03-18-2020 02:48 AM
Hello,
We are trying to migrate the CISCO ASA configuration to the Palo Alto using expedition and we have imported the ASA config to the expedition by clicking on "Group access-lists by remarks".
We have around 38K access lists on Cisco ASA and the security policies on the Palo alto firewall is not merging as expected. We did migrations before and the access-lists around 30K are shrinked to around 2800.
Currently expedition is running on 1.1.58.1. We are not able to identify the root cause and expecting assistance on this.
Thank you in advance.
Thanks,
Santosh
03-18-2020 03:44 AM
Do you get the expected results if you do not mark the option of Grouping ACL's?
03-18-2020 03:46 AM
Thank you for the response Dgildelaig
Regardless of marking and non-marking the Merge option, the acl count is the same.
03-18-2020 04:01 AM
Can you contact us to fwmigrate@paloaltonetworks.com and we can check why may be some ACLs missing?
If you have already identified any missing ACL in the migration, provide also some information about it, in case we spot what specific that ACL may have that we did not support yet.
03-18-2020 04:05 AM
Hello,
The ACL's are not missing, however the issue is with ACL merging. We have around 30000 security policies.
For suppose, if we have 10 rules with source, same destination port and with 10 destinations, Ideally the expedition should merge this to single rule, but this is not happening now.
Can you please help us on this matter.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!