Fortigate 5.6.X migration -> QoS policies and DSCP marking missing

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Fortigate 5.6.X migration -> QoS policies and DSCP marking missing

L1 Bithead

Hi Community,

 

Currently working on a Forti to Palo migration. To my surprise, after uploading the current Forti´s configuration to the Migration tool, I noticed that the QoS polices had not been converterd//were missing. Also, the Forti, within the "config firewall shaper traffic-shaper" section does some "set diffservcode X" for some of the "firewall shaper traffic-shaper" polcies, which are not available within the new Palo Alto configuration-> security policies (where DSCP is configured).

 

Anyone know why these 2 problems are occurring and how could they be fixed?

 

Thanks.

HonoAl

3 REPLIES 3

L6 Presenter

Hi @HonoAl , Those two sections of the Fortinet configuration won't get converted automatically in the current version of Expedition.   The current version of Expedition will auto convert address, services objects, security rules, and NAT rules, but not QOS policy.  If you would like to help us to develop a new feature, please open a TAC case and attach your Fortinet config so we can validate to see if it's possible to auto map the QOS policy from Fortinet to Palo Alto Networks. 

Hi Lychiang,

 

Think we all agree that QoS policies are of paramount relevance when planning and implementing a migration. Being able to convert these using Expedition will significantly increase the value provided by this tool to all its users 🙂

 

Looking forward to seeing this new feature added soon. What´s the ETA for this new development?

 

Thanks.

Hi @HonoAl , 

 

Once you opened a TAC case , Please send your TAC case # to fwmigrate@paloaltonetworks.com. Thanks ! 

  • 3691 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!