ASA to PANOS Migration

Showing results for 
Show  only  | Search instead for 
Did you mean: 
Please sign in to see details of an important advisory in our Customer Advisories area.

ASA to PANOS Migration

L1 Bithead



I am migrating an ASA config over to PANOS using the migration tool. I havent been able to figure out why the static nat rules are not migrating successfully. This is also breaking the ACL conversion as well. I am on expedition tool 1.1.33.




Community Team Member

Hi @Tarik_Admani ,


I think you'll have better luck with your question in the Expedition discussions area so I moved it here.


Good luck !


LIVEcommunity team member, CISSP
Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.

L5 Sessionator

Could you share the configuration with us (or at least a relevant snippet of the configuration) to our email (fwmigrate at paloaltonetworks dot com) to check what may be happening?

Yes sir,


I see these errors in the migraiton tool - 


Nat RuleID [89] is trying to apply a group to the translated packet. [nat (inside,outside) static x.x.x.x]. Rule not imported


I sent a scrubbed snippet to the email alias - basically this example of the nat conversion is in one of the 7 step migration videos on youtube. 



Thanks Kiwi!

Thanks for the help, to update anyone else that runs into this, I had to downgrade expedition to 1.1.28 and the nat rules and security policies migrated, going through the final review right now. 

  • 5 replies
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!