<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HA Firewall Device Migration/Hardware Swap in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ha-firewall-device-migration-hardware-swap/m-p/458423#M101902</link>
    <description>&lt;P&gt;Thank you for your detailed response, unfortunately it landed in my Spam folder for a week. We came to a similar conclusion to your's independently, you provided useful additional info, and validated our similar approach.&lt;/P&gt;</description>
    <pubDate>Wed, 12 Jan 2022 19:00:18 GMT</pubDate>
    <dc:creator>Akeakamai</dc:creator>
    <dc:date>2022-01-12T19:00:18Z</dc:date>
    <item>
      <title>HA Firewall Device Migration/Hardware Swap</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-firewall-device-migration-hardware-swap/m-p/456292#M101696</link>
      <description>&lt;P&gt;Need to replace an HA pair of Panorama managed, currently deployed firewalls (PA-5220s) with a different pair of Panorama managed&amp;nbsp; firewalls (also PA-5220s), with minimum/no downtime; device licensing is different between #1 &amp;amp; #2 pairs, necessitating the swap.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Proposed procedure (detailed in attached picture)&lt;/P&gt;&lt;P&gt;- Copy Panorama DG/Template for HA pair #1 to replacement DG/Template for HA pair #2&lt;BR /&gt;- Push Panorama config to HA pair #2&lt;BR /&gt;- Replace current passive firewall (1b) with it's replacement (2d), sync sessions&lt;/P&gt;&lt;P&gt;- Swap HA roles (1b is now active)&lt;/P&gt;&lt;P&gt;- Replace current passive firewall (1a) with it's replacement (2c)&lt;/P&gt;&lt;P&gt;- Swap HA roles&lt;/P&gt;&lt;P&gt;- Delete DG/Template #1&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Hardware is identical (HA requires this)&lt;/P&gt;&lt;P&gt;HA configs are identical: timers, peer IP addresses, etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyone see issues with the proposed procedure? Suggestions for alternative procedure?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thought about using Panorama RMA procedure to just replace #1 firewalls one at a time and using HA to minimize downtime, maybe similar to above, start by serial number swap for passive firewall, HA swap, replace serial number for formerly active device, swap, etc hardware&lt;/P&gt;</description>
      <pubDate>Sat, 01 Jan 2022 02:33:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-firewall-device-migration-hardware-swap/m-p/456292#M101696</guid>
      <dc:creator>Akeakamai</dc:creator>
      <dc:date>2022-01-01T02:33:56Z</dc:date>
    </item>
    <item>
      <title>Re: HA Firewall Device Migration/Hardware Swap</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-firewall-device-migration-hardware-swap/m-p/456430#M101719</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Why not just swap the licensing? Might be a simpler solution.&lt;/P&gt;
&lt;P&gt;Just a thought.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jan 2022 17:00:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-firewall-device-migration-hardware-swap/m-p/456430#M101719</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2022-01-03T17:00:29Z</dc:date>
    </item>
    <item>
      <title>Re: HA Firewall Device Migration/Hardware Swap</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-firewall-device-migration-hardware-swap/m-p/456554#M101734</link>
      <description>&lt;P&gt;Swapping licenses would be the easiest solution, Palo Alto told us that was not an option, hence my migration plan&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jan 2022 23:18:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-firewall-device-migration-hardware-swap/m-p/456554#M101734</guid>
      <dc:creator>Akeakamai</dc:creator>
      <dc:date>2022-01-03T23:18:54Z</dc:date>
    </item>
    <item>
      <title>Re: HA Firewall Device Migration/Hardware Swap</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-firewall-device-migration-hardware-swap/m-p/456559#M101736</link>
      <description>&lt;P&gt;Thank you for the post&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/119406"&gt;@Akeakamai&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I agree with Otakar that swapping Firewalls for license migration might be overkill, however if this step is unavoidable in your scenario, I would say your proposed procedure looks functional, however I believe this could be a bit simplified.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since you are using the same Firewalls with the identical configuration, I think you can use existing Device Group and Template Stack, so I would skip first step with cloning existing&amp;nbsp;Device Group and Template Stack.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Before you start with migration, disable HA Preemption in your existing Firewall HA pair to avoid unexpected failover during migration.&lt;/P&gt;&lt;P&gt;- Suspend in HA setting current passive firewall (1b) and disconnect all interfaces, then cable all ports in replacement firewall (2d).&lt;/P&gt;&lt;P&gt;- Upgrade&amp;nbsp;replacement firewall (2d) to the same PAN-OS version, install the same content update, install license, but keep HA as suspended.&lt;/P&gt;&lt;P&gt;- Place&amp;nbsp;replacement firewall (2d) into existing Device Group and Template Stack and push the configuration.&lt;/P&gt;&lt;P&gt;- After configuration is pushed, I would do basic verification that all setting was applied. If HA setting is configured for "auto" mode, you should at least see all interfaces to be up. Also all information under High Availability should be "Match" and HA1, HA1 Backup, HA2,... should be up.&lt;/P&gt;&lt;P&gt;- Clean/Replace old Firewall SN with new one in Panorama by:&amp;nbsp;replace device old &amp;lt;old SN#&amp;gt; new &amp;lt;new SN#&lt;/P&gt;&lt;P&gt;- If you are using BGP peering, it might be safer to temporarily configure static route as a fall back if BGP session drops during Firewall failover.&lt;/P&gt;&lt;P&gt;- If you did not get stuck or came across any issue with any of the above steps, I would make replacement firewall (2d) functional in HA and proceed with failover (make firewall (1a) suspended).&lt;/P&gt;&lt;P&gt;- If all is running fine on&amp;nbsp;firewall (2d) do the same procedure for&amp;nbsp;&lt;SPAN&gt;firewall (1a)&amp;nbsp;and replace it with firewall&amp;nbsp;(2c).