Expedition Discussions
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Expedition Discussions

Discussions

Resolved! ML gets stuck at "Pending"

I started by running the command scp export log traffic start-time equal 2018/07/30@00:00:00 end-time equal 2018/07/30@23:45:00 to expedition@172.30.200.117:/PALogs/mltest.csv on my PA220. root@Expedition:/PALogs# ls -ltotal 64296-rw-rw-r-- 1 expedition expedition 65830760 Aug 1 17:35 mltest.csvdrwxr-xr-x 2 www-data www-data 4096 Aug 1 ...

Untitled.png
mbowling by L1 Bithead
  • 46185 Views
  • 26 replies
  • 3 Likes

If You Need an OVA...

I created an OVA for my team and put it up here (Note, this isn't the official release now offered by PANW): https://drive.google.com/open?id=1Z9GrCF8I_BZzpbEmEh6G75npo05_4G0c Be sure to go Settings > M. Learning > and change the Expedition ML Address address to your VM's IP. Then return to the Dashboad and Start the Agent. [UPDATE 6.4...

trice by L1 Bithead
  • 73072 Views
  • 46 replies
  • 23 Likes

Resolved! How to Upload configuration files bigger than 2MB

Expedition uses APACHE as a web server and PHP as module for the scripts. By default PHP allow users to upload files with a maximum size of 2M, this can be updated by changing the PHP.ini sudo vi /etc/php/7.0/apache2/php.ini go to line where this variable is defined upload_max_filesize = 2M and replace by upload_max_filesize = 250M There...

alestevez by L7 Applicator
  • 30134 Views
  • 5 replies
  • 11 Likes

Expedition for Cisco ACLs

How is the tool at migrating ACLs ? A lot of those practices are not in line with newer security policies and next generation principles. Is it useful to migrate the ACLs or start from scratch ?

Cisco ASA VPN Filters

I am running the Expedition Tool on our Cisco ASA firewalls and the tools is stating that most of our IP Address, IP Address Groups and Services are invalid. When I go over these invalid objects, they are all part of our VPN filters on our VPN tunnels. Is there anyway for the Tool to recognize that these are ACLs rules in the ASA and that they...

jrtuck by L2 Linker
  • 8016 Views
  • 7 replies
  • 0 Likes

Only Changes API push?

I'm probably missing it, but where is the option to push "only changes" through the API. I know the MT had it, but can't seem to find it on expedition.

Sec101 by L4 Transporter
  • 6375 Views
  • 4 replies
  • 1 Likes

Resolved! How to Upgrade?

Can someone please provide the steps to update Expedition? I'm currentl using 1.0.84, and I know that there are more recent versions. However I see no way from the UI to install updates and apt-get doesn't work because it says the repo is insecure. Thanks!

Resolved! Unused FQDN Objects

Hey Team! I'm looking into Expedition for possibly using it to find unused FQDN Objects on our Firewalls that are in rules. We hit our quota almost every quarter which creates havoc and maintenance time, less work on the fun stuff here.I would love to know if this tool could be used for finding Unused FQDN objects in and out of rules. Thanks

Jmarx1 by L1 Bithead
  • 4978 Views
  • 1 replies
  • 0 Likes

Resolved! Spyware Snippet

Hello, Apparently there is no option to import a spyware profile snippet into my project. On the snippet tabs when I try to add one the type field doesn't contain a spyware option. I tried manually typing:spyware, spayware profiles,etc.... But when I try to import the snippet into my project it doesn't show up under objects>contents>spyw...

Trouble doing ML on security policy from panorama?

Can you use the ML and rule enhancements on security policy that is located in panorama. Im struggling a bit to get it to work. I set my project up to use panorama and then brought in the firewalls. There is not a schedule log export function to panorama to csv so I am exporting from firewall. I tried fwd syslog but the tool did not recogniz...

firewallconn.png
firewalloutput.png
panoramaOutput.png
panoramaconn.png

Resolved! Convert Local Security Policies to Panorama Policies

We have quite a few Palo Altos that we inherited that have many local policies. We would like to manage these policies via Panorama. Is it possible to convert Local Security Policies to Panorama Policies using Expedition? If so is there a guide on how to do that?

CZellars by L1 Bithead
  • 12092 Views
  • 5 replies
  • 0 Likes
  • 1186 Posts
  • 89 Subscriptions
Labels