Expedition Discussions
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Expedition Discussions

Discussions

Resolved! ML gets stuck at "Pending"

I started by running the command scp export log traffic start-time equal 2018/07/30@00:00:00 end-time equal 2018/07/30@23:45:00 to expedition@172.30.200.117:/PALogs/mltest.csv on my PA220. root@Expedition:/PALogs# ls -ltotal 64296-rw-rw-r-- 1 expedition expedition 65830760 Aug 1 17:35 mltest.csvdrwxr-xr-x 2 www-data www-data 4096 Aug 1 ...

Untitled.png
mbowling by L1 Bithead
  • 46163 Views
  • 26 replies
  • 3 Likes

If You Need an OVA...

I created an OVA for my team and put it up here (Note, this isn't the official release now offered by PANW): https://drive.google.com/open?id=1Z9GrCF8I_BZzpbEmEh6G75npo05_4G0c Be sure to go Settings > M. Learning > and change the Expedition ML Address address to your VM's IP. Then return to the Dashboad and Start the Agent. [UPDATE 6.4...

trice by L1 Bithead
  • 72954 Views
  • 46 replies
  • 23 Likes

Resolved! How to Upload configuration files bigger than 2MB

Expedition uses APACHE as a web server and PHP as module for the scripts. By default PHP allow users to upload files with a maximum size of 2M, this can be updated by changing the PHP.ini sudo vi /etc/php/7.0/apache2/php.ini go to line where this variable is defined upload_max_filesize = 2M and replace by upload_max_filesize = 250M There...

alestevez by L7 Applicator
  • 30114 Views
  • 5 replies
  • 11 Likes

Expedition support for PanOS9.1.1

Dears, We've needed to upgrade our Panorama & firewalls for bug fixing reasons to PanOs9.1.1. Since the Panorama upgrade our migrations using Expedition are having issues: PanOS9.1.1 with Expedition: Expedition pre 1.1.56: after a merge and config import, following is the config load error on Panorama: "job failed because ...

Resolved! What is the difference between the generated merged xml and the pretty.xml?

After merging a config in Expedition, when you generate the XML you get two files: projectname.xml and projectname.zip. The ZIP contains a text doc with the set commands as well as the same projectname.xml and a larger projectname-pretty.xml. What is the difference between the two xml files? To further elaborate, here is a sanitized example:...

Migration Tool - Error generating the api key

Hi Guys, I tried to add Panorama or Physcial PAN in the migraiotn tool for log connector but keep getting error "Error generating the api key". I dobule confirm the IP and login crediential are correct when I fill in but not sure what else I would check.

EricWen by L0 Member
  • 2408 Views
  • 1 replies
  • 0 Likes

Resolved! Need Help with Expedition

We are having difficulties logging into the web portal of Expedition – after entering credential and password, the browser just sits there showing “suthenticating … please wait” when I use Firefox. I could not even use Chrome or any other browsers to access Expedition web portal – I am getting ERR_SSL_KEY_USAGE_INCOMPATIBLE error message. Any su...

sd44 by L1 Bithead
  • 5609 Views
  • 5 replies
  • 0 Likes

Troubleshoot "Configuration is invalid" after Expedition export

We are migrating multiple Cisco ASA pairs into PA-3260. PANOS 9.0.7, Expedition 1.1.69.3. Initially we are testing using a single ASA at a time. At least one of the "simpler" ASAs seems to migrate cleanly. Our "main" ASA is more complex. After working to clean duplicates and etc, we are able to get to the point where the Commit Check does not...

image001.png

Migrate Security Rules in multiple device groups with Expedition

Hello, I have a policy rule imported from a Juniper with one Vsys. I'd like to split the rules and migrate them in different Device Group (Multiple VSYS) in a Panorama It seems that Expedition only give the possibilty to export the rules in one Device group in the Mapping tab. So if rules belong to multiple device, the only solution i ve found...

expedition pre-define http mismatch actual firewall

We had migration activity that causing the outage. After review the technical detail. we notice when merge service object, TCP-80 over write service-http. the actual firewall service-http use port 80 and 8080. Expedition pre-define as 80 only, that causing the problem. One more thing, when show running security policy and nat policy, palo al...

ZHOUJO5 by L2 Linker
  • 2891 Views
  • 1 replies
  • 0 Likes

Merging of security policies result in sequence gotten out of order

Hi all, I've got 2 different sets of PAN xml files, both contained firewall policies are almost identical, except 1 of them contains additional rules. I've imported both into Expedition and merge both configs together, such that the security policies would contained the set of policies from FW1 above, and the set of policies from FW 2 below. ...

chtoh82 by L2 Linker
  • 9491 Views
  • 2 replies
  • 0 Likes

Cisco FTD 6.2.x to PAN Migration

When trying to import a file from a Cisco ASA 5525-X running FTD 6.2.0.2 we only get the vpn tunnel and nat rules. The security rulebase does not show up in the import. Is there a work around to get the whole rulebase imported?

Resolved! Expedition unable to process security rule for Rule Enrichment

Hi guys, I'm working with a customer who has Expedition installed on their network on Ubuntu 16.04. Expedition is on the latest version (1.1.68). I've setup a traffic log forwarder from one of their firewalls which connects to their Expedition just fine. I've added their Panorama device, pulled in the managed devices and running config. I've pro...

after address group convert to share, global search show invalid member

when we do panorama migration, before convert address group to share after convert address group to share, you can see firewall no longer shows address group name, and click member not able to locate specific address group. it happen to all other objects as well. just wondering if we can confirm this is some format syntax issue between expedit...

1.JPG
2.JPG
ZHOUJO5 by L2 Linker
  • 2671 Views
  • 1 replies
  • 0 Likes

Expedition Device Import

Hello, I have a PA-3020 device that I would like to use Expedition to help me Audit and Evaluate. I can't give Expedition direct access to the FW, so I've been trying to import XML files. I can't seem to get a full import of everything on the firewall. I found this posting, but it didn't have a resolution: https://live.paloaltonetworks.com/...

Resolved! Check Point Application Control Policy Conversion

I have a client running Check Point R77 who wishes to migrate their Application Control policy. Does Expedition support conversion of a non-unified Check Point App Control policy? The policy is defined in a separate layer (non-unified policy), unified policy was introduced in R80. @aestevez ?

mb_equate by L3 Networker
  • 3220 Views
  • 1 replies
  • 0 Likes

Migrating from ASA 8.2 makes double objects and rules

I'm migrating configuration from ASA version 8.2 and I noticed that quite a lot of objects are doubled and also some rules are doubled. If I look at doubled objects 1 of them has 'default' under 'src File' coloumn and the other has config file name in that coloumn (filename matching the one i imported). I only imported this named config file....

santonic by L6 Presenter
  • 5782 Views
  • 5 replies
  • 0 Likes
  • 1185 Posts
  • 89 Subscriptions
Labels