt;&lt;BR /&gt;&amp;lt;ndp-proxy&amp;gt;&lt;BR /&gt;&amp;lt;enabled&amp;gt;no&amp;lt;/enabled&amp;gt;&lt;BR /&gt;&amp;lt;/ndp-proxy&amp;gt;&lt;BR /&gt;&amp;lt;ip&amp;gt;&lt;BR /&gt;&amp;lt;entry name="172.26.0.1/16"/&amp;gt;&lt;BR /&gt;&amp;lt;/ip&amp;gt;&lt;BR /&gt;&amp;lt;lldp&amp;gt;&lt;BR /&gt;&amp;lt;enable&amp;gt;no&amp;lt;/enable&amp;gt;&lt;BR /&gt;&amp;lt;/lldp&amp;gt;&lt;BR /&gt;&amp;lt;/layer3&amp;gt;&lt;BR /&gt;&amp;lt;/entry&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;OR&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You could have duplicate elsewhere.. like routing table:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;lt;virtual-router&amp;gt;&lt;BR /&gt;&amp;lt;entry name="default"&amp;gt;&lt;BR /&gt;&amp;lt;interface&amp;gt;&lt;BR /&gt;&amp;lt;member&amp;gt;ethernet1/1&amp;lt;/member&amp;gt;&lt;BR /&gt;&amp;lt;member&amp;gt;ethernet1/2&amp;lt;/member&amp;gt;&lt;BR /&gt;&amp;lt;member&amp;gt;ethernet1/3&amp;lt;/member&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;lt;member&amp;gt;ethernet1/1&amp;lt;/member&amp;gt;&lt;BR /&gt;&amp;lt;member&amp;gt;ethernet1/2&amp;lt;/member&amp;gt;&lt;BR /&gt;&amp;lt;member&amp;gt;ethernet1/3&amp;lt;/member&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;lt;/interface&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Notice that I duplicated (for example my eth1/1 through eth1/3)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You just need to roll up your sleeves, and manually remove your duplicate interface configs, wherever they are, in your config.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Oct 2020 10:04:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/interface-is-showing-invalid-after-migrating-from-cisco-asa/m-p/358732#M87913</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2020-10-26T10:04:45Z</dc:date>
    </item>
  </channel>
</rss>

