<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article Nominated Discussion: Move Firewall to New Panorama in General Articles</title>
    <link>https://live.paloaltonetworks.com/t5/general-articles/nominated-discussion-move-firewall-to-new-panorama/ta-p/570874</link>
    <description>&lt;DIV class="lia-message-template-content-zone"&gt;
&lt;P data-unlink="true"&gt;&lt;SPAN&gt;This Nominated Discussion Article is based on the post "&lt;/SPAN&gt;&lt;STRONG&gt;&lt;A href="https://live.paloaltonetworks.com/t5/general-topics/move-firewall-to-new-panorama/m-p/539747" target="_self"&gt;Move Firewall to New Panorama&lt;/A&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;SPAN&gt;" by&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/167427"&gt;@securehops&lt;/a&gt;&amp;nbsp;&amp;nbsp;and answered by Cyber Elite&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/77347"&gt;@TomYoung&lt;/a&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;We currently have 2 Panoramas (virtual) managing different firewalls..&amp;nbsp; We'd like to move all firewalls to 1 pano, so we can retire the other one.&amp;nbsp; &amp;nbsp;What's the best/safest way to accomplish that?&amp;nbsp; Is there a way to avoid having duplicate objects while migrating or would it be a cleanup effort after the fact.&amp;nbsp; &amp;nbsp;It's a mix of standalone firewalls and HA (active/passive) firewalls.&amp;nbsp; &amp;nbsp;These are all in production, so concerned about downtime.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I know there is a process to import standalone firewalls into panorama, but these firewalls are already managed by pano.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Response:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;Thank you for the excellent info.&amp;nbsp; Let me answer your 2 questions 1st:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;You do not have to move all of the config locally.&amp;nbsp; You can import the device configuration (including Shared) and templates into the new Panorama using "load config partial mode merge".&amp;nbsp; This would be preferred because moving all the config locally can make it difficult to move partial Network and Device configuration to Panorama.&lt;/LI&gt;
&lt;LI&gt;It can definitely be phased over 1 NGFW at a time.&amp;nbsp; If you are using template variables, make sure you manually configure those after the NGFWs are moved to Panorama.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Expedition makes some things easier, but it does take time to install and learn.&amp;nbsp; Unless you have a LOT of objects, I probably would not.&amp;nbsp; Instead, I would do the following:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;As much as possible, I would change the object names on the old to match the new.&amp;nbsp; Definitely have Automated Commit Recovery enabled before you do this.&amp;nbsp; Make sure the device group and template names are different!&lt;/LI&gt;
&lt;LI&gt;Rename your zones on the old Panorama to match the new.&amp;nbsp; This is tricky.&amp;nbsp; After the rename, create the old zones again in the templates so that the push does not fail on the managed device.&amp;nbsp; After the push is successful, delete the old zones.&lt;/LI&gt;
&lt;LI&gt;Rename your shared objects before the migration.&amp;nbsp; It will be easier to standardize the names before the migration because you can just rename and not have to swap objects inside the policies.&amp;nbsp; Otherwise, Expedition makes the rename/swap easier.&lt;/LI&gt;
&lt;LI&gt;When you migrate a NGFW, aim for a like-for-like configuration.&amp;nbsp; Don't adjust the templates or device groups on the new Panorama until all the devices are moved.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;/DIV&gt;</description>
    <pubDate>Tue, 26 Dec 2023 17:06:17 GMT</pubDate>
    <dc:creator>JayGolf</dc:creator>
    <dc:date>2023-12-26T17:06:17Z</dc:date>
    <item>
      <title>Nominated Discussion: Move Firewall to New Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/general-articles/nominated-discussion-move-firewall-to-new-panorama/ta-p/570874</link>
      <description>&lt;P&gt;&lt;SPAN&gt;This Nominated Discussion Article is based on the post "&lt;/SPAN&gt;&lt;STRONG&gt;&lt;A href="https://live.paloaltonetworks.com/t5/general-topics/move-firewall-to-new-panorama/m-p/539747" target="_self"&gt;Move Firewall to New Panorama&lt;/A&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;SPAN&gt;" by&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/167427"&gt;@securehops&lt;/a&gt;&amp;nbsp;&amp;nbsp;and answered by Cyber Elite&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/77347"&gt;@TomYoung&lt;/a&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Dec 2023 17:06:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-articles/nominated-discussion-move-firewall-to-new-panorama/ta-p/570874</guid>
      <dc:creator>JayGolf</dc:creator>
      <dc:date>2023-12-26T17:06:17Z</dc:date>
    </item>
    <item>
      <title>Re: Nominated Discussion: Move Firewall to New Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/general-articles/nominated-discussion-move-firewall-to-new-panorama/tac-p/570885#M692</link>
      <description>&lt;P&gt;Thanks &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/220841"&gt;@JayGolf&lt;/a&gt; !&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Check out the post in the link above or below.&amp;nbsp; &lt;A href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/167427" target="_blank"&gt;@securehops&lt;/A&gt; has posted 5 "load config partial" commands that we used!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/general-topics/move-firewall-to-new-panorama/m-p/539747" target="_blank"&gt;https://live.paloaltonetworks.com/t5/general-topics/move-firewall-to-new-panorama/m-p/539747&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Tue, 26 Dec 2023 17:47:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-articles/nominated-discussion-move-firewall-to-new-panorama/tac-p/570885#M692</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-12-26T17:47:34Z</dc:date>
    </item>
  </channel>
</rss>

