<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Migration / Import of configuration only to a destination vsys, a particular vsys in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/migration-import-of-configuration-only-to-a-destination-vsys-a/m-p/511389#M106314</link>
    <description>&lt;P&gt;Look into the&amp;nbsp;&lt;EM&gt;load config partial&amp;nbsp;&lt;/EM&gt;command and its various options. Assuming that you are familiar with xpath this is an easy option that doesn't require you to manually modify the configuration file or utilize the Expedition tool. Expedition is the only option that I'm aware of that would let you do this easy enough without required knowledge of XML and the actual configuration file.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 10 Aug 2022 02:27:35 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2022-08-10T02:27:35Z</dc:date>
    <item>
      <title>Migration / Import of configuration only to a destination vsys, a particular vsys</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/migration-import-of-configuration-only-to-a-destination-vsys-a/m-p/511286#M106298</link>
      <description>&lt;P&gt;Migration / Import of configuration only to a destination Vsys, a particular vsys.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hello good afternoon, as always thank you very much for the support and collaboration as always. Please your your suggestions, advice and / or guidance, how is it possible to perform the import/load config, of a PA configuration, to be loaded only, but only in a vsys( vsys4 ) without touching anything of the rest of vsys of the firewall, just import and load that configuration to the vsys4 ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Environment/Infra:&lt;/P&gt;
&lt;P&gt;PA-5250 Physical Firewall - HA&lt;/P&gt;
&lt;P&gt;Vsys1 ready and OK&lt;/P&gt;
&lt;P&gt;Vsys2 ready and OK&lt;/P&gt;
&lt;P&gt;Vsys3 ready and OK.&lt;/P&gt;
&lt;P&gt;Vys4 created, without any configuration, but waiting for the configuration.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you, I remain attentive, best regards&lt;/P&gt;</description>
      <pubDate>Tue, 09 Aug 2022 02:23:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/migration-import-of-configuration-only-to-a-destination-vsys-a/m-p/511286#M106298</guid>
      <dc:creator>Metgatz</dc:creator>
      <dc:date>2022-08-09T02:23:14Z</dc:date>
    </item>
    <item>
      <title>Re: Migration / Import of configuration only to a destination vsys, a particular vsys</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/migration-import-of-configuration-only-to-a-destination-vsys-a/m-p/511389#M106314</link>
      <description>&lt;P&gt;Look into the&amp;nbsp;&lt;EM&gt;load config partial&amp;nbsp;&lt;/EM&gt;command and its various options. Assuming that you are familiar with xpath this is an easy option that doesn't require you to manually modify the configuration file or utilize the Expedition tool. Expedition is the only option that I'm aware of that would let you do this easy enough without required knowledge of XML and the actual configuration file.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Aug 2022 02:27:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/migration-import-of-configuration-only-to-a-destination-vsys-a/m-p/511389#M106314</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2022-08-10T02:27:35Z</dc:date>
    </item>
    <item>
      <title>Re: Migration / Import of configuration only to a destination vsys, a particular vsys</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/migration-import-of-configuration-only-to-a-destination-vsys-a/m-p/511406#M106318</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/179185"&gt;@Metgatz&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;I would agree with &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt; and tried to expand a little. I recently used the "load partial config" feature and must say it is fantastic!&lt;/P&gt;
&lt;P&gt;There is some nice documentations explaining how to use the command:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-cli-quick-start/use-the-cli/load-configurations/load-a-partial-configuration" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-cli-quick-start/use-the-cli/load-configurations/load-a-partial-configuration&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/manage-firewalls/transition-a-firewall-to-panorama-management/load-a-partial-firewall-configuration-into-panorama" target="_blank"&gt;https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/manage-firewalls/transition-a-firewall-to-panorama-management/load-a-partial-firewall-configuration-into-panorama&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClbLCAS" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClbLCAS&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There you can also find instructions how to get the correct xpath for each part of the configuration.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now let note that "load partial config" can be used only if you have your configuration in XML format. From your post I assume you already have&amp;nbsp; complete FW config in XML format.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would assume that you want to migrate single firewall as new vsys to existing firewall. In that case I would suggest the following:&lt;/P&gt;
&lt;P&gt;- Export running config from the firewall that will be migrated. And save it with different name from "running-config.xml"&lt;/P&gt;
&lt;P&gt;- Import that file to the firewall with the VSYSs. Only import it, do not load it. You can do that via the GUI. FW will save this xml and list it under saved configs.&lt;/P&gt;
&lt;P&gt;- Using the API browser (explained in the links above) get the xpath for the relevant config you want to import. Depending on what configuration you want to keep and what want to ignore you can use xpaths for specific config only - address, address-groups, security policy rules, etc. Or more generic like all network settings&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Aug 2022 07:41:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/migration-import-of-configuration-only-to-a-destination-vsys-a/m-p/511406#M106318</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2022-08-10T07:41:16Z</dc:date>
    </item>
  </channel>
</rss>

