Expedition version 4 - SRX to Palo Alto migration issue

Reply
L1 Bithead

Expedition version 4 - SRX to Palo Alto migration issue

I am using Expedition Version4.

 

SRX JunOs configs to PanOs migration,  only few interfaces, zones and one VR(logging-vr) are getting migrated. Tool doesn't detect any security groups, address books, security policies...etc. We have hundreds of security groups in one box, which are configured for different customers. All the security groups need to be migrated one by one.

 

Toatally I am unable to migrate the whole SRX configuration to Palo alto, except few base configs of the box.

 

Any help would be greatly appreciated.

L4 Transporter

Re: Expedition version 4 - SRX to Palo Alto migration issue

Hi,

 

Please, send us a private message to fwmigrate at paloaltonetworks dot com and we will check more in detail this case. We may need to get access to the configuration to verify where the issue in the SRX parser may be, if the problem is that the parser is not supporting your type of config.

 

We will update this thread afterwards.

L1 Bithead

Re: Expedition version 4 - SRX to Palo Alto migration issue

Hi dgildelaig,

 

I have shared the sample srx configuration file with fwmigrate at paloaltonetworks dot com. Please check and let me know if any issues with that configuration.

 

 

L4 Transporter

Re: Expedition version 4 - SRX to Palo Alto migration issue

Make sure that you do not modify the XML structure, as we have created the parsers to work with specific schemas for each vendor.

If you provide the XML subcontent (removing some of the parent XML elements) it won't comply with the SRX schema, and the parser won't be able to load the content correctly.

 

Does it make sense?

L1 Bithead

Re: Expedition version 4 - SRX to Palo Alto migration issue

Hi dgildelaig,

We have multiple configuration groups under a single Juniper SRX box (like vsys in Netscreen) which are configured for different customers. The configuration which I have shared is the sample configuration of customer1 and the configuration group name is Customer-1. The command I have used to get that configuration is 'show configuration groups Customer-1 | display xml | no-more' .  When we try to import the output of 'show configuration groups Customer-1 | display xml | no-more' in to the expedition tool import is not happening and we are getting 'Invalid XML' error message (XML is invalid. Tip:Remove attributes from configuration tag ). 

 

Even if  I try to migate the entire SRX box configuration  (show configuration | display xml | no-more)some basic componets are only getting migrated.  

 

Hope it make sense

 

L4 Transporter

Re: Expedition version 4 - SRX to Palo Alto migration issue

I checked in our email, and I could not find a config attached to any email related to SRX.

 

Could you please send it again and refer to this Forum Thread in the email? Thanks

L1 Bithead

Re: Expedition version 4 - SRX to Palo Alto migration issue

Hi dgildelaig,

 

Sent the srx config file to your email id. Please check.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!