What is Expedition?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
L7 Applicator
89% helpful (15/17)

What is Expedition?

 

Expedition is the fourth evolution of the Palo Alto Networks Migration Tool. The main purpose of this tool was help reducing the time and efforts to migrate a configuration from one of the supported vendors to Palo Alto Networks.

 

By using the Migration Tool, everyone can convert a configuration from Checkpoint or Cisco or any other vendor to a PAN-OS and give you more time to improve the results. Migration Tool 3 added some functionalities to allow our customers to enforce security policies based on App-ID and User-ID as well.

 

With Expedition, we have gone one step further, not only because we want to continue helping to facilitate the transition of a security policy from others vendors to PAN-OS, but we want to ensure the outcome is the best as possible. This is why we added a Machine Learning module that can help you generate new security policies based on real log traffic and the introduction of the Best Practices Assessment Tool to check the configuration complies with the Best Practices recommended by our security experts.

 

With all these huge improvements we expect the next time you use Expedition the journey to the excellence will be easier.

 

NOTE: Expedition is supported by the community as best effort

 

The Palo Alto Networks TAC does not provide support, so please post your questions in the community.

 

Go to: Expedition landing page on LIVEcommunity

Rate this article:
(1)
Comments
L2 Linker

Does anyone know the minimum VMware Workstation version required to import the Expedition VM?  I have 10.0.7.build-2844087 and Expedition fails to start as Workstaion does not recognize the VM type.

 

Thank you,  Rich

L7 Applicator

Current version is using hardware version 12. But you can modify it to reduce it. It should work.

L2 Linker

Do you know what I would modify to ge tthis to work?

Can we convert from PIX to 8.0?

L7 Applicator
L1 Bithead

Can the tool be used for CiscoFirePOwer? or just ASA?

Thanks

L3 Networker

Just ASA for now.  I guess the assumption is that FP is new and cusotmers aren't leaving it yet.  YET.

L7 Applicator

If the Firepower config has the access-lists like this will work

 

access-list myaccesslist advaced xxxx x xx x x x

L1 Bithead

Has anyone been able to get this working with Virtualbox without first using VMWare Workstation or ESXi?  I know the "VBoxManage clondhd" command lets you convert VMDK to a VDI file but I'm not sure if that'll work with an export with multiple vmdk files.

L1 Bithead

Can Expedition help migrate rules from your Palo Alto firewalls to Panorama?

L5 Sessionator


Panorama can already adopt the configuration that a FW has. There is not need to involve Expedition in this process

L0 Member

Wasn't sure if it was posted previously....has anyone successfully installed on RHEL or Ubuntu 18.04 LTS

L0 Member

Can we migrate from Barracuda Next Gen to Palo alto? 

Any one please share me guide for the migration tool? 

 

L6 Presenter

Hi @palanisamy Barracuda is not supported at this point.  Please see below the supported vendors matrix :

 

https://live.paloaltonetworks.com/t5/expedition-articles/expedition-supported-3rd-party-vendor-matri...

 

L0 Member

Hello-

 

I reviewed this link below in which it discusses installing Expedition on Ubuntu 16.04 LTS.  Is Ubuntu required to run Expedition now or can it be installed as a ova on a Win hypervisor?

 

https://live.paloaltonetworks.com/t5/expedition-articles/new-expedition-installation-procedure/ta-p/...

 

Thanks in advance.

~sK

L6 Presenter

Hello @skhirbash 

Yes, Ubuntu 16.04 is required , please review the installation video via the below link:

 

https://youtu.be/II_6dgnPn0U

 

 

L0 Member

@lychiang .. Thank you!

L0 Member

Can the tool be used to move from SonicWall to paloalto?

 

Thanks

L6 Presenter

Hi @Kwrite17 Sonicwall is not supported at this point.  Please see below the supported vendors matrix :

 

https://live.paloaltonetworks.com/t5/expedition-articles/expedition-supported-3rd-party-vendor-matri...

 

L1 Bithead

Please share the download link. Thanks in advance

L0 Member

@lychiang Can Expedition be used to merge or replace configuration from one Palo to another?
Merging security rules and network objects between two PA-850s, for example

L6 Presenter

@john.mayer yes, you can use expedition to merge two PA configuration, but you will probably end up with a lot of duplications on all objects, and you will need to clean up before you export the config. 

L0 Member

@lychiang is this the best tool to migrate from from an older Palo Alto to a newer one (with different interfaces and amounts?)

L6 Presenter

@KellyPruett For PAN-OS migration, you should not need Expedition, you can just export the the config from old device and load then modify the interface info after load it on the new device. 

L0 Member

Thank you for the information, I'll look up more about the export/import process to new hardware.

  • 101903 Views
  • 26 comments
  • 13 Likes
Register or Sign-in
Contributors
Article Dashboard
Version history
Last Updated:
‎10-07-2019 09:02 AM
Updated by:
Retired Member