<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to Migrate of existing config / rules from PA-3020 in a HA pair to PA-460 in a HA Pair in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-migrate-of-existing-config-rules-from-pa-3020-in-a-ha/m-p/459796#M102010</link>
    <description>&lt;P&gt;How to Migrate of existing config / rules from PA-3020 in a HA pair to PA-460 in a HA Pair?&lt;/P&gt;</description>
    <pubDate>Thu, 20 Jan 2022 13:30:57 GMT</pubDate>
    <dc:creator>ChirPatel</dc:creator>
    <dc:date>2022-01-20T13:30:57Z</dc:date>
    <item>
      <title>How to Migrate of existing config / rules from PA-3020 in a HA pair to PA-460 in a HA Pair</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-migrate-of-existing-config-rules-from-pa-3020-in-a-ha/m-p/459796#M102010</link>
      <description>&lt;P&gt;How to Migrate of existing config / rules from PA-3020 in a HA pair to PA-460 in a HA Pair?&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jan 2022 13:30:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-migrate-of-existing-config-rules-from-pa-3020-in-a-ha/m-p/459796#M102010</guid>
      <dc:creator>ChirPatel</dc:creator>
      <dc:date>2022-01-20T13:30:57Z</dc:date>
    </item>
    <item>
      <title>Re: How to Migrate of existing config / rules from PA-3020 in a HA pair to PA-460 in a HA Pair</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-migrate-of-existing-config-rules-from-pa-3020-in-a-ha/m-p/459818#M102013</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/114701"&gt;@ChirPatel&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;The only real "issue" that you'll run into is interface changes if you're using interfaces on the PA-3020 that don't exist on the PA-460; not really an issue since you can just update that interface information in the GUI or find/replace it in the XML configuration file before you load it onto the PA-460. (IE: You're using ethernet1/18 on the PA-3020 that won't exist on the PA-460).&lt;/P&gt;
&lt;P&gt;The actual configuration migration however can just be exported and loaded without issue. The validation process will catch anything that won't actually function on the PA-460 (like that interface problem mentioned above), so that you can go through and correct any of that.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm partial to actually going through the configuration once you have it loaded on the PA-460 and ensuring that everything inputted is actually still needed. Hardware migrations are always a good time to verify that you don't have any unused objects configured, or any rulebase entries that aren't actually needed anymore.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Take a look at this migration guide:&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/content/dam/techdocs/en_US/pdf/hardware/migration/firewall-migration-guide.pdf" target="_blank"&gt;https://docs.paloaltonetworks.com/content/dam/techdocs/en_US/pdf/hardware/migration/firewall-migration-guide.pdf&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jan 2022 15:16:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-migrate-of-existing-config-rules-from-pa-3020-in-a-ha/m-p/459818#M102013</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2022-01-20T15:16:00Z</dc:date>
    </item>
    <item>
      <title>Re: How to Migrate of existing config / rules from PA-3020 in a HA pair to PA-460 in a HA Pair</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-migrate-of-existing-config-rules-from-pa-3020-in-a-ha/m-p/466151#M102656</link>
      <description>&lt;P&gt;Thanks That worked for us, few issues related to HA port, Log allocation, barring that everything worked.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Feb 2022 11:35:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-migrate-of-existing-config-rules-from-pa-3020-in-a-ha/m-p/466151#M102656</guid>
      <dc:creator>ChirPatel</dc:creator>
      <dc:date>2022-02-16T11:35:38Z</dc:date>
    </item>
    <item>
      <title>Re: How to Migrate of existing config / rules from PA-3020 in a HA pair to PA-460 in a HA Pair</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-migrate-of-existing-config-rules-from-pa-3020-in-a-ha/m-p/512710#M106523</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;- when upgrading PA-3020 to PA-460, how might one be able to satisfy the PanOS requirement as device state restoration is required for migrations, when configurations are heavily managed via panorama policies?&lt;/P&gt;
&lt;P&gt;pa-3020 max ver- 9.1.x&lt;/P&gt;
&lt;P&gt;pa-460 min ver - 10.1.x&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Determine the target PAN‐OS release—Before you Migrate to New Firewalls, ensure that the old&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;firewall is running the same PAN‐OS release and the same content release version as is installed on the&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;new firewall. If the old firewall does not support the PAN‐OS release that is installed on the new&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;firewall, you must ensure that the old firewall is no more than one feature release behind. For example,&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;if the new firewall is running PAN‐OS 8.0, then the old firewall must be running or upgraded to a&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;PAN‐OS 7.1 release before you migrate. If the old and new firewalls are not within one feature release,&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;you cannot use the device state export and import process to migrate due to schema changes that occur&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;from feature release to feature release.&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Aug 2022 17:09:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-migrate-of-existing-config-rules-from-pa-3020-in-a-ha/m-p/512710#M106523</guid>
      <dc:creator>BrianThomas</dc:creator>
      <dc:date>2022-08-23T17:09:37Z</dc:date>
    </item>
    <item>
      <title>Re: How to Migrate of existing config / rules from PA-3020 in a HA pair to PA-460 in a HA Pair</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-migrate-of-existing-config-rules-from-pa-3020-in-a-ha/m-p/512722#M106525</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/90457"&gt;@BrianThomas&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;I don't use device states since my configurations are kept in XML format and directly modified. I'm&amp;nbsp;&lt;EM&gt;guessing&amp;nbsp;&lt;/EM&gt;since I don't have the lab equipment multiple versions behind like that to validate, but you should still be able to do exactly as you would with just the configuration export/import process. Import the device state and correct the validation errors that will be present following the import due to the version difference.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Aug 2022 18:27:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-migrate-of-existing-config-rules-from-pa-3020-in-a-ha/m-p/512722#M106525</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2022-08-23T18:27:35Z</dc:date>
    </item>
  </channel>
</rss>

