Expedition server sizing
Anyone know server sizing requirements for this? Minimum cpu, memory and storage? Also, what is the recommended way to install?
Anyone know server sizing requirements for this? Minimum cpu, memory and storage? Also, what is the recommended way to install?
I started by running the command scp export log traffic start-time equal 2018/07/30@00:00:00 end-time equal 2018/07/30@23:45:00 to expedition@172.30.200.117:/PALogs/mltest.csv on my PA220. root@Expedition:/PALogs# ls -ltotal 64296-rw-rw-r-- 1 expedition expedition 65830760 Aug 1 17:35 mltest.csvdrwxr-xr-x 2 www-data www-data 4096 Aug 1 ...
I created an OVA for my team and put it up here (Note, this isn't the official release now offered by PANW): https://drive.google.com/open?id=1Z9GrCF8I_BZzpbEmEh6G75npo05_4G0c Be sure to go Settings > M. Learning > and change the Expedition ML Address address to your VM's IP. Then return to the Dashboad and Start the Agent. [UPDATE 6.4...
Expedition uses APACHE as a web server and PHP as module for the scripts. By default PHP allow users to upload files with a maximum size of 2M, this can be updated by changing the PHP.ini sudo vi /etc/php/7.0/apache2/php.ini go to line where this variable is defined upload_max_filesize = 2M and replace by upload_max_filesize = 250M There...
Hello, does using the expedition tool require having a palo alto device or can i just export the config as a file and install it on the device later ?
When I edit my IPSec VPN IKE gateways I cannot see any IKEv2 column on the page and I cannot add one. When looking at the IKE gateway configuration I can see IKE2 settings and my correct settings are there. When I export the configuration and import into Panorama all of the IPSec tunnels are missing. I can see the IPSec configurations in the exp...
4x brand new VM and expedition installations. Configured RADIUS via GUI, configured user with external auth. Any attempts to log in with external auth result with an error "Failed: Incorrect user or password." Attempts to test connection with RADIUS server return an error as well: "Server Connection Testing: Error: No reply received from the s...
Hi, I am trying to use Expedition to look at current PAN configs. But I am getting randomly automatically logged out within 5 minutes. There's so warning, no error that I can see, it just logs me out. Can someone point me in a troubleshooting direction or share experience they may have to correct? Thanks.
Hi, I tried to migrate a configuration SRX to Palo Alto when I export the configuration all objects and interfaces stay in pending and I can't download the Palo Alto configuration. With multiple configurations of SRX same problem. I tested to do a fresh install of Expedition (1.2.79) same things, I don't have any invalid objects or rules."Jo...
Hello, I am working on a migration where the source ASA has 74 VPN L2L tunnels (to remote stores using same config) and the migration tool has created individual ACLs and Zones for each. This makes managing them tedious and would prefer to have a single zone named VPN STORES and all tunnel interfaces within that zone and one ACL. Is there a me...
We got our Fortigate done. Thanks for the help with that. Now we are having issues with expedition not importing a Juniper firewall configuration properly. We import the configuration XML file from Juniper into the project, and we can see service group objects, but no address objects, rules or NAT rules. The juniper is running 21.3R0 code.
I am working on a project where the source ASA has port-channels and sub-interfaces within the configuration. The file imports and almost everything shows BUT the interfaces. How do I create and map to the new platform if they are not recognized?
I am running Expedition version 1.2.78. Currently, I have a PA820 up and running in production. This PA820 is managed by Panorama. I also have an ASA that I want to migrate to PA820. I am very new to Expedition so I am asking for step-by step instructions on how to: -Convert ASA objects and policies, export to xml files and then import them ...
Hello team. I follow the steps to Install Expedition in a VM like the Guide that the official web pages says. But when I try to acces by GUI WEB browsing, I get the message that not is posiblle to reach, the server refused the connection. I check and I see the port 80 and 443 are not in LISTEN. Could you help me with this? The informat...
I just setup the expedition VM in my VMware. Its VM is remotely accessible over SSH. However, the VM is not accessible through Web GUI (Expedition) Please advise, how to troubleshoot and fix the issue. Distributor ID: UbuntuDescription: Ubuntu 20.04.6 LTSRelease: 20.04 Network INFO expedition@expedition:~$ ip a1: lo: <LOOPBACK,UP,LOWER_...
Verify the PanOrders agent is running to accept background jobs PanOrders Agent is stoppedRemediation: Start the agent
Hello, when are logical routers supported in the Palo Alto Expedition? What is the best pratice migration at this moment? We have PA-5410 with software 10.2.3 and advanced routing enabled. Would it be better to turn off advanced routing, do the configuration migration and then turn advanced routing on again? I know logical routers are new an...
Hi everyone, We wants to forward Expedition's logs like login/logout or audit log to their syslog server like Splunk or smt. I couldn't see any syslog option on admin or user guide, also in UI either. Is there any way to send these logs? BR
I use Expedition often for optimising existing PAN deployments. I'm currently using it to re-map interfaces for some new hardware, moving from physical interfaces to a LACP trunk. Problem is the exported config is missing the zone for a loopback interface. This interface is used for GlobalProtect, and the config fails to commit until the zone ...

