<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Easy way to transfer the configuration of PA-220 to PA-440 in Expedition Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/expedition-discussions/easy-way-to-transfer-the-configuration-of-pa-220-to-pa-440/m-p/557641#M4706</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/230828"&gt;@iex2022&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks for posting.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The target use of expedition is for migration from 3rd party product to Palo Alto. Since these Firewalls are managed by Panorama, the migration should be straight forward. I would suggest below steps:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1.)&lt;/P&gt;
&lt;P&gt;Clone Template / Template Stack currently assigned to PA-220 and assign PA-440 to newly cloned&amp;nbsp;Template / Template Stack. If necessary adjust the configuration in Template that is hardware specific to PA-440, for example interfaces.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2.)&lt;/P&gt;
&lt;P&gt;Assign PA-440 to the same Device Group as PA-220, then push the Template Stack and Device Group to PA-440.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3.)&lt;/P&gt;
&lt;P&gt;If there was no error / issue with pushing the configuration, I would schedule a maintenance window to move cables (or open ports on the switch) from PA-220 to PA-440. Since you mentioned this is a migration with the same configuration, I expect IP addresses assigned to data plane interfaces to be the same, therefore window for cut over might be necessary to avoid IP address duplication.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;4.)&lt;/P&gt;
&lt;P&gt;If traffic is going through and failover test passed, I would remove PA-220 from Panorama and cleaned up all related configuration.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regarding versions, there should be no issue. As long as Panorama is running the same version or higher than Firewall.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
    <pubDate>Wed, 13 Sep 2023 03:16:14 GMT</pubDate>
    <dc:creator>PavelK</dc:creator>
    <dc:date>2023-09-13T03:16:14Z</dc:date>
    <item>
      <title>Easy way to transfer the configuration of PA-220 to PA-440</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/easy-way-to-transfer-the-configuration-of-pa-220-to-pa-440/m-p/557635#M4705</link>
      <description>&lt;P&gt;&lt;SPAN&gt;We have two PA-220 firewalls that work in both active and standby mode. Panorama is in control of these two firewalls. We are now attempting to move it to PA-440 because of network issues. Is it possible to transfer the configuration from PA-220 to PA-440 from panorama export configuraiton or can I used expedition to do that? I don't see any documentation. Please review the versions listed below.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;PA-220 - Version 9.1.16&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;PA-440 - Version 10.1.8&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Panorama - Version 10.2.3-h2&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Sep 2023 01:56:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/easy-way-to-transfer-the-configuration-of-pa-220-to-pa-440/m-p/557635#M4705</guid>
      <dc:creator>iex2022</dc:creator>
      <dc:date>2023-09-13T01:56:51Z</dc:date>
    </item>
    <item>
      <title>Re: Easy way to transfer the configuration of PA-220 to PA-440</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/easy-way-to-transfer-the-configuration-of-pa-220-to-pa-440/m-p/557641#M4706</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/230828"&gt;@iex2022&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks for posting.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The target use of expedition is for migration from 3rd party product to Palo Alto. Since these Firewalls are managed by Panorama, the migration should be straight forward. I would suggest below steps:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1.)&lt;/P&gt;
&lt;P&gt;Clone Template / Template Stack currently assigned to PA-220 and assign PA-440 to newly cloned&amp;nbsp;Template / Template Stack. If necessary adjust the configuration in Template that is hardware specific to PA-440, for example interfaces.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2.)&lt;/P&gt;
&lt;P&gt;Assign PA-440 to the same Device Group as PA-220, then push the Template Stack and Device Group to PA-440.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3.)&lt;/P&gt;
&lt;P&gt;If there was no error / issue with pushing the configuration, I would schedule a maintenance window to move cables (or open ports on the switch) from PA-220 to PA-440. Since you mentioned this is a migration with the same configuration, I expect IP addresses assigned to data plane interfaces to be the same, therefore window for cut over might be necessary to avoid IP address duplication.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;4.)&lt;/P&gt;
&lt;P&gt;If traffic is going through and failover test passed, I would remove PA-220 from Panorama and cleaned up all related configuration.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regarding versions, there should be no issue. As long as Panorama is running the same version or higher than Firewall.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Wed, 13 Sep 2023 03:16:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/easy-way-to-transfer-the-configuration-of-pa-220-to-pa-440/m-p/557641#M4706</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2023-09-13T03:16:14Z</dc:date>
    </item>
  </channel>
</rss>

