When you go to the "objects" tab, and you can click on the right lower corner "red" dot to remove unused objects as shown in the screenshot. After removing unused objects, you will need to click on the "Green" dot again to re-calculate unused objects so it will reflect the change.
Please aware of the pre-defined service objects like application-default, http, https , those can't be removed due to it's pre-defined service objects in PAN-OS.
Hello @shallugarg ,
For duplicate objects, you can go to Dashboard and click on the red number shown on the duplicate objects and it will take you to see the duplicate objects, example, if it's address objects, you can right-click on the address objects and click on "merge" to merge either based on name and value or value.
Thanks for your quick reply.
i see 56 duplicate objects for address and that has been taken care of.
I see under services section that there are 6 duplicate entries for services.
domain tcp 53
domain udp 53
nfs tcp 2049
nfs udp 2049
sunrpc tcp 111
sunrpc udp 111
Hi in your example , you might not want to merge tcp 53 and udp 53 to one single service object , you should rename the object name, for example, domain_tcp , domain_udp , that way you can keep both service objects since they do have different value,
Thanks. At last i was able to figure out how to replace that
Last piece is that i checked the invalid section again from dashboard and observed i have few in invalid zones.
P.S. i am trying to convert config from ASA to Palo Alto.
Do, i need to fix this as well
Yes, if it shows invalid object, you need to fix it before you are able to import it to PAN-OS device, for example: if it's ICMP service object, you will need to replace the service object with ICMP application, please refer below video for replacing invalid service object with the application.
For an invalid zone, you can go to "Monitor" -> "Migration log" to see what's the reason it sees the zone as invalid.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!