We are migrating multiple Cisco ASA pairs into PA-3260. PANOS 9.0.7, Expedition 1.1.69.3. Initially we are testing using a single ASA at a time. At least one of the "simpler" ASAs seems to migrate cleanly. Our "main" ASA is more complex. After working to clean duplicates and etc, we are able to get to the point where the Commit Check does not generate any errors. Yet, the firewall indicates simply that the Configuration is invalid. The XML is about 94k lines long! Is there any guidance on what we could look for either in Expedition or in the PAN, in order to resolve this and get to a clean potential configuration? Our intention is to then use this as our new base configuration, and add the easier ASAs into it through Expedition.
... View more