Expedition Discussions
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Expedition Discussions

Discussions

Resolved! ML gets stuck at "Pending"

I started by running the command scp export log traffic start-time equal 2018/07/30@00:00:00 end-time equal 2018/07/30@23:45:00 to expedition@172.30.200.117:/PALogs/mltest.csv on my PA220. root@Expedition:/PALogs# ls -ltotal 64296-rw-rw-r-- 1 expedition expedition 65830760 Aug 1 17:35 mltest.csvdrwxr-xr-x 2 www-data www-data 4096 Aug 1 ...

Untitled.png
mbowling by L1 Bithead
  • 46161 Views
  • 26 replies
  • 3 Likes

If You Need an OVA...

I created an OVA for my team and put it up here (Note, this isn't the official release now offered by PANW): https://drive.google.com/open?id=1Z9GrCF8I_BZzpbEmEh6G75npo05_4G0c Be sure to go Settings > M. Learning > and change the Expedition ML Address address to your VM's IP. Then return to the Dashboad and Start the Agent. [UPDATE 6.4...

trice by L1 Bithead
  • 72954 Views
  • 46 replies
  • 23 Likes

Resolved! How to Upload configuration files bigger than 2MB

Expedition uses APACHE as a web server and PHP as module for the scripts. By default PHP allow users to upload files with a maximum size of 2M, this can be updated by changing the PHP.ini sudo vi /etc/php/7.0/apache2/php.ini go to line where this variable is defined upload_max_filesize = 2M and replace by upload_max_filesize = 250M There...

alestevez by L7 Applicator
  • 30111 Views
  • 5 replies
  • 11 Likes

Where's the source code?

The open-source Expedition tool speeds your migration to next-generation firewall technologies and more efficient processes, enabling you to keep pace with emerging security threats and industry best practices. https://www.paloaltonetworks.com/products/secure-the-network/next-generation-firewall/migration-tool We're in the CSL and I'd like to ...

Expedition can't process any csv

I've tried manually importing and using scp. I see the file. I see it's a supported panos version and still get an error for no files to process. drwxr-----+ 2 www-data www-data 4096 Aug 30 19:15 data -rwxr----- 1 www-data www-data 8118829895 Aug 30 19:25 xxxxxxx.csv

Running out of drive space

Recently I have started running out of space in Expedition. I am in the process of requesting more space for the VM but this issue is something that has just started. I have 1 large project that is eating up 12GB of space by itself. There are a ton of rule merges that are happening and I can only do 10 at a time, so every time that happens a new...

aporue by L3 Networker
  • 3316 Views
  • 2 replies
  • 0 Likes

PPPoE on a VLAN tagged sub-interface

Hi, I would like to request a feature, whereby you can configure PPPoE on a VLAN tagged sub-interface. I used to do this on cisco ASA's but since I started to deploy PA's I can only configure pppoe on physical interfaces. This is quite a common configuration for most engineer and would greatful if the feature was to become available. Many th...

Eros02 by L0 Member
  • 3404 Views
  • 1 replies
  • 1 Likes

Work on a specific device group from Panorama Configuration.

We are exploring to use the expedition tool to analyze and implement best practices on our current Panorama/firewall configurations. Our firewall configurations are mosty templates that came from Panorama, so all the configuration are in Panorama. I noticed that I had to use Panorama xml to view all device-group configurations instead of using s...

Anyone have issues with SSH keys after install?

Running in AWS, I moved the initsetup.sh script to /tmp and ran it. Expedition came up working. However, I went back in to remediate a mariadb setting that was showing on the home page and I was no longer able to use my key pair and the "ubuntu" user that comes stock with AWS. Has anyone run into this issue?

Expedition Issues

I'm sorry to complain, but there are a number of issues i've found with this software. I've allocated ample resources to the VM. 1. The UI is really laggy, unresponsive, and the filter window often doesn't rspond to being closed. 2. It is not auto processing CSV files and deleting them as it is configured. 3. The API generation creates inval...

Resolved! Expedition - No supported files to process

Hi all,I have the issue that imported logs from firewall on 8.1.X release can't be processed in Expedition.I already changed the permissions of PALogs to anything possible. Also chmod 777 PALogs/. Files are imported correctly but can't be processed at this point. Any ideas what to try next? BRtisc

Screenshot 2019-03-01 at 10.27.21.png
tisc by L1 Bithead
  • 8037 Views
  • 4 replies
  • 0 Likes

Resolved! No supported files to process

Hi all, I sucessfully exported the logs from my PA200 (currently on release 7.1.16) via SCP to the PALogs folder. Expedition can find the files but when I do the "Process Files" I get the dreaded "No supported files to process". Can I get an hint on what am I doing wrong here?

expedition_error.jpg

[CHECKPOINT R80][EXPEDITION 1.1.32] Address group bad Import

Hello all, I successfully manage to import Checkpoint R80 config into Expedition but Address groups are missing. They are all imported as "Host" with their UID as "Name" and with "1.1.1.1" as IP Address. Does anyone have experienced this issue ? Is their a way to get the address groups managed properly ? Thank you in advance for your help.

Sydrou by L1 Bithead
  • 2712 Views
  • 1 replies
  • 0 Likes

Expedition Generate XML & SET Output hung at 'Loading Response-pages :: vsys : shared'

Hi, I am currently running Expedition 1.1.35 and am trying to migrate a locally managed firewall to Panorama using templates. After merging the configurations, the Generate XML & SET Output gets hung at 'Loading Response-pages :: vsys : shared'. I have deleted and recreated the project, as well as removing and readding the devices within the...

EXPEDITION_ERROR.gif

Migrating FortiGate 5.x to PA IPSec Tunnels

I have a Expedition Sever version 1.1.35 to migrate a FortiGate configuration to PA. So when I import the backup file, all IPSec Tunnels are grouped in a "Tunnel Media", but all tunnels are named same like the Physical Port Number and the Original name of tunnel is lost. Is this a bug or the normal behavior of the Expedition tool.

tunnel_interfaces.png

ASA to PANOS Migration

Hi, I am migrating an ASA config over to PANOS using the migration tool. I havent been able to figure out why the static nat rules are not migrating successfully. This is also breaking the ACL conversion as well. I am on expedition tool 1.1.33. thanks

  • 1185 Posts
  • 89 Subscriptions
Labels