<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Migrating PA-3050 to PA-1420 in Expedition Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/expedition-discussions/migrating-pa-3050-to-pa-1420/m-p/644914#M5194</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/336923"&gt;@Kevin_Clark&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you mind sharing the steps that you did?&lt;/P&gt;
&lt;P&gt;Did you still use the expedition or config export/import method?&lt;/P&gt;
&lt;P&gt;I'm in the same boat trying to migrate from 3020 (9.x) to 1420 (11.x).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I greatly appreciate your feedback.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 21 Nov 2024 21:03:47 GMT</pubDate>
    <dc:creator>iamxCPx</dc:creator>
    <dc:date>2024-11-21T21:03:47Z</dc:date>
    <item>
      <title>Migrating PA-3050 to PA-1420</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/migrating-pa-3050-to-pa-1420/m-p/591724#M5084</link>
      <description>&lt;P&gt;I'm attempting to use Expedition to merge the config from our PA-3050 (PAN-OS 9.1.x) into the config for a PA-1420 (PAN-OS 11.0.x).&amp;nbsp;The problem is that the vsys1 components aren't transferring across.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can anyone guide me through what I need to do to get this merge working in Expedition? Thanks in advance.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Base config: PA-1420_base.xml&lt;/P&gt;
&lt;P&gt;Config to migrate: drfw_20240711.xml&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After hitting the Merge button go to the Devices section and view the now updated PA-1420 config: It d&lt;SPAN&gt;oesn't show the interfaces, virtual wires or virtual routers:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Screenshot 2024-07-11 at 16.12.29.png" style="width: 852px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/60738i9ADCF93301329967/image-dimensions/852x247/is-moderation-mode/true?v=v2" width="852" height="247" role="button" title="Screenshot 2024-07-11 at 16.12.29.png" alt="Screenshot 2024-07-11 at 16.12.29.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;
&lt;P&gt;Those components are still shown in the config from the PA-3050 that I'm trying to migrate:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Screenshot 2024-07-11 at 16.12.43.png" style="width: 851px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/60739i53164E85918008A2/image-dimensions/851x248/is-moderation-mode/true?v=v2" width="851" height="248" role="button" title="Screenshot 2024-07-11 at 16.12.43.png" alt="Screenshot 2024-07-11 at 16.12.43.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;
&lt;P&gt;For the record this is a screenshot of the configs after I've imported them but before making any changes:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Screenshot 2024-07-11 at 16.10.44.png" style="width: 836px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/60737i06430D612722F750/image-dimensions/836x464/is-moderation-mode/true?v=v2" width="836" height="464" role="button" title="Screenshot 2024-07-11 at 16.10.44.png" alt="Screenshot 2024-07-11 at 16.10.44.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;
&lt;P&gt;And this is a screenshot after I've dragged the components across just prior to hitting the Merge button:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Screenshot 2024-07-11 at 16.11.16.png" style="width: 847px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/60740iEB96A50CC6557559/image-dimensions/847x483/is-moderation-mode/true?v=v2" width="847" height="483" role="button" title="Screenshot 2024-07-11 at 16.11.16.png" alt="Screenshot 2024-07-11 at 16.11.16.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Thu, 11 Jul 2024 15:34:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/migrating-pa-3050-to-pa-1420/m-p/591724#M5084</guid>
      <dc:creator>Kevin_Clark</dc:creator>
      <dc:date>2024-07-11T15:34:27Z</dc:date>
    </item>
    <item>
      <title>Re: Migrating PA-3050 to PA-1420</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/migrating-pa-3050-to-pa-1420/m-p/591822#M5085</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/336923"&gt;@Kevin_Clark&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for reaching out.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Expedition tool is intended to help on migrations from 3rd party vendors and also to optimise the security posture on a PANOS device.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The migration you are describing could be done using PANOS features as export and import from old to new devices (you may need to update networking information and VPN configuration).&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Once you have your configuration pushed to your new device you can download it to Expedition and do some optimisation like removing duplicates and merging similar policies among other features Expedition can help.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Said that, if you still want to use Expedition for that please check&amp;nbsp;the file /tmp/error after doing the merge and share it with me using the email &lt;A href="mailto:fwmigrate@paloaltonetworks.com" target="_blank"&gt;fwmigrate@paloaltonetworks.com&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;David&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jul 2024 08:22:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/migrating-pa-3050-to-pa-1420/m-p/591822#M5085</guid>
      <dc:creator>dpuigdomenec</dc:creator>
      <dc:date>2024-07-12T08:22:39Z</dc:date>
    </item>
    <item>
      <title>Re: Migrating PA-3050 to PA-1420</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/migrating-pa-3050-to-pa-1420/m-p/591850#M5086</link>
      <description>&lt;P&gt;Thanks, David.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm pleased to report that the import of the config from our PA-3050 (PAN-OS 9.1.x) into our new PA-1420 (PAN-OS 11.0.x) was successful. Thank you for this recommendation.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kevin&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jul 2024 14:51:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/migrating-pa-3050-to-pa-1420/m-p/591850#M5086</guid>
      <dc:creator>Kevin_Clark</dc:creator>
      <dc:date>2024-07-12T14:51:34Z</dc:date>
    </item>
    <item>
