<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: RMA replacement in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/rma-replacement/m-p/524920#M108585</link>
    <description>&lt;P&gt;Yes, we are able to push the config by clicking the force template value. For somehow, there is a configuration error in the template that cause GUI for RMA unit cannot be access. We already log the ticket to RMA for this issue.&lt;/P&gt;
&lt;P&gt;Thanks all for your help.&lt;/P&gt;</description>
    <pubDate>Fri, 23 Dec 2022 01:59:56 GMT</pubDate>
    <dc:creator>Momoj</dc:creator>
    <dc:date>2022-12-23T01:59:56Z</dc:date>
    <item>
      <title>RMA replacement</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rma-replacement/m-p/524456#M108508</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We will doing a RMA replacement for PA-3220. The faulty unit is cannot access anymore from GUI or CLI and it's managed from Panorama. We only have the backup configuration and not the device state. So, what we should?&lt;/P&gt;
&lt;P&gt;1)Do we replace the fault unit with the new one, configure the HA with the active unit and replace the S/N in the firewall? It is possible the active unit to sync the device state to the new spare unit?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Dec 2022 09:14:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rma-replacement/m-p/524456#M108508</guid>
      <dc:creator>Momoj</dc:creator>
      <dc:date>2022-12-19T09:14:38Z</dc:date>
    </item>
    <item>
      <title>Re: RMA replacement</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rma-replacement/m-p/524468#M108512</link>
      <description>&lt;P&gt;Configuration backup has all local information needed like mgmt interface IP, HA settings etc so you don't need device state.&lt;/P&gt;
&lt;P&gt;After physical replacement replace serial number in Panorama and commit from Panorama to firewall.&lt;/P&gt;
&lt;P&gt;If firewalls show "out of sync" in HA dashboard then click "sync to peer" from surviving HA member (and not from RMA device).&lt;/P&gt;</description>
      <pubDate>Mon, 19 Dec 2022 14:39:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rma-replacement/m-p/524468#M108512</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2022-12-19T14:39:48Z</dc:date>
    </item>
    <item>
      <title>Re: RMA replacement</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rma-replacement/m-p/524476#M108515</link>
      <description>&lt;P&gt;Alright. I understand. So we need to load backup config first? After that, we do the physical replacement, serial number in&lt;SPAN&gt;&amp;nbsp;Panorama and commit from Panorama to firewall. But when we try to load backup into RMA device, it have commit error and when we try to resolve it, it will have another error.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;or&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;is it possible if we change the management IP and configure HA with the active unit? and then, we change the serial number in&amp;nbsp;Panorama and commit from Panorama to firewall.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Dec 2022 17:27:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rma-replacement/m-p/524476#M108515</guid>
      <dc:creator>Momoj</dc:creator>
      <dc:date>2022-12-19T17:27:18Z</dc:date>
    </item>
    <item>
      <title>Re: RMA replacement</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rma-replacement/m-p/524478#M108516</link>
      <description>&lt;P&gt;What error do you get? Is it missing some settings that were pushed from Panorama?&lt;/P&gt;
&lt;P&gt;If this is the case then try following:&lt;/P&gt;
&lt;P&gt;Import backup config into RMA firewall.&lt;/P&gt;
&lt;P&gt;Change RMA mgmt to use temporary unique IP.&lt;BR /&gt;Configure networking so that this temporary IP can reach Panorama.&lt;/P&gt;
&lt;P&gt;Add new RMA fw serial into "Panorama &amp;gt; Managed Devices &amp;gt; Summary" as new firewall.&lt;/P&gt;
&lt;P&gt;Add RMA fw to same template group and Device group as old firewall.&lt;/P&gt;
&lt;P&gt;Push and commit to RMA fw from Panorama to merge imported backup with config settings pushed from Panorama.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If this works then you can remove old fw from device group and template group.&lt;/P&gt;
&lt;P&gt;Change RMA mgmt IP to match old firewall.&lt;/P&gt;
&lt;P&gt;Perform physical install.&lt;BR /&gt;Sync config from surviving fw to RMA fw on HA dashboard.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Dec 2022 17:36:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rma-replacement/m-p/524478#M108516</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2022-12-19T17:36:27Z</dc:date>
    </item>
    <item>
      <title>Re: RMA replacement</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rma-replacement/m-p/524479#M108517</link>
      <description>&lt;P&gt;Actually temporary unique IP is not needed as I assume old dead firewall is not connected to network any more.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Dec 2022 17:38:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rma-replacement/m-p/524479#M108517</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2022-12-19T17:38:31Z</dc:date>
    </item>
    <item>
      <title>Re: RMA replacement</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rma-replacement/m-p/524484#M108520</link>
      <description>&lt;P&gt;Yeah, the old firewall is not connected to the network. So, we just replace the old serial number to new serial number?&lt;/P&gt;</description>
      <pubDate>Mon, 19 Dec 2022 19:09:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rma-replacement/m-p/524484#M108520</guid>
      <dc:creator>Momoj</dc:creator>
