Expedition Discussions
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Expedition Discussions

Discussions

Resolved! ML gets stuck at "Pending"

I started by running the command

scp export log traffic start-time equal 2018/07/30@00:00:00 end-time equal 2018/07/30@23:45:00 to expedition@172.30.200.117:/PALogs/mltest.csv

on my PA220. 

 

root@Expedition:/PALogs# ls -l
total 64296
-rw-rw-r-- 1 expe

...

Untitled.png
mbowling by L1 Bithead
  • 43213 Views
  • 26 replies
  • 3 Likes

If You Need an OVA...

I created an OVA for my team and put it up here (Note, this isn't the official release now offered by PANW):

https://drive.google.com/open?id=1Z9GrCF8I_BZzpbEmEh6G75npo05_4G0c

 

Be sure to go Settings > M. Learning > and change the Expedition ML Addr

...

trice by L1 Bithead
  • 67593 Views
  • 45 replies
  • 23 Likes

Resolved! How to Upload configuration files bigger than 2MB

Expedition uses APACHE as a web server and PHP as module for the scripts. By default PHP allow users to upload files with a maximum size of 2M, this can be updated by changing the PHP.ini

 

sudo vi /etc/php/7.0/apache2/php.ini go to line where this ...

alestevez by L7 Applicator
  • 28639 Views
  • 5 replies
  • 11 Likes

Dynamic NAT and Interface Dynamic NAT ASA Pre8.3

I have discovered that importing a Pre8.3 Config that has an interface dyanmic NAT (DNAT/PAT) causes the DNAT to be not an interface nat but a Translated Address NAT. I also made an earlier post on how these appear in the wrong order of operations (a

...

dega by L2 Linker
  • 2497 Views
  • 0 replies
  • 0 Likes

Expedition Updates with SSL Inspection

I ran into issues updating Expedition through my PAN Firewall running SSL decryption.

 

After a bit of troubleshooting there are two changes I needed to make on the expedition VM.

 

  1.  Update cert file with your SSL Decrypt cert - This allows apt to tr
...

Resolved! where do I check logs when merge never completes

I've got a pretty straight forward ASA to Palo migration. I followed the guide step by step. Unused objects and invalid stuff has been removed. When I click on the merge button it stays in the pending state forever. (No error message or any other fee

...

PerryK by L2 Linker
  • 8063 Views
  • 5 replies
  • 0 Likes

PALogs sub-dirs

Does Expedition actively use the following PALogs subdirs, or can I clean these out?

 

connections.parquet

sparkLocalDir

spark-warehouse

 

Basically, I am asking because I have a limited ammount of space and LOTS of logs being sent to the PALogs dir,

...

Migration from pa500 to pa820

I am planning on using the migration tool to conver the config from pa500.

 

To do this once I get the same firmware on both the boxed do I also have to import the base config from the pa820 to the migration tool?

 

I also read somewhere something ab

...

Invalid Name not functional and Odd Search Behavior

I have several invalid address objects that were migrated with a name #.#.#.#/# and i want to replace the '/' with a '-' so that the name is valid, but the replace option is not functioning. The method was to right click and select predefined filters

...

2018-09-25_13-27-01.png
2018-09-25_13-40-49.png
dega by L2 Linker
  • 3395 Views
  • 2 replies
  • 0 Likes

Two ASA pre 8.3 Problems

I have run into two ASA pre 8.3 Problems.

1) importing a deny security rule that had a destination port of 445, was changed to be all tcp ports ( that would be a small problem =D)

2) Importing routes pointed to the inside with a vpn on the outside th

...

dega by L2 Linker
  • 2311 Views
  • 0 replies
  • 0 Likes

Resolved! MaxReports is already reached

After upgrading to 1.0.105 I recieve an error that E: sub-process /usr/bin/dpkg returned an error code (1).

 

I also see the following error:

"No apport report written because MaxReports is reached already".


Any help would be appreciated.


Thanks,
Bob

bagherib by L3 Networker
  • 14617 Views
  • 3 replies
  • 0 Likes

Error during upgrade

I'm currently running 1.104 and tried the upgrde process as I always do before using Expedition.  As of yesterday I recieve the following error:

 

Any help would be appreicated.

Expedition_upgrade_error.jpg
bagherib by L3 Networker
  • 2776 Views
  • 2 replies
  • 0 Likes

Expedition Inconcistencies

I'm importing my projects in both MT3.3 and Expedition 1.0.105.

 

Q?  Why does MT3 import service objects using "_" underscore vs. Expedtion which uses "-" hyphens?

 

Q?  Why does my services use underscores in Expedtion, yet, the objects in the serv

...

bagherib by L3 Networker
  • 2923 Views
  • 2 replies
  • 0 Likes

Resolved! BPA working for some config but not for others

Hi,

 

I'm running Expedition 1.0.105 with BP rules version 3.2.0 and while the analysis in working some FW configs, I've got some other FW configs for which nothing happen. I'm, of course, able to import the config in the tool and browse it

 

but wh

...

rules.png
brrenaud by L2 Linker
  • 6380 Views
  • 4 replies
  • 0 Likes
  • 1172 Posts
  • 89 Subscriptions
Top Liked Authors
Labels