      <title>Re: Migrating PA-3050 to PA-1420</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/migrating-pa-3050-to-pa-1420/m-p/644914#M5194</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/336923"&gt;@Kevin_Clark&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you mind sharing the steps that you did?&lt;/P&gt;
&lt;P&gt;Did you still use the expedition or config export/import method?&lt;/P&gt;
&lt;P&gt;I'm in the same boat trying to migrate from 3020 (9.x) to 1420 (11.x).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I greatly appreciate your feedback.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Nov 2024 21:03:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/migrating-pa-3050-to-pa-1420/m-p/644914#M5194</guid>
      <dc:creator>iamxCPx</dc:creator>
      <dc:date>2024-11-21T21:03:47Z</dc:date>
    </item>
    <item>
      <title>Re: Migrating PA-3050 to PA-1420</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/migrating-pa-3050-to-pa-1420/m-p/648989#M5195</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/36541"&gt;@iamxCPx&lt;/a&gt;&amp;nbsp;I didn't end up using Expedition to make the config changes because it turned out to be relatively straightforward to edit the XML file, and then validate those changes in the web UI before committing them.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. Exported the config from the 3050&lt;/P&gt;
&lt;P&gt;2. Modifications to the XML in a text editor, e.g.&amp;nbsp;changed the interface references to what they needed to be on the 1420, set the management interface to the temporary IP address for the 1420&lt;/P&gt;
&lt;P&gt;3.&amp;nbsp;&lt;SPAN&gt;Import the XML on the 1420&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;4. Commit -&amp;gt; Validate to see what errors&amp;nbsp;it spits out, e.g.&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;Validation Error:&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;rulebase -&amp;gt; security -&amp;gt; rules -&amp;gt; Block Known Malicious Dynamic -&amp;gt; destination 'panw-known-ip-list' is not an allowed keyword&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;rulebase -&amp;gt; security -&amp;gt; rules -&amp;gt; Block Known Malicious Dynamic -&amp;gt; destination panw-known-ip-list is an invalid ipv4/v6 address&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN&gt;5. Edit the XML to correct the errors&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;6. Repeat steps 2-5 until no more validation errors&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Nov 2024 08:47:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/migrating-pa-3050-to-pa-1420/m-p/648989#M5195</guid>
      <dc:creator>Kevin_Clark</dc:creator>
      <dc:date>2024-11-22T08:47:12Z</dc:date>
    </item>
    <item>
      <title>Re: Migrating PA-3050 to PA-1420</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/migrating-pa-3050-to-pa-1420/m-p/650139#M5196</link>
      <description>&lt;P&gt;Thank you for this.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have more questions if you don't mind.&lt;/P&gt;
&lt;P&gt;Did you do this after you set up the licenses and upgraded to the latest software version on the 1420?&lt;/P&gt;
&lt;P&gt;I haven't connected the 1420 live to the internet. At the moment, I am only connected to the management port.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I wonder if the import will fail if it does not have the same licenses on the 1420.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;TIA.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Nov 2024 18:20:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/migrating-pa-3050-to-pa-1420/m-p/650139#M5196</guid>
      <dc:creator>iamxCPx</dc:creator>
      <dc:date>2024-11-22T18:20:39Z</dc:date>
    </item>
    <item>
      <title>Re: Migrating PA-3050 to PA-1420</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/migrating-pa-3050-to-pa-1420/m-p/650239#M5197</link>
      <description>&lt;P&gt;It looks like he had not yet installed the licenses, that is why he got an error about "&lt;SPAN&gt;'panw-known-ip-list' is not an allowed keyword". No big deal, but with the licenses installed and content updated first, the PA firewall will have its EDL's downloaded and won't give this error.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;For me, the best practice is to:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;1. Connect mgt interface on new firewall, get dns to work, fetch licenses, obtain content updates.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;2. Get PAN-OS to same level as prior firewall or upgrade prior firewall to catch up. The closer the better but they don't need to be exact.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;3. Export running config of old firewall, e.g. save file on disk "PA3050-config.xml".&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;4. On new firewall, save named config snapshot "PA1410-original". Import "PA3050-config.xml" to new firewall. Load config. Look it over. (I have never had to edit the xml file first) but I agree with the above last 3 steps, reposted below.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To answer your question, import or load will not fail if licenses don't match, but possibly the validation or commit could fail, which you can tweak before successful commit.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;5. Commit -&amp;gt; Validate to see what errors&amp;nbsp;it spits out, e.g.&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI aria-level="1"&gt;&lt;SPAN&gt;Validation Error:&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI aria-level="1"&gt;&lt;SPAN&gt;rulebase -&amp;gt; security -&amp;gt; rules -&amp;gt; Block Known Malicious Dynamic -&amp;gt; destination 'panw-known-ip-list' is not an allowed keyword&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI aria-level="1"&gt;&lt;SPAN&gt;rulebase -&amp;gt; security -&amp;gt; rules -&amp;gt; Block Known Malicious Dynamic -&amp;gt; destination panw-known-ip-list is an invalid ipv4/v6 address&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN&gt;6. Edit the XML to correct the errors&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;7. Repeat steps 2-5 until no more validation errors&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Nov 2024 19:36:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/migrating-pa-3050-to-pa-1420/m-p/650239#M5197</guid>
      <dc:creator>ksalustro</dc:creator>
      <dc:date>2024-11-22T19:36:15Z</dc:date>
    </item>
  </channel>
</rss>

