<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Migration from PA 220 to PA 440 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/migration-from-pa-220-to-pa-440/m-p/528591#M109138</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am in the process of migrating from a pa220 os 10.1 to a pa440 os 10.1.3. I imported the configuration from the pa 220 to the pa440 I ran into three issues:&lt;/P&gt;
&lt;P&gt;1.we are getting 1gig from the ISP and even with Qos disabled we are only getting 150mbps&lt;/P&gt;
&lt;P&gt;2. We have a toshiba phone system not IP every thing works except when calling location B across the ipsec tunnel, the call goes through and we can hear them talk but they cannot hear us and I have already disabled ALG&lt;/P&gt;
&lt;P&gt;3. We were able to access the internal camera system remotely and now we can't&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Compared config and they match,scratching my head.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 25 Jan 2023 17:56:27 GMT</pubDate>
    <dc:creator>janelle.provine</dc:creator>
    <dc:date>2023-01-25T17:56:27Z</dc:date>
    <item>
      <title>Migration from PA 220 to PA 440</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/migration-from-pa-220-to-pa-440/m-p/528591#M109138</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am in the process of migrating from a pa220 os 10.1 to a pa440 os 10.1.3. I imported the configuration from the pa 220 to the pa440 I ran into three issues:&lt;/P&gt;
&lt;P&gt;1.we are getting 1gig from the ISP and even with Qos disabled we are only getting 150mbps&lt;/P&gt;
&lt;P&gt;2. We have a toshiba phone system not IP every thing works except when calling location B across the ipsec tunnel, the call goes through and we can hear them talk but they cannot hear us and I have already disabled ALG&lt;/P&gt;
&lt;P&gt;3. We were able to access the internal camera system remotely and now we can't&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Compared config and they match,scratching my head.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2023 17:56:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/migration-from-pa-220-to-pa-440/m-p/528591#M109138</guid>
      <dc:creator>janelle.provine</dc:creator>
      <dc:date>2023-01-25T17:56:27Z</dc:date>
    </item>
    <item>
      <title>Re: Migration from PA 220 to PA 440</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/migration-from-pa-220-to-pa-440/m-p/528661#M109154</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/238468"&gt;@janelle.provine&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;1.we are getting 1gig from the ISP and even with Qos disabled we are only getting 150mbps&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;Have you verified counters? If you've been testing without security profiles applied, speed/duplex have been verified, and you have QoS disabled the 450 shouldn't have any issues with that. The only other thing that I've seen cause similar issues (to a far lesser extent) is when the firewall is behind another device performing a double NAT.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2. We have a toshiba phone system not IP every thing works except when calling location B across the ipsec tunnel, the call goes through and we can hear them talk but they cannot hear us and I have already disabled ALG&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;You've verified that you don't have any traffic between location B and your primary location being denied? Either to the phone system itself or to the other phone if media bypass is enabled on the phone system for internal calls?&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3. We were able to access the internal camera system remotely and now we can't&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;How were you able to access it before, directly to the IP/FQDN or by using GlobalProtect? Combined with your first question, did you also upgrade your internet when you swapped to the PA-450? Is it possible that you replaced some ISP gear that wasn't put into passthrough mode and is performing its own NAT; this would explain the broken camera system access if you were accessing it directly by IP/FQDN.&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jan 2023 04:02:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/migration-from-pa-220-to-pa-440/m-p/528661#M109154</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2023-01-26T04:02:45Z</dc:date>
    </item>
    <item>
      <title>Re: Migration from PA 220 to PA 440</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/migration-from-pa-220-to-pa-440/m-p/528719#M109166</link>
      <description>&lt;P&gt;&lt;SPAN&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Have you verified counters? &lt;STRONG&gt;Which counters are you referring too the ISP tested and said there was 1 gig coming to the modem.&amp;nbsp;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If you've been testing without security profiles applied&amp;nbsp; &lt;STRONG&gt;no I have profiles,&lt;/STRONG&gt; &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;speed/duplex have been verified &lt;STRONG&gt;-you mean of the pc,s and switch the pc's are on?&lt;/STRONG&gt;, &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;a&lt;/SPAN&gt;&lt;SPAN&gt;nd you have QoS disabled -&lt;/SPAN&gt;&lt;STRONG style="font-family: inherit;"&gt;yes and the speed went from 50 to 150&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The only other thing that I've seen cause similar issues (to a far lesser extent) is when the firewall is behind another device performing a double NAT.-&lt;STRONG&gt; not sure how to check that all I have it natted to the external IP and the net hop in the vr is the modem&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;You've verified that you don't have any traffic between location B and your primary location being denied? - &lt;STRONG&gt;yes the configuration is exactly the same as on the pa 220 that I migrated from , I imported it directly to the 440. This is not a voip they do not have IP phones it is going from the PBX ip on our side to a IP address of the PBX on the remote site across a ipsec tunnel.&amp;nbsp;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;How were you able to access it before, directly to the IP/FQDN or by using GlobalProtect?&amp;nbsp; &lt;STRONG&gt;-direct by the external IP address no gpvpn. The internet speed was upgraded quite awhile ago but they were limited by the PA 220 that is why we are upgrading them to PA440&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Is it possible that you replaced some ISP gear that wasn't put into passthrough mode and is performing its own NAT; this would explain the broken camera system access if you were accessing it directly by IP/FQDN. &lt;STRONG&gt;- the ISP came and checked it out and the only thing they said was the that traffic was being shapped I am sure they meant we were doing it&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 31 Jan 2023 15:35:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/migration-from-pa-220-to-pa-440/m-p/528719#M109166</guid>
      <dc:creator>janelle.provine</dc:creator>
      <dc:date>2023-01-31T15:35:37Z</dc:date>
    </item>
  </channel>
</rss>

