- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
10-13-2024 08:26 PM
Hello everyone,
I imported the configuration from Cisco ASA to PA-460 by following the tutorial from https://www.youtube.com/watch?v=-gbQ-YcgoPs&list=PLD6FJ8WNiIqVez8EBeoyRsnQcKTA5FuZ-. Everything went well except for the Security Zone section which was not exported in the XML file. Can somebody help me?
10-15-2024 06:08 AM
Hi @M.Danuarta
I can confirm it is a bug on version 1.2.96 and it is fixed in 1.2.97 (ETA 21/OCT).
The issue is happening when migrating to a FW. The default template for the zone is not properly set and that causes Zones are not exported in the XML/API and set commands file.
Thanks for pointing this out,
Best
10-14-2024 04:09 AM
Hi @M.Danuarta
Could you check you moved also the zones while doing the drag and drop on the export section. Please see above image as an example.
Also reach out to fwmigrate@paloaltonetworks.com to get in touch with the team and if needed jump into a call.
Thanks!
10-14-2024 04:49 AM - edited 10-14-2024 04:49 AM
Hello @dpuigdomenec ,
Thanks for the response, yes I have done that but it's okay because I have found a solution by using an older version of Expedition which is 1.2.93.
Maybe bug in 1.2.96?
10-14-2024 08:16 AM
Hi @M.Danuarta It could be a bug in 1.2.96. I will test in my lab and publish here my results. Thanks!
10-14-2024 01:00 PM
Hi @M.Danuarta I have verified with merging a ciscoasa config and panorama config in Expedition v1.2.96 and export it out as xml file, I was able to see all the zones are showing in the xml file. I suspect could be when you drag and drop the zone folder from left to right , you drop it to the DG folder instead of template->Device->vsys1 like the solution mentioned in below article:
if you need further helps, please contact fwmigrate@paloaltonetworks.com. Thank you!
10-14-2024 07:22 PM
Hello @lychiang , thanks for trying to help
But in the project I'm working on it's a direct migration to the firewall not through panorama. I have followed the tutorial from this video https://www.youtube.com/watch?v=RMHfO4MA0jw&ab_channel=PaloAltoNetworksLIVEcommunity and the result is still the zone is not exported to xml.
But i want to try through panorama too to see if it works
10-14-2024 08:00 PM
Ah yes, it turns out that if it is through the panorama configuration file, the zone is exported properly. But I still can't migrate directly to the firewall config.
10-15-2024 06:08 AM
Hi @M.Danuarta
I can confirm it is a bug on version 1.2.96 and it is fixed in 1.2.97 (ETA 21/OCT).
The issue is happening when migrating to a FW. The default template for the zone is not properly set and that causes Zones are not exported in the XML/API and set commands file.
Thanks for pointing this out,
Best
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!