Expedition Discussions
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Expedition Discussions

Discussions

Resolved! ML gets stuck at "Pending"

I started by running the command scp export log traffic start-time equal 2018/07/30@00:00:00 end-time equal 2018/07/30@23:45:00 to expedition@172.30.200.117:/PALogs/mltest.csv on my PA220. root@Expedition:/PALogs# ls -ltotal 64296-rw-rw-r-- 1 expedition expedition 65830760 Aug 1 17:35 mltest.csvdrwxr-xr-x 2 www-data www-data 4096 Aug 1 ...

Untitled.png
mbowling by L1 Bithead
  • 46161 Views
  • 26 replies
  • 3 Likes

If You Need an OVA...

I created an OVA for my team and put it up here (Note, this isn't the official release now offered by PANW): https://drive.google.com/open?id=1Z9GrCF8I_BZzpbEmEh6G75npo05_4G0c Be sure to go Settings > M. Learning > and change the Expedition ML Address address to your VM's IP. Then return to the Dashboad and Start the Agent. [UPDATE 6.4...

trice by L1 Bithead
  • 72954 Views
  • 46 replies
  • 23 Likes

Resolved! How to Upload configuration files bigger than 2MB

Expedition uses APACHE as a web server and PHP as module for the scripts. By default PHP allow users to upload files with a maximum size of 2M, this can be updated by changing the PHP.ini sudo vi /etc/php/7.0/apache2/php.ini go to line where this variable is defined upload_max_filesize = 2M and replace by upload_max_filesize = 250M There...

alestevez by L7 Applicator
  • 30111 Views
  • 5 replies
  • 11 Likes

Invisible 'merged' tag on export

When I am importing the XML from Expedition it has started to give me errors due to a tag that is present on merged objects. The tag is 'merged' and you can see it in Panorama in the tag column but when you open the object nothing is in that field. Determined that all I have to do is open the open and save it but this is a real pain with the num...

aporue by L3 Networker
  • 2735 Views
  • 1 replies
  • 0 Likes

CSV import: format of NAT policy?

I am migrating from a Clavister firewall. Configuration is in XML format, which I am converting to CSV. Everything but NAT works OK, but I have not been able to find a description of how to format the fields for TP to get the desired result. Can anyone enlighten me on how the parser interprets those fields? Most pressing right now is how ...

update servers required by expedition apt-get

What servers or their URLs are required by expedition apt-get. We've whitelisted *.paloaltonetworks.com. We're asking because we se following: Install these packages without verification? [y/N] y Get:1 https://conversionupdates.paloaltonetworks.com expedition-updates/ expedition-beta 1.1.17 [40.7 MB] Fetched 40.7 MB in 5s (7,139 kB/s) ...

Screen Shot 2019-05-07 at 08.33.56.jpg
Laimonas by L2 Linker
  • 6101 Views
  • 4 replies
  • 0 Likes

load config partial mode append issue

I am trying to do a ‘load config partial mode append’ to get the policy exported from Expedition into a device-group that already has policy/nat rules (those rules are from a previous Expedition project, and we are trying to combine 2 ASA contexts into 1 PA firewall). Normally I do a ‘merge’ instead of an ‘append,’ but the rules/nat’s are mergin...

aporue by L3 Networker
  • 3083 Views
  • 1 replies
  • 0 Likes

Rule merge all results

I am running Expedition 1.0.106 and have a question about merging rules. Once the analysis is done I am presented with cases that I look at individually. From there I can merge by highlighting the rules or by clicking on the 'merge by selection or all results'. Either one of those ways works to merge a case. The question I have is the part that...

aporue by L3 Networker
  • 19203 Views
  • 34 replies
  • 0 Likes

Import Interface Issue

I have a weird issue when I import the XLM into the firewalls and wanted to see if anyone has any thoughts on it. I am importing the interface configurations from Cisco ASA's into templates in Panorama that were migration in Expedition. The import into the template and the commit to Panorama works just fine but when I push to the firewall I keep...

CommitError.PNG
aporue by L3 Networker
  • 4463 Views
  • 4 replies
  • 0 Likes

load config partial mode append issue

I am trying to combine 2 ASA contexts into a single PA config. Used Expedition to do the migration separately for each context and everything but the rules worked as expected. Normally I use 'load config partial mode merge' which also worked in this case for everything but rules. Not sure what the trigger is to merge rules but it did indeed merg...

aporue by L3 Networker
  • 2369 Views
  • 0 replies
  • 0 Likes

Invalid FQDN Object on import

When importing panorama we have two fqdn address objects that are detected as invalid: EXT-SaS-Monitoring_02ws.centrastage.net fqdn 02ws.centrastage.net EXT-SaS-Monitoring_02cc.centrastage.net fqdn 02cc.centrastage.net All objects with a number as the first character of the fqdn are detected as "invalid" objects. Unable to use auto update fe...

Tags mapping not preserved on address import using CSV

Hi! I'm running Expedition 1.1.18, and using CSV import to get data from a Clavister FW. CSV was generated by a python script I wrote. The CSV I'm generating has data for the 'tag' field, but on import it looks like the mapping is lost. The tags are created! But they are no longer applied to the objects (addresses) from which they were l...

Resolved! Converting XML from firewall to Panorama template

Hi, I assume this question has been previously discussed, however I wasn't able to find a thread that describes the process. I am looking to import an .xml file from a palo alto firewall and use expedition to convert the config into a device group and template within panorama. Can someone share the steps needed to acheive this?

Resolved! Can we export certain objects via a XML file

Hello ! On MT we can export our objects (addresses, groups, policies, etc.) to excel. So I was wondering : can we do the same but instead of an excel file we export the objects in a XML file ? For now the only two ways to export something in a XML file is when you export the base configuration or the whole project (at least that's what I've ...

OverPass by L0 Member
  • 5993 Views
  • 2 replies
  • 0 Likes

Failed to parse security policy

Dears I'm migrating from Cisco ASA to paloalto 3220, I migrated all configuration successfully but I faced the following error Detailsvsys1Error: Number of security rules (8721) exceeds vsys capacity (2500)Error: Failed to parse security policy(Module: device)Commit failed however, PA-3220 support 10,000 policy I have only 8721, what is th...

  • 1185 Posts
  • 89 Subscriptions
Labels