Expedition Discussions
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Expedition Discussions


Resolved! ML gets stuck at "Pending"

I started by running the command

scp export log traffic start-time equal 2018/07/30@00:00:00 end-time equal 2018/07/30@23:45:00 to expedition@

on my PA220. 


root@Expedition:/PALogs# ls -l
total 64296
-rw-rw-r-- 1 expe


mbowling by L1 Bithead
  • 26 replies

If You Need an OVA...

I created an OVA for my team and put it up here (Note, this isn't the official release now offered by PANW):



Be sure to go Settings > M. Learning > and change the Expedition ML Addr


trice by L1 Bithead
  • 44 replies

Resolved! How to Upload configuration files bigger than 2MB

Expedition uses APACHE as a web server and PHP as module for the scripts. By default PHP allow users to upload files with a maximum size of 2M, this can be updated by changing the PHP.ini


sudo vi /etc/php/7.0/apache2/php.ini go to line where this ...

alestevez by L7 Applicator
  • 5 replies

Resolved! Panorama configuration device log

I managing all firewalls in panorama, with all rules in devicegroups and none local rules. Is it possible to use panorama configuration in expedition but forwarding logs from the firewalls ? That way I save disk space on the expedition server by only


Checkpoint R77.30 to Paloalto migration


I would like to migrate a couple of Checkpoint Firewalls to Paloalto but I’m not sure what’s the best approach to proceed with this migration. Also, Checkpoint has all blades ON with full configuration. Does Expedition migration tool able to migr


Resolved! Migrate Checkpoint 80.10


I try a migration from checkpoint 8R0.10.

I've updated to the last bersion (1.1.12) and I see option "VERSION 80.10" in the checkpoint tab, but this option is grayed out.

I try with R80 option but It does nothing after "upload" is clicked.




Basic Workflow Questions

Migrating four Checkpoint clusters into single Panorama/HA firewall pair. My initial thought was to tackle each Checkpoint cluster as it's own project (good/bad idea? not sure how projects fit into overall workflow). Running if it matters.



Cisco ASA 5506 > PA-220 migration

Hi everyone.

I want to migrate one Cisco ASA 5506 Firewall to a new PA-220 Firewall. I have looked at the "Expedition" tool that PaloAlto provider, but I can't really wrap my head around how it works.
I have access to the complete config file from the


Auto Zone assignment & template

Hello dear community


I'm currently migrating an ASA configuration to Palo VM, and after importing config files expedition has correctly calculated the from and to zones on my ruleset 

However, after adapting some IP address of my ethernet interface



Issues Merging security policies



I'm trying to migrate from Cisco ASA to Palo Alto and I'm using current xml file from our live Panorama server.

When I exported the xml I made sure to only select the device-group for the firewall I will be migrating to. 


I imported bot


Top Solution Authors
Top Liked Authors