Expedition server sizing
Anyone know server sizing requirements for this? Minimum cpu, memory and storage? Also, what is the recommended way to install?
Anyone know server sizing requirements for this? Minimum cpu, memory and storage? Also, what is the recommended way to install?
I started by running the command scp export log traffic start-time equal 2018/07/30@00:00:00 end-time equal 2018/07/30@23:45:00 to expedition@172.30.200.117:/PALogs/mltest.csv on my PA220. root@Expedition:/PALogs# ls -ltotal 64296-rw-rw-r-- 1 expedition expedition 65830760 Aug 1 17:35 mltest.csvdrwxr-xr-x 2 www-data www-data 4096 Aug 1 ...
I created an OVA for my team and put it up here (Note, this isn't the official release now offered by PANW): https://drive.google.com/open?id=1Z9GrCF8I_BZzpbEmEh6G75npo05_4G0c Be sure to go Settings > M. Learning > and change the Expedition ML Address address to your VM's IP. Then return to the Dashboad and Start the Agent. [UPDATE 6.4...
Expedition uses APACHE as a web server and PHP as module for the scripts. By default PHP allow users to upload files with a maximum size of 2M, this can be updated by changing the PHP.ini sudo vi /etc/php/7.0/apache2/php.ini go to line where this variable is defined upload_max_filesize = 2M and replace by upload_max_filesize = 250M There...
I'm needing to perform an address object and service object cleanup to help reduce overall config size. I have NUMEROUS duplicates in the Panorama config and would like to consolidate them quickly via Expedition. Before I do, I need to know if the last version of Expedition before it went EOL supported Panos 11.1.x code. I already ran it thro...
I have created a project and imported the ASA show running-config into my project. However, I cannot see any security policies when I go to the POLICIES tab. I can see NAT policies but no the security policies (ASA access-list rules).Has anyone encountered this problem? Any workaround suggestions or known articles?
Panorama M600 PANOS v11.2.4-h2Firewall PA-3260 PANOS v10.1.7Expedition VM v1.2.102Let me preface this with I need the logs from Panorama (30 Days) because the local Firewall does not store that many days worth... and syslog isn't an option.If I export from Firewall, Expedition supports and processes successfully. If I export from Panorama, Exped...
Hello all, I can't import any of the Exported Named Configuration Snapshots from any of my firewalls nor any of the exports from Panorama. Create a new project. Click the Import Tab > Click Browse. Select my .XML. Expedition looks like it's importing, but nothing shows up in Expedition—no Policies, Objects, or Network. It's hard to be...
Greetings, We recently upgraded our Panorama to 9.1.4 and built a new Expedition VM with version 1.1.80. While configuring the new Expedition server I have added our Panorama and downloaded the running configuration under 'Contents'. However, when I try to download the Connected Devices under the 'Panorama Devices' tab, the process is stuck a...
I am migrating a from a CP firewall that uses asterisks as Wildcards and I need to create a Custom URL Category in order to be able to migrate the URLs over to PAN-OS. Is it possible to create Custom URL Categories in Expedition in order to allow this from a CP to PAN-OS NGFW within Expeidition?
I am using Expedition Version4. SRX JunOs configs to PanOs migration, only few interfaces, zones and one VR(logging-vr) are getting migrated. Tool doesn't detect any security groups, address books, security policies...etc. We have hundreds of security groups in one box, which are configured for different customers. All the security groups nee...
Hello, I'm working on migrating a Checkpoint Firewall running R.81 to a Palo Alto using Expedition and after a few attempts and failures I started digging deeper into the objects configured on the Checkpoint. There are multiple "Domain Objects" which start with a "." and then followed by domain. Unfortunately FQDN objects in Palo Alto do not s...
Hi, I'm migrating Cisco ASA security policies and showing some invalid services. icmp-echo icmp-traceroute Please let me know the correct services and how to replace it in service groups. Thanks, Karun
Need some help, running expedition 1.2.102. I have a standalone firewall through an acquisition that i have modified in expedition to merge into a specific device group in our panorama. Yes i know that i can just import any PA firewall into panorama but i only want specific components. Yes i know about doing a load partial but i dont want to spe...
Hi all, I was wondering if Expedition has a way (like permitted-IPs in the fw mgmt interface) to limit the GUI/CLI access from specific IPs instead of being open to all!
Hi Team, Do you have a guide on how to migrate from Forcepoint to Palo Alto using the Expedition Tool? Which are the required files and steps to action this? We have tested multiple combinations of file import and here’s the constatations : *While importing ZIP with data.zip , I could fing the policy name for the dedicated firewall , but it impo...
I see a couple discussions already posted about this, but they are from a few years ago and the solutions are not working for me. I've got Panorama imported as a device and I can see all device information from it (security policies, managed firewalls, objects, templates, etc). It appears expedition can see everything it needs to see. I at...
Hi, Is expedition can clone device group policy to new device group policy? As we want to test POC on testing firewall and don't want to alter the existing policy in production device group so we configure new device group and want to copy one-on-one policy in production device group to testing device group. Can expedition do that?
Hi, I upgraded Expedition tool to 1.2.102 and encountered a symptom I hadn't experienced before. I'm about to migrate an ASA config to a Palo Alto config, and everything seems to be going fine until generating the merged configuration. All the merged data is visible on the Expedition surface, but after generating the files, it contains only th...

