<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article Nominated Discussion: Move Firewall to new Panorama in General Articles</title>
    <link>https://live.paloaltonetworks.com/t5/general-articles/nominated-discussion-move-firewall-to-new-panorama/ta-p/540288</link>
    <description>&lt;DIV class="lia-message-template-content-zone"&gt;
&lt;P&gt;&lt;SPAN&gt;This Nominated Discussion Article is based on the post "&lt;/SPAN&gt;&lt;A href="http://Mover firewall to new Panorama" target="_blank" rel="noopener"&gt;Generate cookie vs Accept Cookie&lt;/A&gt;&lt;SPAN&gt;" by&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/167427"&gt;@securehops&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;and responded to by our Cyber Elite&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/77347"&gt;@TomYoung&lt;/a&gt;.&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;Read on to see the discussion and solution! Check out the discussion to see all responses from Tom.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;We currently have 2 Panoramas (virtual) managing different firewalls..&amp;nbsp; We'd like to move all firewalls to 1 pano, so we can retire the other one.&amp;nbsp; &amp;nbsp;What's the best/safest way to accomplish that?&amp;nbsp; Is there a way to avoid having duplicate objects while migrating or would it be a cleanup effort after the fact.&amp;nbsp; &amp;nbsp;It's a mix of standalone firewalls and HA (active/passive) firewalls.&amp;nbsp; &amp;nbsp;These are all in production, so concerned about downtime.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I know there is a process to import standalone firewalls into panorama, but these firewalls are already managed by pano.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;STRONG&gt;Response:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;Let's talk about how to get the configurations from the old Panorama to the new one.&amp;nbsp; I can think of 2 ways:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;If you have Expedition, you can use it to merge the configurations and clean up duplicates.&amp;nbsp; Then you can import the configuration into the new Panorama.&lt;/LI&gt;
&lt;LI&gt;If you do not have Expedition, you can use the "load config partial mode merge" command to import the device group and templates into the new Panorama.&amp;nbsp; If you have duplicate names in the Shared device group, you will get errors.&amp;nbsp; If the duplicates also have the same value, you do not need to fix anything.&amp;nbsp; They are already there.&amp;nbsp; If they have the same name and a different value (which seems doubtful), you will need to fix it.&amp;nbsp; Items with duplicate values will need to be cleaned up afterwards.&amp;nbsp; Duplicate rules will need to be cleaned up afterwards.&amp;nbsp; &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClbLCAS" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClbLCAS&lt;/A&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Any time that you import configurations into Panorama as opposed to building them from scratch, you will need to do some cleanup/restructuring. Thankfully, the Move button on the bottom of Policies and Objects makes that easier.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;You do not have to move all of the config locally.&amp;nbsp; You can import the device configuration (including Shared) and templates into the new Panorama using "load config partial mode merge".&amp;nbsp; This would be preferred because moving all the config locally can make it difficult to move partial Network and Device configuration to Panorama.&lt;/LI&gt;
&lt;LI&gt;It can definitely be phased over 1 NGFW at a time.&amp;nbsp; If you are using template variables, make sure you manually configure those after the NGFWs are moved to Panorama.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Expedition makes some things easier, but it does take time to install and learn.&amp;nbsp; Unless you have a LOT of objects, I probably would not.&amp;nbsp; Instead, I would do the following:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;As much as possible, I would change the object names on the old to match the new.&amp;nbsp; Definitely have Automated Commit Recovery enabled before you do this.&amp;nbsp; Make sure the device group and template names are different!&lt;/LI&gt;
&lt;LI&gt;Rename your zones on the old Panorama to match the new.&amp;nbsp; This is tricky.&amp;nbsp; After the rename, create the old zones again in the templates so that the push does not fail on the managed device.&amp;nbsp; After the push is successful, delete the old zones.&lt;/LI&gt;
&lt;LI&gt;Rename your shared objects before the migration.&amp;nbsp; It will be easier to standardize the names before the migration because you can just rename and not have to swap objects inside the policies.&amp;nbsp; Otherwise, Expedition makes the rename/swap easier.&lt;/LI&gt;
&lt;LI&gt;When you migrate a NGFW, aim for a like-for-like configuration.&amp;nbsp; Don't adjust the templates or device groups on the new Panorama until all the devices are moved.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;</description>
    <pubDate>Fri, 28 Apr 2023 15:07:41 GMT</pubDate>
    <dc:creator>JayGolf</dc:creator>
    <dc:date>2023-04-28T15:07:41Z</dc:date>
    <item>
      <title>Nominated Discussion: Move Firewall to new Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/general-articles/nominated-discussion-move-firewall-to-new-panorama/ta-p/540288</link>
      <description>&lt;P&gt;&lt;SPAN&gt;This Nominated Discussion Article is based on the post "&lt;/SPAN&gt;&lt;A href="http://Mover firewall to new Panorama" target="_blank" rel="noopener"&gt;Generate cookie vs Accept Cookie&lt;/A&gt;&lt;SPAN&gt;".&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Apr 2023 15:07:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-articles/nominated-discussion-move-firewall-to-new-panorama/ta-p/540288</guid>
      <dc:creator>JayGolf</dc:creator>
      <dc:date>2023-04-28T15:07:41Z</dc:date>
    </item>
  </channel>
</rss>

