Security Profiles not showing up in Expedition

L1 Bithead

Security Profiles not showing up in Expedition

Hello,

I currently push my security profiles from Panorama to devices, When adding the device to expedition I do not see the security profiles show up in Expedition. Would someone be able to explain why and also let me know how I can pull them into Expedtion?

L4 Transporter

Re: Security Profiles not showing up in Expedition

All configurations pushed from Panorama will not be seen in the firewall's local running-config configuration file. this is expected. 

 

if you want to see the security profiles (pushed from Panorama) you will need to import the Panorama configuration.

L1 Bithead

Re: Security Profiles not showing up in Expedition

I had to build the profiles from the Panorama config using the xml code from the profiles then import into my project. Is there a better way of doing this? 

L1 Bithead

Re: Security Profiles not showing up in Expedition

We are seeing the same issue, it would help out a lot if we could more easily pull those profiles into Expedition from Panorama.

https://live.paloaltonetworks.com/t5/Expedition-Discussions/Migrating-of-Local-Rules-that-use-Panora...

 

L4 Transporter

Re: Security Profiles not showing up in Expedition

Saul / Chad

 

Have you tried importing your Panorama config into your project? Then you can merge your recently migrated config into the appropriate device-group in Panorama within Expedition. 

 

Once your new config is merged into Panorama you will then have access to the security profiles and groups that can be applied to the recently mgirated security policies. 

 

Once you've finalized the merge and config of your policies you can then incrementally load only the edited or new device-group and any shared objects into Panorama.

 

I will write a workflow document for this process this week and publish on the live site. 

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!