When running an ASA migration, most all of the hosts and networks are imported as address-groups due to what appears to be the way they are defined within the ASA configuration. MT3 appears to generate H- host and N- network entries to include in the groups (with the original names) -- one entry per group.
Due to the limit of groups on the Palo Alto Networks platforms, the desire is to convert these groups of 1 entry to ip-netmask address objects of the same name.
When trying to use the "Group to Address" feature, nothing appears to happen. We have tried with nothing selected, one group object selected, multiple group objects selected and matching single group and associated objected selected. Still nothing appears to happen and I have not been able to locate a log of the issue. How might we debug and correct the issue? (We want all groups of 1 entry with their auto-generated entry to be converted to an ip-netmask address object, with the address-group name which is what is used in policy whiling removing the address-group)
One troubling fact we noticed, we tried MT3.1beta4 and this "Group to Address" function seems to be missing all together. Where did it go?
Solved! Go to Solution.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!
The Live Community thanks you for your participation!