<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Convert VSD Juniper(Screen OS) configuration to Palo Alto in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/convert-vsd-juniper-screen-os-configuration-to-palo-alto/m-p/394241#M91087</link>
    <description>&lt;DIV class="grid-x "&gt;&lt;DIV class="medium-12 cell"&gt;&lt;P&gt;&lt;SPAN&gt;Hi team,&lt;BR /&gt;&lt;BR /&gt;We have a Juniper firewall configuration with 4 VSD(virtual security device) and we want to migrate that kind of configuration on Palo Alto.&lt;BR /&gt;&lt;BR /&gt;We have tried to migrate that configuration but we didn't find this capability on palo alto firewall.&lt;BR /&gt;&lt;BR /&gt;Does exist any similiar capability in palo alto?&lt;BR /&gt;&lt;BR /&gt;Thanks ,&lt;BR /&gt;Regards.&lt;/SPAN&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
    <pubDate>Fri, 26 Mar 2021 10:35:06 GMT</pubDate>
    <dc:creator>Fjrubiab</dc:creator>
    <dc:date>2021-03-26T10:35:06Z</dc:date>
    <item>
      <title>Convert VSD Juniper(Screen OS) configuration to Palo Alto</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/convert-vsd-juniper-screen-os-configuration-to-palo-alto/m-p/394241#M91087</link>
      <description>&lt;DIV class="grid-x "&gt;&lt;DIV class="medium-12 cell"&gt;&lt;P&gt;&lt;SPAN&gt;Hi team,&lt;BR /&gt;&lt;BR /&gt;We have a Juniper firewall configuration with 4 VSD(virtual security device) and we want to migrate that kind of configuration on Palo Alto.&lt;BR /&gt;&lt;BR /&gt;We have tried to migrate that configuration but we didn't find this capability on palo alto firewall.&lt;BR /&gt;&lt;BR /&gt;Does exist any similiar capability in palo alto?&lt;BR /&gt;&lt;BR /&gt;Thanks ,&lt;BR /&gt;Regards.&lt;/SPAN&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 26 Mar 2021 10:35:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/convert-vsd-juniper-screen-os-configuration-to-palo-alto/m-p/394241#M91087</guid>
      <dc:creator>Fjrubiab</dc:creator>
      <dc:date>2021-03-26T10:35:06Z</dc:date>
    </item>
    <item>
      <title>Re: Convert VSD Juniper(Screen OS) configuration to Palo Alto</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/convert-vsd-juniper-screen-os-configuration-to-palo-alto/m-p/394260#M91089</link>
      <description>&lt;P&gt;Read about Palo Alto virtual systems as it is similart to VSD but you need to have the correct palo Alto model and license for VSYS:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/virtual-systems/virtual-systems-overview" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/virtual-systems/virtual-systems-overview&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/virtual-systems/virtual-systems-overview/platform-support-and-licensing-for-virtual-systems.html" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/virtual-systems/virtual-systems-overview/platform-support-and-licensing-for-virtual-systems.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also the Palo Alto migration tool could be tested to migrate the security configuration to some extend:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/products/secure-the-network/next-generation-firewall/migration-tool" target="_blank" rel="noopener"&gt;https://www.paloaltonetworks.com/products/secure-the-network/next-generation-firewall/migration-tool&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Mar 2021 11:19:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/convert-vsd-juniper-screen-os-configuration-to-palo-alto/m-p/394260#M91089</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2021-03-26T11:19:03Z</dc:date>
    </item>
    <item>
      <title>Re: Convert VSD Juniper(Screen OS) configuration to Palo Alto</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/convert-vsd-juniper-screen-os-configuration-to-palo-alto/m-p/394345#M91113</link>
      <description>&lt;P&gt;I think that this solution is not valid because in the configuration each subinterface needs an IP. For example&lt;/P&gt;&lt;P&gt;(belongs VSD 0)set interface ethernet0 / 0.99 ip X.Y.Z.32/24&lt;BR /&gt;(belongs VSD 0)set interface ethernet0 / 0.99 route&lt;BR /&gt;(belongs VSD 1)set interface ethernet0 / 0.99: 1 ip X.Y.Z.30/24&lt;BR /&gt;(belongs VSD 1)set interface ethernet0 / 0.99: 1 route&lt;BR /&gt;(belongs VSD 2)set interface ethernet0 / 0.99: 2 ip X.Y.Z.29/24&lt;BR /&gt;(belongs VSD 2)set interface ethernet0 / 0.99: 2 route&lt;BR /&gt;(belongs VSD 3)set interface ethernet0 / 0.99: 3 ip X.Y.Z.31/24&lt;BR /&gt;(belongs VSD 3)set interface ethernet0 / 0.99: 3 route&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;They also share the same security policies, objects, and the rest of the configuration. And the cluster configuration is active / active. VSD 0 and 2 are active on firewall A and passive on firewall B. AND VSD 1 and 3 are active on firewall B and passive on firewall A.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://kb.juniper.net/InfoCenter/index?page=content&amp;amp;id=KB7051&amp;amp;cat=NS_204&amp;amp;actp=LIST" target="_blank" rel="noopener"&gt;https://kb.juniper.net/InfoCenter/index?page=content&amp;amp;id=KB7051&amp;amp;cat=NS_204&amp;amp;actp=LIST&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Mar 2021 14:03:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/convert-vsd-juniper-screen-os-configuration-to-palo-alto/m-p/394345#M91113</guid>
      <dc:creator>Fjrubiab</dc:creator>
      <dc:date>2021-03-26T14:03:15Z</dc:date>
    </item>
    <item>
      <title>Re: Convert VSD Juniper(Screen OS) configuration to Palo Alto</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/convert-vsd-juniper-screen-os-configuration-to-palo-alto/m-p/394469#M91143</link>
      <description>&lt;P&gt;Better test the Palo Alto as you can also create sub interfaces from one physical and attach them to a vsys. Each VSYS will have its own virtual router and there is an option one vsys to send the traffic to another vsys if needed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFgCAK" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFgCAK&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also shared objects can be configured, so that when you configure one object to&amp;nbsp; be present in all vsys:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/virtual-systems/virtual-systems-overview/shared-objects-for-virtual-systems.html" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/virtual-systems/virtual-systems-overview/shared-objects-for-virtual-systems.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For VSYS active/active there is not exactly the same but you can check below post as the chassis are in active/active and a virtual ip address is used that active just on one of the chassis&amp;nbsp; and standby on the other. The virtual ip will e related to a specific vsys, so for example vsys 1 will be get the traffic on chassis 1 and vsys 2 will get the traffic on chassis2:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/general-topics/ha-active-active-mode-with-multi-vsys/td-p/278637" target="_blank" rel="noopener"&gt;https://live.paloaltonetworks.com/t5/general-topics/ha-active-active-mode-with-multi-vsys/td-p/278637&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/high-availability/ha-concepts/floating-ip-address-and-virtual-mac-address.html" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/high-availability/ha-concepts/floating-ip-address-and-virtual-mac-address.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I suggest asking palo alto for a demo and can we close this thread as it is better to test this with a live demo ?&lt;/P&gt;</description>
      <pubDate>Fri, 26 Mar 2021 19:06:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/convert-vsd-juniper-screen-os-configuration-to-palo-alto/m-p/394469#M91143</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2021-03-26T19:06:02Z</dc:date>
    </item>
  </channel>
</rss>

