I had recently did a migration via expedition from ScreenOS (6.3.0r25.0) to PANOS, ScreenOS supports both TCP and UDP ports within a single object. When the configuration gets ported over to PANOS, Expedition creates one TCP service and one UDP service, then adds both of them into a Service Group. This is because PANOS does not support both TCP and UDP ports within a single object.
However, Expedition chooses only the TCP service object for the security policy instead of choosing the Service Group, this should not be the expected behaviour. Hence, could I check if this is a bug? Thanks.
Thanks for pointing this out.
This may be a missing control in the Expedition parser. Could you contact us to firstname.lastname@example.org to deeper inspect this case (potentially with a sample of the configuration) so we can resolve it?
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!
The Live Community thanks you for your participation!