      <dc:date>2022-12-19T19:09:53Z</dc:date>
    </item>
    <item>
      <title>Re: RMA replacement</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rma-replacement/m-p/524485#M108521</link>
      <description>&lt;P&gt;In this case yes as simple step try to replace serial number and commit from Panorama to RMA fw.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Dec 2022 19:11:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rma-replacement/m-p/524485#M108521</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2022-12-19T19:11:32Z</dc:date>
    </item>
    <item>
      <title>Re: RMA replacement</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rma-replacement/m-p/524486#M108522</link>
      <description>&lt;P&gt;Alright, thank you. we managed to change S/N to a new one but it seems like the RMA device in the panorama is disconnected.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Dec 2022 19:34:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rma-replacement/m-p/524486#M108522</guid>
      <dc:creator>Momoj</dc:creator>
      <dc:date>2022-12-19T19:34:50Z</dc:date>
    </item>
    <item>
      <title>Re: RMA replacement</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rma-replacement/m-p/524487#M108523</link>
      <description>&lt;P&gt;RMA firewall has Panorama configuration under Device &amp;gt; Setup &amp;gt; Management &amp;gt; Panama settings?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What ms logs shows on RMA firewall?&lt;/P&gt;
&lt;P&gt;less mp-log ms.log&lt;/P&gt;
&lt;P&gt;Or view new logs as they appear&lt;/P&gt;
&lt;P&gt;tail follow yes mp-log ms.log&lt;/P&gt;</description>
      <pubDate>Mon, 19 Dec 2022 19:43:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rma-replacement/m-p/524487#M108523</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2022-12-19T19:43:50Z</dc:date>
    </item>
    <item>
      <title>Re: RMA replacement</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rma-replacement/m-p/524500#M108527</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/242714"&gt;@Momoj&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;in addition to going through logs mentioned by Raido, if you are running PAN-OS 10.1.3 and higher, you will have to import authentication key to Firewall to allow communication with Panorama:&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/panorama/10-1/panorama-admin/manage-firewalls/add-a-firewall-as-a-managed-device" target="_blank"&gt;https://docs.paloaltonetworks.com/panorama/10-1/panorama-admin/manage-firewalls/add-a-firewall-as-a-managed-device&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Mon, 19 Dec 2022 22:06:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rma-replacement/m-p/524500#M108527</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2022-12-19T22:06:16Z</dc:date>
    </item>
    <item>
      <title>Re: RMA replacement</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rma-replacement/m-p/524716#M108548</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sorry for my late reply and thanks for all helps. It seems like we managed to connect from RMA firewall to Panorama. But when we want try to push the config file from panorama to firewall, it still have some error same as when we try to do backup config directly to firewall.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Dec 2022 01:49:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rma-replacement/m-p/524716#M108548</guid>
      <dc:creator>Momoj</dc:creator>
      <dc:date>2022-12-21T01:49:42Z</dc:date>
    </item>
    <item>
      <title>Re: RMA replacement</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rma-replacement/m-p/524719#M108549</link>
      <description>&lt;P&gt;What error do you get?&lt;/P&gt;
&lt;P&gt;Does checking "Force Template Values" when committing from Panorama to RMA fix the issue?&lt;/P&gt;</description>
      <pubDate>Wed, 21 Dec 2022 03:41:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rma-replacement/m-p/524719#M108549</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2022-12-21T03:41:44Z</dc:date>
    </item>
    <item>
      <title>Re: RMA replacement</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rma-replacement/m-p/524868#M108572</link>
      <description>&lt;P&gt;Just noticed this post - we are going through a similar ordeal and wondering if you have completed the restore process.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;this is our experience/problems so far:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/general-topics/problems-after-rma-of-an-active-passive-pair/td-p/524841" target="_blank"&gt;https://live.paloaltonetworks.com/t5/general-topics/problems-after-rma-of-an-active-passive-pair/td-p/524841&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Dec 2022 15:08:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rma-replacement/m-p/524868#M108572</guid>
      <dc:creator>RREALICA</dc:creator>
      <dc:date>2022-12-22T15:08:14Z</dc:date>
    </item>
    <item>
      <title>Re: RMA replacement</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rma-replacement/m-p/524920#M108585</link>
      <description>&lt;P&gt;Yes, we are able to push the config by clicking the force template value. For somehow, there is a configuration error in the template that cause GUI for RMA unit cannot be access. We already log the ticket to RMA for this issue.&lt;/P&gt;
&lt;P&gt;Thanks all for your help.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Dec 2022 01:59:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rma-replacement/m-p/524920#M108585</guid>
      <dc:creator>Momoj</dc:creator>
      <dc:date>2022-12-23T01:59:56Z</dc:date>
    </item>
  </channel>
</rss>

