11-28-2021 06:02 PM
Hi
I have converted all objects to Shared and this picture illustrates what I think is the correct mappings of each element. Please confirm/correct as necessary. Thanks!
12-01-2021 02:00 AM
Would you mind posting all the steps from the scratch once you complete the migration?
12-01-2021 07:03 AM - edited 12-01-2021 07:14 AM
I'll post what I can remember but I've been more or less following the ASA conversion video on Youtube that Lynn did. The twists are that I'm using Panorama and not firewall to firewall and I get results I don't like and have to rollback to an earlier snapshot or start over completely.
12-01-2021 01:50 PM
Okay, I cleaned up all of the post-merge duplicates, generated API calls, and tried to send the API calls for shared addresses and it almost immediately failed for:
<hostname> \'<hostname\' is already in use]]>
{"25":{"device":"Panorama","status":"fail","text":"<msg><line><![CDATA[ address -> <hostname> \\'<hostname>\\' is already in use]]><\/line><\/msg>","date":"2021-12-01 12:43:13"}}
Other failures:
tcp-9001 -> tag \'merged\' is already in use
{"25":{"device":"Panorama","status":"fail","text":"<msg><line><![CDATA[ service -> tcp-9001 -> tag \\'merged\\' is already in use]]><\/line><line><![CDATA[ service -> tcp-9001 -> tag is invalid]]><\/line><\/msg>","date":"2021-12-01 13:06:49"}}
I saw this the last time I got this point as well but I had started over thinking I had made a mistake.
I was able to send ethernet & AE interfaces successfully.
12-01-2021 02:00 PM
Other failures:
Services Groups
{"25":{"device":"Panorama","status":"fail","text":"<msg><line><![CDATA[ service-group -> RDP -> members \\'tcp-3389-3389-\\' is not a valid reference]]><\/line><line><![CDATA[ service-group -> RDP -> members is invalid]]><\/line><\/msg>","date":"2021-12-01 13:59:06"}}
zones
{"25":{"device":"Panorama","status":"fail","text":"<msg><line><![CDATA[ zone -> T1-T2-Uplink-SRX -> network -> layer3 \\'ae8.16\\' is not a valid reference]]><\/line><line><![CDATA[ zone -> T1-T2-Uplink-SRX -> network -> layer3 is invalid]]><\/line><\/msg>","date":"2021-12-01 13:55:54"}}
I have zero confidence in Security Policies so I'm not going to bother.
12-01-2021 02:29 PM
Interesting - I did a sub-atomic Generate API Requests and then sent that services port (tcp-9001) and it worked.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!