- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
02-28-2020 12:20 AM
Hi,
I had recently did a migration via expedition from ScreenOS (6.3.0r25.0) to PANOS, ScreenOS supports both TCP and UDP ports within a single object. When the configuration gets ported over to PANOS, Expedition creates one TCP service and one UDP service, then adds both of them into a Service Group. This is because PANOS does not support both TCP and UDP ports within a single object.
However, Expedition chooses only the TCP service object for the security policy instead of choosing the Service Group, this should not be the expected behaviour. Hence, could I check if this is a bug? Thanks.
02-28-2020 12:50 AM
Thanks for pointing this out.
This may be a missing control in the Expedition parser. Could you contact us to fwmigrate@paloaltonetworks.com to deeper inspect this case (potentially with a sample of the configuration) so we can resolve it?
Thanks
02-28-2020 02:00 AM
Hello, thanks for the reply. I've contacted the email aliase. Apologies, I couldn't provided the screen os config as it is confidential to the customer. Thanks!
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!