Expedition Discussions
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Expedition Discussions

Discussions

Resolved! ML gets stuck at "Pending"

I started by running the command scp export log traffic start-time equal 2018/07/30@00:00:00 end-time equal 2018/07/30@23:45:00 to expedition@172.30.200.117:/PALogs/mltest.csv on my PA220. root@Expedition:/PALogs# ls -ltotal 64296-rw-rw-r-- 1 expedition expedition 65830760 Aug 1 17:35 mltest.csvdrwxr-xr-x 2 www-data www-data 4096 Aug 1 ...

Untitled.png
mbowling by L1 Bithead
  • 46532 Views
  • 26 replies
  • 3 Likes

If You Need an OVA...

I created an OVA for my team and put it up here (Note, this isn't the official release now offered by PANW): https://drive.google.com/open?id=1Z9GrCF8I_BZzpbEmEh6G75npo05_4G0c Be sure to go Settings > M. Learning > and change the Expedition ML Address address to your VM's IP. Then return to the Dashboad and Start the Agent. [UPDATE 6.4...

trice by L1 Bithead
  • 73746 Views
  • 46 replies
  • 23 Likes

Resolved! How to Upload configuration files bigger than 2MB

Expedition uses APACHE as a web server and PHP as module for the scripts. By default PHP allow users to upload files with a maximum size of 2M, this can be updated by changing the PHP.ini sudo vi /etc/php/7.0/apache2/php.ini go to line where this variable is defined upload_max_filesize = 2M and replace by upload_max_filesize = 250M There...

alestevez by L7 Applicator
  • 30256 Views
  • 5 replies
  • 11 Likes

Resolved! Problem Object groups to migrate Check Point r81 to Palo Alto in Expedition

Community, I am in a project migrating a checkpoint in version r81.10 in expedition to palo alto, but the object groups are blank when I export the configuration, and it eliminates most of the objects that I need for the configuration. This problem did not happen to me with checkpoint in version R80, everything was migrated correctly, do you kno...

Cisco ASA To Panorama Partial Configuration question

We currently use Panorama to manage multiple firewalls across our organization. We have a Edge ASA Cluster we are needing to migrate over to an existing pair of Palo Alto Firewalls, managed by Panorama. I would like to only migrate over the Objects, Security Policies, and NAT rules, From the Cisco ASA config to the Panorama. I have impor...

Resolved! Struggling to get Expedition working

Hi everyone. I am really struggling to get Expedition working so I can use it to migrate setting from our existing firewall to new firewalls that will be managed by Panorama. I have deployed Ubuntu 20.04.* LTS Server (64-bits AMD) to an EXSi server followed the instructions on https://live.paloaltonetworks.com/t5/expedition-articles/expedition...

a.parmar by L0 Member
  • 2963 Views
  • 3 replies
  • 0 Likes

Expedition - re-assign zones after change in routing

The imported config had an OSPF dynamic routing so some routes were not in routing table. Therefore zones aren't correct on some rules. I can add the routes from OSPF manually into VR in my Expedition project. But how do I force Expedition to re-populate zones throughout whole configuration, please?

santonic by L6 Presenter
  • 4249 Views
  • 7 replies
  • 0 Likes

Security Policy Filter - Affects the IP(s)

I'm working on business unit segmentation projects so I have to identify rules affecting specific subnets and build a new policy. The policies are normally several thousand rules and sometimes over 15 thousand rules so the "Affects the IP" filter comes in very handy however I've noticed some behaviors which don't seem correct or maybe I'm not u...

The '/PALogs/<firewall logs folder>' cannot be scanned. '

I am getting the following error when trying to scan my log folder on expedition "The '/PALogs/&lt;firewall logs folder&gt;' cannot be scanned. '." I am on version 1.1.101. I also am wondering if maybe my rsylog configuration is not right. The folders being created are created by root. I have no issues if I import files manually.

"DM_INLINE_" Network,services and groups not being referenced in policies when importing from ASA

Hi, Im currently migrating a specific context of an ASA with version 9.6. The migrated rules reference the actual objects or any other network/service object group which name does not begin with "DM_INLINE". Is this as intended? im left with a lot of unused object groups named DM_INLINE that should probably get deleted if they are not refe...

Resolved! How to filter out "unused" Address objects and Group objects if they are listed on an unused rule

When I used the "Unused" objects filter, it lists objects that are defined in rules and groups if there is no traffic, as well as objects that aren't used at all. We have some rules that are not used very often, but are still required, so the rules are listed as "unused" only because there has been no traffic for 30 days. Because of this, the ...

ChrisC2 by L1 Bithead
  • 5103 Views
  • 3 replies
  • 0 Likes

Forcepoint Management center migration to panoroma

Hello i have a question about the migration from forcepoint to paloalto network. Is there a link or documentation that explain step by step the migration.Forcepoint does not use uinterface or zone in its policies it just use source and destination address. Will expedition be aware to know the source zone and destination zone ? Cordially

Cisco FTD Migration

I've embarked on my first FTD migration journey for a client and wanted to share my early [and tantalisingly promising] results. The customer is running NGFW Version 6.4.0.17 on FPR-2110 appliances. My exposure to FTD is on par with its popularity, so please bear with me. First thing to note is FTD (and FMC) is basically code running on Linux ...

mb_equate by L3 Networker
  • 10829 Views
  • 5 replies
  • 1 Likes
  • 1187 Posts
  • 89 Subscriptions
Labels