<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Panorama migration from M-100 to M-200 in Panorama Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-migration-from-m-100-to-m-200/m-p/482199#M855</link>
    <description>&lt;P&gt;Dear Community,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;on weekend, I was migrating M-100 to M-200 and though it might be beneficial to share how it went.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Migration scenario:&lt;/P&gt;
&lt;P&gt;2x M-100 in HA in Panorama Mode + 2 log collector groups (1 group for M-500 log collectors and 1 group fop M-600 log collectors). The target was to replace 2x M-100 with 2x M-200 with minimum impact and with no other change in configuration or design.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Migration steps:&lt;/P&gt;
&lt;P&gt;1.) I installed both M-200 with basic settings (management interface IP address/DNS setting/NTP setting/Time Zone/Hostname), added&amp;nbsp;&lt;/P&gt;
&lt;DIV data-pm-slice="1 1 []" data-en-clipboard="true"&gt;support license/device management license and upgraded to the same PAN-OS/Threat &amp;amp; Application/Antivirus version as old M-100.&lt;/DIV&gt;
&lt;DIV data-pm-slice="1 1 []" data-en-clipboard="true"&gt;2.) I exported running configuration from both M-100 and modified both configuration xml files to change management IP address to the one used by M-200 and I changed&amp;nbsp;high-availability encryption from yes to no, then I imported each respective running configuration into both M-200 and loaded the configuration file. While loading the configuration files, I kept all options deselected except of: "Retain rule UUID", then I committed it in both M-200 units. During commit, I got 2 warnings for each log collector group: "Disk 'A' on log collector &amp;lt;S/N&amp;gt; in group &amp;lt;log collector name&amp;gt; has a size of zero bytes".&lt;/DIV&gt;
&lt;DIV data-pm-slice="1 1 []" data-en-clipboard="true"&gt;3.) After the commit was completed, I exported HA key from from each M-200 unit and imported to each other, then I enabled again HA encryption in each unit under:&amp;nbsp;Panorama &amp;gt; High Availability &amp;gt; Setup &amp;gt; Encryption Enabled. After final commit, the HA was functional. I moved on to basic check to make sure all is in place, then I moved to cut over.&lt;BR /&gt;4.) For the actual migration, I shut down old M-100 units and changed management interface IP address of each M-200 to be the same as what M-100 was using. I reflected IP address change in HA setting. After I have committed the change, I have seen that all managed Firewalls appeared to be connected with status for Device Group/Template Stack in sync. The only part that did not go according to plan were log collectors. Although the status for all log collectors was connected, the status was "out of sync" with "Ring version mismatch". I was not able to commit the change to log collectors. It was giving me an error: "Config push failed as one or more disks have a size of zero bytes".&lt;/DIV&gt;
&lt;DIV data-pm-slice="1 1 []" data-en-clipboard="true"&gt;5.) To resolve the above issue, I set the log collector group (I used the same name as what was imported from M-100):&amp;nbsp;set log-collector-group &amp;lt;log collector group name&amp;gt;, then I assigned each of the log collector that belong to particular log collector group: "set log-collector-group &amp;lt;log collector group name&amp;gt; logfwd-setting collectors &amp;lt;log collector S/N&amp;gt;". After this change was committed, all log collectors changed status to: "in sync" and I was able to push configuration change to both log collectors, then I was able to see all new logs to come as well as all old logs from all log collectors.&lt;/DIV&gt;
&lt;DIV data-pm-slice="1 1 []" data-en-clipboard="true"&gt;Since, there was no issue with pushing configuration, running reports and log search, I closed the migration with no other issue left to troubleshoot.&lt;/DIV&gt;
&lt;DIV data-pm-slice="1 1 []" data-en-clipboard="true"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV data-pm-slice="1 1 []" data-en-clipboard="true"&gt;I hope this can help others with similar scenario where Panorama manager has to be replaced while log collectors stay in place.&lt;/DIV&gt;
&lt;DIV data-pm-slice="1 1 []" data-en-clipboard="true"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV data-pm-slice="1 1 []" data-en-clipboard="true"&gt;Kind Regards&lt;/DIV&gt;
&lt;DIV data-pm-slice="1 1 []" data-en-clipboard="true"&gt;Pavel&lt;/DIV&gt;</description>
    <pubDate>Tue, 17 Oct 2023 12:02:05 GMT</pubDate>
    <dc:creator>PavelK</dc:creator>
    <dc:date>2023-10-17T12:02:05Z</dc:date>
    <item>
      <title>Panorama migration from M-100 to M-200</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-migration-from-m-100-to-m-200/m-p/482199#M855</link>
