ASA to PANOS Migration

L1 Bithead

ASA to PANOS Migration

Hi,

 

I am migrating an ASA config over to PANOS using the migration tool. I havent been able to figure out why the static nat rules are not migrating successfully. This is also breaking the ACL conversion as well. I am on expedition tool 1.1.33.

 

thanks

Community Team Member

Re: ASA to PANOS Migration

Hi @Tarik_Admani ,

 

I think you'll have better luck with your question in the Expedition discussions area so I moved it here.

 

Good luck !

-Kiwi.

L4 Transporter

Re: ASA to PANOS Migration

Could you share the configuration with us (or at least a relevant snippet of the configuration) to our email (fwmigrate at paloaltonetworks dot com) to check what may be happening?

L1 Bithead

Re: ASA to PANOS Migration

Yes sir,

 

I see these errors in the migraiton tool - 

 

Nat RuleID [89] is trying to apply a group to the translated packet. [nat (inside,outside) static x.x.x.x]. Rule not imported

 

I sent a scrubbed snippet to the email alias - basically this example of the nat conversion is in one of the 7 step migration videos on youtube. 

 

Thanks,

L1 Bithead

Re: ASA to PANOS Migration

Thanks Kiwi!

L1 Bithead

Re: ASA to PANOS Migration

Thanks for the help, to update anyone else that runs into this, I had to downgrade expedition to 1.1.28 and the nat rules and security policies migrated, going through the final review right now. 

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!