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- Make&amp;nbsp;firewall&amp;nbsp;(2c) active and enable preemption if necessary.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- Clean up all the configuration that was configured temporarily for migration purpose.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- Make failover test just in case to confirm all is working as expected.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;As always unexpected thing can happen, so I would schedule this task for weekend or during time with lowest traffic. Also, I would recommend to to do bench mark connectivity test before and after replacement work to avoid falsely&amp;nbsp;troubleshooting things that were actually not functional before replacement.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Kind Regards&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Pavel&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jan 2022 23:45:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-firewall-device-migration-hardware-swap/m-p/456559#M101736</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2022-01-03T23:45:34Z</dc:date>
    </item>
    <item>
      <title>Re: HA Firewall Device Migration/Hardware Swap</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-firewall-device-migration-hardware-swap/m-p/458423#M101902</link>
      <description>&lt;P&gt;Thank you for your detailed response, unfortunately it landed in my Spam folder for a week. We came to a similar conclusion to your's independently, you provided useful additional info, and validated our similar approach.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jan 2022 19:00:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-firewall-device-migration-hardware-swap/m-p/458423#M101902</guid>
      <dc:creator>Akeakamai</dc:creator>
      <dc:date>2022-01-12T19:00:18Z</dc:date>
    </item>
    <item>
      <title>Re: HA Firewall Device Migration/Hardware Swap</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-firewall-device-migration-hardware-swap/m-p/616163#M121923</link>
      <description>&lt;P&gt;do you have any&amp;nbsp; documentation if you replace newer&amp;nbsp; HA -&amp;nbsp; &amp;nbsp;hardware ?&lt;/P&gt;</description>
      <pubDate>Tue, 05 Nov 2024 19:04:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-firewall-device-migration-hardware-swap/m-p/616163#M121923</guid>
      <dc:creator>amkolev</dc:creator>
      <dc:date>2024-11-05T19:04:25Z</dc:date>
    </item>
    <item>
      <title>Re: HA Firewall Device Migration/Hardware Swap</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-firewall-device-migration-hardware-swap/m-p/616168#M121924</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/122998"&gt;@amkolev&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks for post!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To be honest I do not think there is any difference in procedure between Firewall mentioned in this post and latest Firewalls. Some miner differences might come from features introduced in latest versions of PAN-OS.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Would you mind provide more details what your scenario / migration is?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&amp;nbsp; &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Nov 2024 21:47:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-firewall-device-migration-hardware-swap/m-p/616168#M121924</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2024-11-05T21:47:07Z</dc:date>
    </item>
    <item>
      <title>Re: HA Firewall Device Migration/Hardware Swap</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-firewall-device-migration-hardware-swap/m-p/616197#M121927</link>
      <description>&lt;P&gt;I have 5250 HA - active /passive firewalls&amp;nbsp; registered with Panorama&amp;nbsp; and the end goal is to replace them with the newer PA5420 Firewalls . How would you do it . I am fine with downtime&amp;nbsp; procedure , but would you copy the config&amp;nbsp; or you just de-register old devices&amp;nbsp; from Panorama and add the new devices and add them in the proper Device Group&amp;nbsp; and Templates . the only thing is I would like to keep same Routing and interface configuration ( Ip addresses , sub-interface&amp;nbsp; , routing etc )&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Let me know&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Nov 2024 02:41:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-firewall-device-migration-hardware-swap/m-p/616197#M121927</guid>
      <dc:creator>amkolev</dc:creator>
      <dc:date>2024-11-06T02:41:47Z</dc:date>
    </item>
    <item>
      <title>Re: HA Firewall Device Migration/Hardware Swap</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-firewall-device-migration-hardware-swap/m-p/995908#M122325</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/122998"&gt;@amkolev&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am sorry for late response.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Similar posts for Firewall migration leveraging Panorama came up in the past. Could you have a look?&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/panorama-discussions/palo-alto-5020-migrate-to-5220-from-panorama/td-p/487516" target="_blank" rel="noopener"&gt;https://live.paloaltonetworks.com/t5/panorama-discussions/palo-alto-5020-migrate-to-5220-from-panorama/td-p/487516&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/general-topics/pa-3020-to-pa-460-migration/td-p/516049" target="_blank" rel="noopener"&gt;https://live.paloaltonetworks.com/t5/general-topics/pa-3020-to-pa-460-migration/td-p/516049&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In nutshell, I would in your case place the new Firewall in the same Device Group as old Firewall. For Template Stack, I would clone old Firewall Template and adjusted new Firewall specific configuration in a new Template.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Mon, 02 Dec 2024 06:43:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-firewall-device-migration-hardware-swap/m-p/995908#M122325</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2024-12-02T06:43:02Z</dc:date>
    </item>
  </channel>
</rss>