      <description>&lt;P&gt;Dear Community,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;on weekend, I was migrating M-100 to M-200 and though it might be beneficial to share how it went.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Migration scenario:&lt;/P&gt;
&lt;P&gt;2x M-100 in HA in Panorama Mode + 2 log collector groups (1 group for M-500 log collectors and 1 group fop M-600 log collectors). The target was to replace 2x M-100 with 2x M-200 with minimum impact and with no other change in configuration or design.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Migration steps:&lt;/P&gt;
&lt;P&gt;1.) I installed both M-200 with basic settings (management interface IP address/DNS setting/NTP setting/Time Zone/Hostname), added&amp;nbsp;&lt;/P&gt;
&lt;DIV data-pm-slice="1 1 []" data-en-clipboard="true"&gt;support license/device management license and upgraded to the same PAN-OS/Threat &amp;amp; Application/Antivirus version as old M-100.&lt;/DIV&gt;
&lt;DIV data-pm-slice="1 1 []" data-en-clipboard="true"&gt;2.) I exported running configuration from both M-100 and modified both configuration xml files to change management IP address to the one used by M-200 and I changed&amp;nbsp;high-availability encryption from yes to no, then I imported each respective running configuration into both M-200 and loaded the configuration file. While loading the configuration files, I kept all options deselected except of: "Retain rule UUID", then I committed it in both M-200 units. During commit, I got 2 warnings for each log collector group: "Disk 'A' on log collector &amp;lt;S/N&amp;gt; in group &amp;lt;log collector name&amp;gt; has a size of zero bytes".&lt;/DIV&gt;
&lt;DIV data-pm-slice="1 1 []" data-en-clipboard="true"&gt;3.) After the commit was completed, I exported HA key from from each M-200 unit and imported to each other, then I enabled again HA encryption in each unit under:&amp;nbsp;Panorama &amp;gt; High Availability &amp;gt; Setup &amp;gt; Encryption Enabled. After final commit, the HA was functional. I moved on to basic check to make sure all is in place, then I moved to cut over.&lt;BR /&gt;4.) For the actual migration, I shut down old M-100 units and changed management interface IP address of each M-200 to be the same as what M-100 was using. I reflected IP address change in HA setting. After I have committed the change, I have seen that all managed Firewalls appeared to be connected with status for Device Group/Template Stack in sync. The only part that did not go according to plan were log collectors. Although the status for all log collectors was connected, the status was "out of sync" with "Ring version mismatch". I was not able to commit the change to log collectors. It was giving me an error: "Config push failed as one or more disks have a size of zero bytes".&lt;/DIV&gt;
&lt;DIV data-pm-slice="1 1 []" data-en-clipboard="true"&gt;5.) To resolve the above issue, I set the log collector group (I used the same name as what was imported from M-100):&amp;nbsp;set log-collector-group &amp;lt;log collector group name&amp;gt;, then I assigned each of the log collector that belong to particular log collector group: "set log-collector-group &amp;lt;log collector group name&amp;gt; logfwd-setting collectors &amp;lt;log collector S/N&amp;gt;". After this change was committed, all log collectors changed status to: "in sync" and I was able to push configuration change to both log collectors, then I was able to see all new logs to come as well as all old logs from all log collectors.&lt;/DIV&gt;
&lt;DIV data-pm-slice="1 1 []" data-en-clipboard="true"&gt;Since, there was no issue with pushing configuration, running reports and log search, I closed the migration with no other issue left to troubleshoot.&lt;/DIV&gt;
&lt;DIV data-pm-slice="1 1 []" data-en-clipboard="true"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV data-pm-slice="1 1 []" data-en-clipboard="true"&gt;I hope this can help others with similar scenario where Panorama manager has to be replaced while log collectors stay in place.&lt;/DIV&gt;
&lt;DIV data-pm-slice="1 1 []" data-en-clipboard="true"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV data-pm-slice="1 1 []" data-en-clipboard="true"&gt;Kind Regards&lt;/DIV&gt;
&lt;DIV data-pm-slice="1 1 []" data-en-clipboard="true"&gt;Pavel&lt;/DIV&gt;</description>
      <pubDate>Tue, 17 Oct 2023 12:02:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-migration-from-m-100-to-m-200/m-p/482199#M855</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2023-10-17T12:02:05Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama migration from M-100 to M-200</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-migration-from-m-100-to-m-200/m-p/533722#M1399</link>
