- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
02-03-2022 08:20 AM
hello all,
PA newb here. I recently transitioned to a firewall admin job and am learning my way around Palo Alto for the first time. one issue I've been tasked with exploring is an issue where one of our firewalls has fallen out of sync because it is a VM and has limited object storage capabilities. it is the only VM in our production network. We've explored the idea of just unchecking the "share unused objects" box in panorama, but apparently some of my predecessors weren't so careful when crafting new local rules on other firewalls throughout our AS and referenced panorama pushed objects in their local rules.
needless to say this going to be a quagmire of a project to clean up the firewalls, and after that's done, I'm sure there will be a lot of unused objects leftover in panorama after the cleanup is finished.
while doing some digging I discovered PA has a tool called Expedition which can supposedly identify and remove unused objects in PA firewalls. can expedition be used with panorama in this same capacity? that would make my life a million times easier because otherwise I see no way to identify whether or not an object or applicable object group is used.
any insights would be much appreciated.
03-23-2022 11:54 AM
Hi @S_Hiebert ,
Expedition can work with Panorama. https://www.youtube.com/watch?v=r_l_NjGHv90
Another way to find out is to delete the object. If it is used, you will get an error.
Thanks,
Tom
04-13-2023 06:51 AM
I'm curious if you are using expedition on current hardware. What I mean is, I installed the latest expedition only to find that I could not import configs from my current hardware, nor did it support current software versions. I have used it in the past but gave up because of this. Is anyone else having this issue and if so have you found ways around it? I can't be too specific because when I gave up I just had the server team delete the box. But my delema is I would love to be able to cleanup my firewalls. I especially like the ability to let me know unused objects for this purpose.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!