We are in process of migrating ASA config to Palo Alto (multiple context asa to multiple vsys)
Loading the config into Expedition works fine and we are able to remap interfaces and rename zones that are too long in characters. However, when loading the config into the firewall it is unable to link the interfaces to zones
vsys -> vsys1 -> zone -> "zonename" -> network -> layer3 'ae1."X"' is not a valid reference
This show up on all interfaces on all zone. For now the workaround is to not attach interfaces to zones when importing the config and do it on the firewall once loaded.
Also we have some NAT rules that exceed 31 characters that must be renamed. How can i locate these in expedition? I only see them once i try to load the config in the firewall
... View more