      <description>&lt;P&gt;I had a different scenario for my LCs after upgrading the Panoramas but got the same&amp;nbsp;&lt;SPAN&gt;"Config push failed as one or more disks have a size of zero bytes".&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Your step 5 fixed it for me as well. Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 09 Mar 2023 02:11:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-migration-from-m-100-to-m-200/m-p/533722#M1399</guid>
      <dc:creator>Nathan_Rohrlach</dc:creator>
      <dc:date>2023-03-09T02:11:01Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama migration from M-100 to M-200</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-migration-from-m-100-to-m-200/m-p/562049#M1937</link>
      <description>&lt;P&gt;Hi Kavel,&lt;/P&gt;
&lt;P&gt;Do not mind me asking, the &lt;SPAN&gt;support license/device management license uploaded to the new panorama, is it a new license or a migration license obtained from Palo Alto?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thank you&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Alex&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2023 09:29:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-migration-from-m-100-to-m-200/m-p/562049#M1937</guid>
      <dc:creator>alexander</dc:creator>
      <dc:date>2023-10-17T09:29:56Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama migration from M-100 to M-200</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-migration-from-m-100-to-m-200/m-p/562065#M1938</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/29820"&gt;@alexander&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks for message!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regarding device management license, when I was ordering M-200, I asked for below migration license which did not cost anything and allowed me to convert existing M-100 device management license to M-200.&lt;/P&gt;
&lt;P&gt;PAN-M-200-P-MIG-M100-M200-1K (Panorama license migration from M-100 to M-200, 1K devices)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regarding support, M-200 came with own support. There was no possibility to make transfer from M-100.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2023 12:10:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-migration-from-m-100-to-m-200/m-p/562065#M1938</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2023-10-17T12:10:00Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama migration from M-100 to M-200</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-migration-from-m-100-to-m-200/m-p/562325#M1949</link>
      <description>&lt;P&gt;Hello Pavel,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for the reply.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If i get what you are saying, the migration license is only needed if you have some period left and do not intend to buy a new license.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If the new panorama comes with a new set of device management license that should work as well. Also allow me to clarify, once you've switch the management interface from the old panorama to the new panorama, the devices in the managed device summary will automatically show connected am i right?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Alex&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2023 01:53:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-migration-from-m-100-to-m-200/m-p/562325#M1949</guid>
      <dc:creator>alexander</dc:creator>
      <dc:date>2023-10-19T01:53:07Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama migration from M-100 to M-200</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-migration-from-m-100-to-m-200/m-p/562487#M1952</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/29820"&gt;@alexander&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thank you for reply.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The device management license is perpetual. It does not have any expiration. By using conversion SKU you can save money by not ordering device management license in new Panorama. If you already have&amp;nbsp;device management license in new Panorama, then you do not need to go for conversion.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regarding second question, the answer is yes. It was smooth. All Firewalls showed up as connected within a minute after management interface change. Please note that I have done this migration with PAN-OS 9.1 that did not have secure onboarding yet.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2023 21:12:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-migration-from-m-100-to-m-200/m-p/562487#M1952</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2023-10-19T21:12:03Z</dc:date>
    </item>
  </channel>
</rss>

