Expedition issue: Security policies not merging automatically(While trying to migrate from ASA to PA

Reply
Highlighted

Expedition issue: Security policies not merging automatically(While trying to migrate from ASA to PA

Hello,

 

We are trying to migrate the CISCO ASA configuration to the Palo Alto using expedition and we have imported the ASA config to the expedition by clicking on "Group access-lists by remarks". 

 

We have around 38K access lists on Cisco ASA and the security policies on the Palo alto firewall is not merging as expected.  We did migrations before and the access-lists around 30K are shrinked to around 2800.

 

Currently expedition is running on 1.1.58.1. We are not able to identify the root cause and expecting assistance on this.

 

Thank you in advance.

 

Thanks,

Santosh

 

Highlighted
L5 Sessionator

Re: Expedition issue: Security policies not merging automatically(While trying to migrate from ASA t

Do you get the expected results if you do not mark the option of Grouping ACL's?

Highlighted

Re: Expedition issue: Security policies not merging automatically(While trying to migrate from ASA t

Thank you for the response  Dgildelaig

Regardless of marking and non-marking the Merge option, the acl count is the same.

Highlighted
L5 Sessionator

Re: Expedition issue: Security policies not merging automatically(While trying to migrate from ASA t

Can you contact us to fwmigrate@paloaltonetworks.com and we can check why may be some ACLs missing?
If you have already identified any missing ACL in the migration, provide also some information about it, in case we spot what specific that ACL may have that we did not support yet.

Highlighted

Re: Expedition issue: Security policies not merging automatically(While trying to migrate from ASA t

Hello,

 

The ACL's are not missing, however the issue is with ACL merging. We have around 30000 security policies. 

 

For suppose, if we have 10 rules with source, same destination port and with 10 destinations, Ideally the expedition should merge this to single rule, but this is not happening now.

 

Can you please help us on this matter. 

Highlighted
L5 Sessionator

Re: Expedition issue: Security policies not merging automatically(While trying to migrate from ASA t

Absolutely,

Please contact with me at fwmigrate@paloaltonetworks.com to schedule a session

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!