Expedition Discussions
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Expedition Discussions

Discussions

Resolved! ML gets stuck at "Pending"

I started by running the command scp export log traffic start-time equal 2018/07/30@00:00:00 end-time equal 2018/07/30@23:45:00 to expedition@172.30.200.117:/PALogs/mltest.csv on my PA220. root@Expedition:/PALogs# ls -ltotal 64296-rw-rw-r-- 1 expedition expedition 65830760 Aug 1 17:35 mltest.csvdrwxr-xr-x 2 www-data www-data 4096 Aug 1 ...

Untitled.png
mbowling by L1 Bithead
  • 46476 Views
  • 26 replies
  • 3 Likes

If You Need an OVA...

I created an OVA for my team and put it up here (Note, this isn't the official release now offered by PANW): https://drive.google.com/open?id=1Z9GrCF8I_BZzpbEmEh6G75npo05_4G0c Be sure to go Settings > M. Learning > and change the Expedition ML Address address to your VM's IP. Then return to the Dashboad and Start the Agent. [UPDATE 6.4...

trice by L1 Bithead
  • 73578 Views
  • 46 replies
  • 23 Likes

Resolved! How to Upload configuration files bigger than 2MB

Expedition uses APACHE as a web server and PHP as module for the scripts. By default PHP allow users to upload files with a maximum size of 2M, this can be updated by changing the PHP.ini sudo vi /etc/php/7.0/apache2/php.ini go to line where this variable is defined upload_max_filesize = 2M and replace by upload_max_filesize = 250M There...

alestevez by L7 Applicator
  • 30215 Views
  • 5 replies
  • 11 Likes

Resolved! 'Incorrect user or password' when logging in. PHP 'Connection refused'

I appear to have a php connection issue to my database on my Expedition instance. When trying to upgrade Expedition to the latest version I get the following error. Preparing to unpack .../expedition-beta_1.1.70_amd64.deb ... Unpacking expedition-beta (1.1.70) over (1.1.70) ... Setting up expedition-beta (1.1.70) ... PHP Warning: mysqli::__...

BOkay by L2 Linker
  • 23028 Views
  • 8 replies
  • 0 Likes

LACP Disabled

Has anyone comes across an issue where LACP is disabled on aggregate interfaces after configuration merge? LACP was enabled on Palo Alto base config and after config was merged with Check Point config LACP was off.

jb2020 by L0 Member
  • 2677 Views
  • 1 replies
  • 0 Likes

Expedition support for PanOS9.1.1

Dears, We've needed to upgrade our Panorama & firewalls for bug fixing reasons to PanOs9.1.1. Since the Panorama upgrade our migrations using Expedition are having issues: PanOS9.1.1 with Expedition: Expedition pre 1.1.56: after a merge and config import, following is the config load error on Panorama: "job failed because ...

Resolved! What is the difference between the generated merged xml and the pretty.xml?

After merging a config in Expedition, when you generate the XML you get two files: projectname.xml and projectname.zip. The ZIP contains a text doc with the set commands as well as the same projectname.xml and a larger projectname-pretty.xml. What is the difference between the two xml files? To further elaborate, here is a sanitized example:...

Migration Tool - Error generating the api key

Hi Guys, I tried to add Panorama or Physcial PAN in the migraiotn tool for log connector but keep getting error "Error generating the api key". I dobule confirm the IP and login crediential are correct when I fill in but not sure what else I would check.

EricWen by L0 Member
  • 2426 Views
  • 1 replies
  • 0 Likes

Resolved! Need Help with Expedition

We are having difficulties logging into the web portal of Expedition – after entering credential and password, the browser just sits there showing “suthenticating … please wait” when I use Firefox. I could not even use Chrome or any other browsers to access Expedition web portal – I am getting ERR_SSL_KEY_USAGE_INCOMPATIBLE error message. Any su...

sd44 by L1 Bithead
  • 5652 Views
  • 5 replies
  • 0 Likes

Troubleshoot "Configuration is invalid" after Expedition export

We are migrating multiple Cisco ASA pairs into PA-3260. PANOS 9.0.7, Expedition 1.1.69.3. Initially we are testing using a single ASA at a time. At least one of the "simpler" ASAs seems to migrate cleanly. Our "main" ASA is more complex. After working to clean duplicates and etc, we are able to get to the point where the Commit Check does not...

image001.png

Migrate Security Rules in multiple device groups with Expedition

Hello, I have a policy rule imported from a Juniper with one Vsys. I'd like to split the rules and migrate them in different Device Group (Multiple VSYS) in a Panorama It seems that Expedition only give the possibilty to export the rules in one Device group in the Mapping tab. So if rules belong to multiple device, the only solution i ve found...

expedition pre-define http mismatch actual firewall

We had migration activity that causing the outage. After review the technical detail. we notice when merge service object, TCP-80 over write service-http. the actual firewall service-http use port 80 and 8080. Expedition pre-define as 80 only, that causing the problem. One more thing, when show running security policy and nat policy, palo al...

ZHOUJO5 by L2 Linker
  • 2914 Views
  • 1 replies
  • 0 Likes

Merging of security policies result in sequence gotten out of order

Hi all, I've got 2 different sets of PAN xml files, both contained firewall policies are almost identical, except 1 of them contains additional rules. I've imported both into Expedition and merge both configs together, such that the security policies would contained the set of policies from FW1 above, and the set of policies from FW 2 below. ...

chtoh82 by L2 Linker
  • 9519 Views
  • 2 replies
  • 0 Likes

Cisco FTD 6.2.x to PAN Migration

When trying to import a file from a Cisco ASA 5525-X running FTD 6.2.0.2 we only get the vpn tunnel and nat rules. The security rulebase does not show up in the import. Is there a work around to get the whole rulebase imported?

Resolved! Expedition unable to process security rule for Rule Enrichment

Hi guys, I'm working with a customer who has Expedition installed on their network on Ubuntu 16.04. Expedition is on the latest version (1.1.68). I've setup a traffic log forwarder from one of their firewalls which connects to their Expedition just fine. I've added their Panorama device, pulled in the managed devices and running config. I've pro...

after address group convert to share, global search show invalid member

when we do panorama migration, before convert address group to share after convert address group to share, you can see firewall no longer shows address group name, and click member not able to locate specific address group. it happen to all other objects as well. just wondering if we can confirm this is some format syntax issue between expedit...

1.JPG
2.JPG
ZHOUJO5 by L2 Linker
  • 2682 Views
  • 1 replies
  • 0 Likes

Expedition Device Import

Hello, I have a PA-3020 device that I would like to use Expedition to help me Audit and Evaluate. I can't give Expedition direct access to the FW, so I've been trying to import XML files. I can't seem to get a full import of everything on the firewall. I found this posting, but it didn't have a resolution: https://live.paloaltonetworks.com/...

  • 1187 Posts
  • 89 Subscriptions
Labels