Correct invalid services in Expedition

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Correct invalid services in Expedition

L2 Linker

Hello there,

 

I am currently migrating my ASA 5585 to a Palo 5260 using Expedition tool. Everything on the dashboard has been rectified, except for few services that shows "invalid" and used .

 

I've noticed that Expedition has replaced "icmp" service in ASA to "discard" 

Does anyone know why is that ?

 

Also, there're some invalid services such as (icmp-echo. icmp-echo-reply) but when I try to search/locate them, I don't see them under security policy but they're used in Object groups as shown below So, basically I need to convert them to Ping application as if they were used in security policy ?

AK74_0-1656972005482.png

Finally, I've got "esp" as invalid service but again it's located in an object group. So, how to correct it? replace it with an application (ipsec-esp) or service ?

Thanks

 

4 REPLIES 4

L1 Bithead

I have the same problem and question.

In addition to those, I also have a service object showing up for "GRE", but there is no object in my ASA configured for GRE, or port 47, either individually or within any port range. So I'm not sure where that came from.
They show unused, but I'd still like to understand why they were generated.
I'm wondering if there's any way to display in Expedition what object / config line in the ASA that Expedition referred to in order to create the objects. 3_Invalid_Service_objects_5585i.png

Everything breaks eventually

Hi @Ifixtheinternet Those are default service protocol from your cisco asa config, if it's red dot , means it's not being used in any group object or policies. 

Thanks lychiang,

 

I was not familiar with default objects in the ASA until now.

One must perform a "show run all" on an ASA to see the default objects, which is where I found the default GRE object, as well as the default "echo" object.

The last piece I am uncertain about which AK74 also asked, is why the used service object for ICMP was renamed to "discard".
The service object configured in the ASA is just called "icmp". Not critical as we'll rename it anyway, but I'm still curious.


Everything breaks eventually

What version of Expedition tool are you using ?

  • 3018 Views
  • 4 replies
  • 1 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!