<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Impossible to migrate an ae interface to a different speed in Panorama? in Panorama Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/panorama-discussions/impossible-to-migrate-an-ae-interface-to-a-different-speed-in/m-p/1256304#M3102</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/451289429"&gt;@J.Morgan425685&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thank you for posting!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Unfortunately, I have not done this exact the same operation before, so I can't speak for my own experience, however I spent some time to go through KB articles and documentation. I did not come across any article that reassembles concern of your customer. While there are some limitations what can be configured with AE interfaces from Panorama:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000scQKCAY" target="_self"&gt;Firewall commit failing with error "aeX 'aeX' is invalid" when new Aggregate Ethernet configuration is pushed from Panorama&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000g1QrCAI" target="_self"&gt;Push from Panorama to Firewall fails due to invalid configuration - poe is invalid. Not a PoE port&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;this operation is fully supported: &amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/ngfw/networking/configure-interfaces/configure-an-aggregate-interface-group" target="_self"&gt;Configure an Aggregate Interface Group&lt;/A&gt;. Especially taking into consideration your customer will arrange maintenance window, I do not see any blocker. If you get an error while committing or pushing configuration to managed Firewall, I would start troubleshooting here based on actual error. In the case you run into an issue with configuration / pushing errors, below commands are helpful to drill down the issue:&lt;/P&gt;
&lt;P&gt;Panorama side: mp-log configd.log&lt;/P&gt;
&lt;P&gt;Firewall side: mp-log devsrv.log&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 14 Jun 2026 05:13:50 GMT</pubDate>
    <dc:creator>PavelK</dc:creator>
    <dc:date>2026-06-14T05:13:50Z</dc:date>
    <item>
      <title>Impossible to migrate an ae interface to a different speed in Panorama?</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/impossible-to-migrate-an-ae-interface-to-a-different-speed-in/m-p/1256031#M3100</link>
      <description>&lt;P&gt;Quite new to Panorama, but have been working with Palo Alto standalone firewalls for a little while.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Client has 2 Active Passive HA FW's in Panorama and an ae1 interface with 4x 1G interfaces as members.&lt;/P&gt;
&lt;P&gt;They want to switch this to 4x of the 10G interfaces during an outage window.&lt;/P&gt;
&lt;P&gt;Am I right that I should be able to just remove the 4x 1G members, add the 4x 10G members in the template in panorama and the commit to the devices?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Client seems to think that this isn't possible, they read somewhere Panorama wont allow it - apparently some sort of order of operations issue where it wont work due to the mixed speeds, though at no point would we have a mix of interfaces at the same time, but they can't find where they read the supposed article. They believe an export, manual config edit and import is the only way...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Has anyone done this exact change and can confirm ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jun 2026 04:57:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/impossible-to-migrate-an-ae-interface-to-a-different-speed-in/m-p/1256031#M3100</guid>
      <dc:creator>J.Morgan425685</dc:creator>
      <dc:date>2026-06-11T04:57:27Z</dc:date>
    </item>
    <item>
      <title>Re: Impossible to migrate an ae interface to a different speed in Panorama?</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/impossible-to-migrate-an-ae-interface-to-a-different-speed-in/m-p/1256304#M3102</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/451289429"&gt;@J.Morgan425685&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thank you for posting!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Unfortunately, I have not done this exact the same operation before, so I can't speak for my own experience, however I spent some time to go through KB articles and documentation. I did not come across any article that reassembles concern of your customer. While there are some limitations what can be configured with AE interfaces from Panorama:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000scQKCAY" target="_self"&gt;Firewall commit failing with error "aeX 'aeX' is invalid" when new Aggregate Ethernet configuration is pushed from Panorama&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000g1QrCAI" target="_self"&gt;Push from Panorama to Firewall fails due to invalid configuration - poe is invalid. Not a PoE port&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;this operation is fully supported: &amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/ngfw/networking/configure-interfaces/configure-an-aggregate-interface-group" target="_self"&gt;Configure an Aggregate Interface Group&lt;/A&gt;. Especially taking into consideration your customer will arrange maintenance window, I do not see any blocker. If you get an error while committing or pushing configuration to managed Firewall, I would start troubleshooting here based on actual error. In the case you run into an issue with configuration / pushing errors, below commands are helpful to drill down the issue:&lt;/P&gt;
&lt;P&gt;Panorama side: mp-log configd.log&lt;/P&gt;
&lt;P&gt;Firewall side: mp-log devsrv.log&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 14 Jun 2026 05:13:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/impossible-to-migrate-an-ae-interface-to-a-different-speed-in/m-p/1256304#M3102</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2026-06-14T05:13:50Z</dc:date>
    </item>
  </channel>
</rss>

