I pulled in Panorama as a device, now what?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

I pulled in Panorama as a device, now what?

L2 Linker

We migrated an ASA to a PA and have it managed via Panorama.  We made all the "objects" local to the firewall (vs. Shared).  What I'm trying to do now is compare the Shared objects in Panorama to the objects on the PAN with the local objects so we don't end up w/dup Shared objects.  When I create a new project I'm not seeing the firewall as an option to import, nor can I take the xml file from the firewall (I can but there's nothing there, it's a 5k file).  Prior to Panorama management the file was 245k.  What am I'm missing?  Is my methodology sound?  TIA

6 REPLIES 6

L6 Presenter

Hi @M.Anderson  Please follow below doc to perform migration from firewall to panorama, then you can use expedition to import panorama config to clean up the duplicate objects. 

 

https://docs.paloaltonetworks.com/panorama/11-0/panorama-admin/manage-firewalls/transition-a-firewal...

 

Thank you for the reply lychiang but the firewall has already been pulled into Panorama and Panorama has already been imported into Expedition. This is where I’m stuck.

First of all, when you create an device in panorama , have you retrieved the running config from content tab, also , when you create a project, you will need to assign the panorama to the device , then when you go inside the project, go to import , you should see the panorama in the import tab , you can then double click to import the config. If all the objects are already in panorama config, then when you finished import the panorama config, it should take you to the dashboard , there it will shows you the duplicate objects. 

Thank you @lychiang 

Responses in BOLD

First of all, when you create a device in panorama , have you retrieved the running config from content tab - Yes I had done this

when you create a project, you will need to assign the panorama to the device - This is what I was missing to get the devices in the Project.  I went to Project > Settings > Devices and added the FW device.   Again, what I'm trying to achieve is to compare ONLY the duplicate objects between a single FW and Panorama, not all duplicate objects.  I did see it work for services [see attached] but, addresses shows all DG's.

 

 

It works on Address objects , the same way , once you click on the number on the duplicate address object column on dashboard, it will take you to the address object view and those address object there are duplicate either in the same DG or among different DG , shared .  There is a vsys column , it tells you where the objects located. 

I think I could achieve what I'm looking for if Expedition allowed you to filter on the vsys...

  • 1588 Views
  • 6 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!