Cisco ASA VPN Filters

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Cisco ASA VPN Filters

L2 Linker

I am running the Expedition Tool on our Cisco ASA firewalls and the tools is stating that most of our IP Address, IP Address Groups and Services are invalid.  When I go over these invalid objects, they are all part of our VPN filters on our VPN tunnels.  Is there anyway for the Tool to recognize that these are ACLs rules in the ASA and that they are not invalid?  

7 REPLIES 7

L7 Applicator

before go deep in the troubleshooting, can you verify if you edit the file with "vi" there is no weird characters at the begining of each line line CTRL+M ??? Thanks . And check the format of the config has not been altered, like when a object is defined begins at the very left position and the properties inside it are one space to the right and so... Regards 

This is the configuration directly from the firewall (the .cfg file) and nothing would have been altered.  The Expedition Tool does not seem to understand VPN filter rules, which is just killing us.  We have hundreds of rules to convert over, we just cannot get this Tool to help us, so we are having to do this manually which is just a horrid task!   If their is anything you help us with, it would be appreciated!  

Please share the config file with us via email to fwmigrate at paloaltonetworks dot com or opening a case with support and share the case number with us. Thanks

I have opened a new case for this issue.  The case number is 00968461.  I have uploaded the cisco configuration file to the case. 

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!