Import Panorama Configuration Into Expedition and export Device Specific configuration

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Import Panorama Configuration Into Expedition and export Device Specific configuration

L1 Bithead

Hi Experts, I am quiet new to Expedition, currently i am involved in a mass project where i have to migrate exiting Palo Alto Firewall into new. The existing firewall is managed by panorama which have tons of Network addresses and security policies which also uses shared object and polices from panorama.

    Now my objective is to import that panorama config into expedition and export out config related to specific firewall that i am planning to migrate.

Is there any documentation or video on this? 

3 REPLIES 3

Cyber Elite
Cyber Elite

Hi @LijoMathai ,

 

I have migrated a single firewall configuration to Panorama using Expedition.  So, the reverse should work, also.  Here are the steps:

 

  1. Import the NGFW configuration 1st.  The 1st imported PAN-OS configuration is the base config.  I personally like to load the Day 1 Configuration on my NGFW and use it as my base config.  In that way, I have a lot of best practices configured.
  2. Import the Panorama config into Expedition next.  Look at the dashboard and fix any items, if desired.
  3. Under Export drag the source configuration items on the left under templates to Device or Network on the right.  Drag the policies and objects on the left to vsys1 on the right.
  4. Merge and export.

https://www.youtube.com/watch?v=RMHfO4MA0jw

 

Thanks,

 

Tom

 

Edit:  Hi @LijoMathai , the steps above work if the new NGFW is not managed by Panorama.  Is that what you want?

Help the community: Like helpful comments and mark solutions.

L1 Bithead

Hi, I managed to get the required config, Thanks

L2 Linker

@LijoMathai  I am also looking to do the same, how did you make it work?

  • 2189 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!