<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Migration Issue from PA-500 (HA-Active/passive) to PA-3220 with HA-Active/Passive in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/migration-issue-from-pa-500-ha-active-passive-to-pa-3220-with-ha/m-p/511542#M106344</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hi Brothers,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Existing PA-500 (PAN-OS 8.1.17) and New PA-3220&amp;nbsp;(PAN-OS 8.1.17)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I tried to export the running config from FW (PA-500) as XML format and import it into the new FW (PA-3220)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Shows me a lot of error and warning as there is a lot of&amp;nbsp;discrepancies as following&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Details&lt;BR /&gt;Validation Error:&lt;BR /&gt;deviceconfig -&amp;gt; high-availability -&amp;gt; interface -&amp;gt; ha1 -&amp;gt; port 'ethernet1/7' is not an allowed keyword&lt;BR /&gt;deviceconfig -&amp;gt; high-availability -&amp;gt; interface -&amp;gt; ha1 -&amp;gt; port is invalid&lt;BR /&gt;deviceconfig -&amp;gt; high-availability -&amp;gt; interface -&amp;gt; ha1 is invalid&lt;BR /&gt;deviceconfig -&amp;gt; high-availability -&amp;gt; interface is invalid&lt;BR /&gt;deviceconfig -&amp;gt; high-availability is invalid&lt;BR /&gt;deviceconfig is invalid&lt;BR /&gt;tag -&amp;gt; Static NAT 'Static NAT' is already in use&lt;BR /&gt;tag -&amp;gt; Hide NAT 'Hide NAT' is already in use&lt;BR /&gt;tag -&amp;gt; NONAT 'NONAT' is already in use&lt;BR /&gt;tag -&amp;gt; Static NAT 'Static NAT' is already in use&lt;BR /&gt;tag -&amp;gt; Hide NAT 'Hide NAT' is already in use&lt;BR /&gt;tag -&amp;gt; NONAT 'NONAT' is already in use&lt;BR /&gt;tag is invalid&lt;BR /&gt;vsys is invalid&lt;BR /&gt;devices is invalid&lt;BR /&gt;Config 'WHDEV':&lt;BR /&gt;GlobalProtect App Dynamic Configuration misses information for 'uninstall'.&lt;BR /&gt;(Module: sslvpn)&lt;BR /&gt;Configuration is invalid&lt;BR /&gt;Warnings&lt;BR /&gt;Duplicate certificate subject found:&lt;BR /&gt;/CN=*.whitedriveproducts.com&lt;BR /&gt;Certificate WH_PTGW_Cert in shared expired on Apr 12 23:59:59 2022 GMT&lt;BR /&gt;vsys1&lt;BR /&gt;Warning: certificate chain not correctly formed in certificate wildcard.whitedriveproducts.com&lt;BR /&gt;vsys1: Rule 'whitedriveproducts.sharepoint.com' application dependency warning:&lt;BR /&gt;Application 'ms-office365-base' requires 'web-browsing' be allowed, but 'web-browsing' is denied in Rule 'deny_host_hopts02.wh.corp_all_other'&lt;BR /&gt;vsys1: Rule 'whitedriveproducts.sharepoint.com_external_resources' application dependency warning:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there any recommended solution to solve the issue or should i do it manually?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 11 Aug 2022 09:08:30 GMT</pubDate>
    <dc:creator>Mohammed_Alalawi</dc:creator>
    <dc:date>2022-08-11T09:08:30Z</dc:date>
    <item>
      <title>Migration Issue from PA-500 (HA-Active/passive) to PA-3220 with HA-Active/Passive</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/migration-issue-from-pa-500-ha-active-passive-to-pa-3220-with-ha/m-p/511542#M106344</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hi Brothers,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Existing PA-500 (PAN-OS 8.1.17) and New PA-3220&amp;nbsp;(PAN-OS 8.1.17)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I tried to export the running config from FW (PA-500) as XML format and import it into the new FW (PA-3220)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Shows me a lot of error and warning as there is a lot of&amp;nbsp;discrepancies as following&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Details&lt;BR /&gt;Validation Error:&lt;BR /&gt;deviceconfig -&amp;gt; high-availability -&amp;gt; interface -&amp;gt; ha1 -&amp;gt; port 'ethernet1/7' is not an allowed keyword&lt;BR /&gt;deviceconfig -&amp;gt; high-availability -&amp;gt; interface -&amp;gt; ha1 -&amp;gt; port is invalid&lt;BR /&gt;deviceconfig -&amp;gt; high-availability -&amp;gt; interface -&amp;gt; ha1 is invalid&lt;BR /&gt;deviceconfig -&amp;gt; high-availability -&amp;gt; interface is invalid&lt;BR /&gt;deviceconfig -&amp;gt; high-availability is invalid&lt;BR /&gt;deviceconfig is invalid&lt;BR /&gt;tag -&amp;gt; Static NAT 'Static NAT' is already in use&lt;BR /&gt;tag -&amp;gt; Hide NAT 'Hide NAT' is already in use&lt;BR /&gt;tag -&amp;gt; NONAT 'NONAT' is already in use&lt;BR /&gt;tag -&amp;gt; Static NAT 'Static NAT' is already in use&lt;BR /&gt;tag -&amp;gt; Hide NAT 'Hide NAT' is already in use&lt;BR /&gt;tag -&amp;gt; NONAT 'NONAT' is already in use&lt;BR /&gt;tag is invalid&lt;BR /&gt;vsys is invalid&lt;BR /&gt;devices is invalid&lt;BR /&gt;Config 'WHDEV':&lt;BR /&gt;GlobalProtect App Dynamic Configuration misses information for 'uninstall'.&lt;BR /&gt;(Module: sslvpn)&lt;BR /&gt;Configuration is invalid&lt;BR /&gt;Warnings&lt;BR /&gt;Duplicate certificate subject found:&lt;BR /&gt;/CN=*.whitedriveproducts.com&lt;BR /&gt;Certificate WH_PTGW_Cert in shared expired on Apr 12 23:59:59 2022 GMT&lt;BR /&gt;vsys1&lt;BR /&gt;Warning: certificate chain not correctly formed in certificate wildcard.whitedriveproducts.com&lt;BR /&gt;vsys1: Rule 'whitedriveproducts.sharepoint.com' application dependency warning:&lt;BR /&gt;Application 'ms-office365-base' requires 'web-browsing' be allowed, but 'web-browsing' is denied in Rule 'deny_host_hopts02.wh.corp_all_other'&lt;BR /&gt;vsys1: Rule 'whitedriveproducts.sharepoint.com_external_resources' application dependency warning:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there any recommended solution to solve the issue or should i do it manually?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Aug 2022 09:08:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/migration-issue-from-pa-500-ha-active-passive-to-pa-3220-with-ha/m-p/511542#M106344</guid>
      <dc:creator>Mohammed_Alalawi</dc:creator>
      <dc:date>2022-08-11T09:08:30Z</dc:date>
    </item>
    <item>
      <title>Re: Migration Issue from PA-500 (HA-Active/passive) to PA-3220 with HA-Active/Passive</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/migration-issue-from-pa-500-ha-active-passive-to-pa-3220-with-ha/m-p/511868#M106389</link>
      <description>&lt;P&gt;Hello there.&lt;BR /&gt;&lt;BR /&gt;It appears that the 3220 already has a configuration on it.&amp;nbsp; Why else would be errors like "tag already in use"&lt;BR /&gt;I would ensure that you have NO configuration on 3220 (other than mgmt IP), i.e, a blank config.&lt;BR /&gt;If it was me, I would clean up the configuration (expired certificate would be deleted) and other manual steps and then I would try commit.&amp;nbsp; These errors look very simple to fix.&amp;nbsp; Five minutes of work at the most.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Good luck.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Aug 2022 15:54:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/migration-issue-from-pa-500-ha-active-passive-to-pa-3220-with-ha/m-p/511868#M106389</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2022-08-15T15:54:25Z</dc:date>
    </item>
    <item>
      <title>Re: Migration Issue from PA-500 (HA-Active/passive) to PA-3220 with HA-Active/Passive</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/migration-issue-from-pa-500-ha-active-passive-to-pa-3220-with-ha/m-p/511976#M106415</link>
      <description>&lt;P&gt;is the pa500 have a lot configuration?&lt;BR /&gt;if no, you can do it manually,&lt;/P&gt;
&lt;P&gt;otherwise, you can try using palo alto migration tool (expedition)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Aug 2022 09:03:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/migration-issue-from-pa-500-ha-active-passive-to-pa-3220-with-ha/m-p/511976#M106415</guid>
      <dc:creator>DennyChanditya</dc:creator>
      <dc:date>2022-08-16T09:03:01Z</dc:date>
    </item>
  </channel>
</rss>

