Hi,
I did not do any re-mapping of the interfaces in the expedition tool. When i imported the configuration to Panorama, the SVI in the cisco FWSM are converted into vlan interfaces in Palo Alto. I tried installing the policy and policy installation succeeded. However, all the vlan interfaces are not mapped to the vsys in which i have defined the policy. If i try to remap the interfaces to specific vsys, i start getting the same error as before.
I have templates and device group configured in Panorama under which the specific vsys exists.
Few basic questions:
1. My only interface to physical network switch is ae1. This is not mapped to any vsys and is configured as layer2.
2. By the migration tool, i have got vlan interfaces created as part of the migrated configuration from cisco. These are not automatically mapped to any vsys. If my understanding is correct, i need to bring these to specific vsys.
3. Is there any additional configuration required to make the ae1 interface to allow traffic in all VLANs and act as trunk?
4. Do i need to create any manual L2 VLAN inside ISE to support the corresponding L3-VLAN interface? Usually in cisco firewall, i have not done this.
Please help.
... View more