- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
01-24-2019 07:26 AM
Hi Guys,
I'm migrating to a PA 3220 running PAN-OS 8.1.5. I migrated the Cisco config using the migration tool 3.3.10.
Policies, Zones, Interfaces, NATs, everything was migrated. However, site to site VPNs weren't.
Doesn't the migration tool migrate site to site VPNs?
Am I missing something?
Thanks.
01-24-2019 07:30 AM
Have you tried this in Expedition? MT3 has not been updated in years and will not be.
Your S2S tunnels should migrate.
01-24-2019 08:22 AM
I'm going to install Expedition and migrate again. Thanks.
01-28-2019 02:43 AM
Hi mate,
unfortunately, it didn't work either using Expedition. None IPSec tunnel was imported
Any idea?
01-28-2019 07:25 AM
Can you contact us at fwmigrate at paloaltnetworks dot come to check it further?
Expedition should be able to import your VPNs, so we will check it.
02-10-2020 05:46 PM
it would be good to hear the general outcome of such exchanges.
i realize that you shouldn't reveal sensitive information, but tips on what the problem was and the general resolution would help others greatly.
thanks
02-11-2020 12:59 AM
The cisco parser in Expedition has been improved to understand and include more types of VPNs.
In the newest versions of Expedition this should be fixed.
02-11-2020 08:09 PM
thanks, that helps the rest of us know what happened.
i had a different problem: the VPNs migrated, but they were all invalid.
finally figured out that the IKE profiles weren't assigned so i had to select them then they were okay.
i had to figure this out myself: are there any guides that would have given me a clue?
thanks
02-12-2020 01:17 AM
You can check the migration workflow guide here:
https://live.paloaltonetworks.com/t5/Expedition-Articles/Expedition-User-Guide-v1-2/ta-p/285157
Also you can send an email to fwmigrate at paloaltnetworks dot come to check this problem further.
02-12-2020 02:17 AM
Most probably that piece of information is not updated in your Manual.
Sorry for not having it updated enough.
02-12-2020 06:05 AM
yes, i used the guide, but it didn't say much about VPNs.
will keep in mind the option of fwmigrate dot com
thanks
02-12-2020 06:11 AM
don't get me wrong, it did a great job of converting overall. the logs were helpful, just had to figure out the correlation.
one thing: with the NAT rules, the warnings were connected when i edited, but not on the VPN, so it took me longer to track down the connection.
thanks
02-13-2020 06:51 AM
Thanks,
I will take a look into this
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!