cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Who rated this post

Hi @mss.support ,

1 you will zip all three asa config into a zip file 

2. upload your asazip file in the import -> cisco -> upload multiple files 

Screen Shot 2021-04-30 at 9.29.04 AM.png

3. Upload your PAN-OS config under Import -> Palo Alto -> upload a single file. upload your base config here . it can be either firewal or panorma config depends where your policy going to be managed at. 

4.  You will need to fix all the red number showing in the dashboard for each of the cisco asa file , you can switch the context located at the right bottom corner to get to each of the ciscoasa config and make modification for each of the ciscoasa config 

Screen Shot 2021-04-30 at 9.38.41 AM.png

5.  Since you are merging three ciscoasa firewall into one palo alto firewall, you will need to review which network interfaces you would like to migrate to the palo alto network, if there are not many interfaces, you can build the interfaces and zone on the firewall directly, please make sure the zone name needs to match the zone name in the policy.  If there are a lot of interfaces you would like to keep from ciscoasa config, you will need to fix the interface configurations under each cisocasa config, make sure you rename each of the interfaces to PAN-OS naming conventions and each of the configs do not have duplicated interface names, also you might only need one VR depends on your use case. When you ready to merge the source and base configs, you can go to "Export" -> " Mapping" -> if you need to merge the network interface, you will first start with ciscoasa1 config, check all checkbox under "network", drag and drop them to "network" section onto the right side base config (If you already built interfaces and zone on the firewall, you do not need to merge the network configuration ) for policy and objects, under vsys1, drag and drop them to the right side vsys 1, continue for ciscoasa2 and ciscoas3 

Screen Shot 2021-04-30 at 9.29.33 AM.png

 

6. Once you finished drag and drop, you should see configuration from 3 ciscoasa moved to base config as below :

Screen Shot 2021-04-30 at 9.30.27 AM.png

 

7. You can then click on "Merge" to merge the config 

8. Once the merge is done, you can then click "Generate XML and set output" to download the merged xml file. 

Screen Shot 2021-04-30 at 9.55.06 AM.png

9 You could then load the config using "load config partial" or if you have direct access between expedition and firewall, you can then do an API calls from expedition to firewall to push the configuration over. 

 

 

 

 

 

 

 

 

Who rated this post