Reply
L0 Member
Posts: 1
Registered: ‎10-29-2018

ASA Migration - Zones

We are in process of migrating ASA config to Palo Alto (multiple context asa to multiple vsys)

 

Loading the config into Expedition works fine and we are able to remap interfaces and rename zones that are too long in characters. However, when loading the config into the firewall it is unable to link the interfaces to zones

 

vsys -> vsys1 -> zone -> "zonename" -> network -> layer3 'ae1."X"' is not a valid reference

 

This show up on all interfaces on all zone. For now the workaround is to not attach interfaces to zones when importing the config and do it on the firewall once loaded.

 

Also we have some NAT rules that exceed 31 characters that must be renamed. How can i locate these in expedition? I only see them once i try to load the config in the firewall

 

L4 Transporter
Posts: 187
Registered: ‎05-01-2009

Re: ASA Migration - Zones

For the zones names that exceed 31 characters you can see the warning message under the 'Monitor' tab when logged into your project. 

 

For the Zone mappings, this occurs when you merge the migrated config into your base configuration. 

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!