<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PA-3020 to PA-460 Migration in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-to-pa-460-migration/m-p/546451#M111692</link>
    <description>&lt;P&gt;Hey &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/249853"&gt;@Sanjay_Ramaiah&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;It looks you have used different account when you first posted your question. I have accepted &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192693"&gt;@PavelK&lt;/a&gt;&amp;nbsp; answer as solution on your behalf.&lt;/P&gt;</description>
    <pubDate>Tue, 20 Jun 2023 08:46:16 GMT</pubDate>
    <dc:creator>aleksandar.astardzhiev</dc:creator>
    <dc:date>2023-06-20T08:46:16Z</dc:date>
    <item>
      <title>PA-3020 to PA-460 Migration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-to-pa-460-migration/m-p/516049#M107169</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;We are migrating one of our PA-3020 to PA-460 next Monday.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;gt; PA-3020 is managed with the Panorama.&lt;/P&gt;
&lt;P&gt;&amp;gt; Panorama is in the version 10.0.11 and the PA-3020 is in the version 8.1.18.&lt;/P&gt;
&lt;P&gt;&amp;gt; Could you please help me with what all need to be considered while migrating this firewall to PA-460.&lt;/P&gt;
&lt;P&gt;&amp;gt; Panorama is hosted on a VM.&lt;/P&gt;
&lt;P&gt;&amp;gt; Can i just export the named configuration and current version of PA-3020 and import it to the PA-460 directly?&lt;/P&gt;
&lt;P&gt;&amp;gt; Also the export includes the management details as well? If yes, just adding the new SN on the Panorama will be enough to get the connectivity to PA-460 and Panorama?&lt;/P&gt;
&lt;P&gt;&amp;gt; If the version of PA-460 is 10.x.x and we exporting the configuration from PA-3020 version 8.1.18 will that be a problem?&lt;/P&gt;
&lt;P&gt;&amp;gt; Also please share me the best practices during the migration so that it will be helpful for my future migrations.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Sanjay S&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2022 09:54:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-to-pa-460-migration/m-p/516049#M107169</guid>
      <dc:creator>sanjay.ramaiah</dc:creator>
      <dc:date>2022-09-27T09:54:41Z</dc:date>
    </item>
    <item>
      <title>Re: PA-3020 to PA-460 Migration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-to-pa-460-migration/m-p/516066#M107171</link>
      <description>&lt;P&gt;Hello &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/236469"&gt;@sanjay.ramaiah&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thank you for the post!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Exporting configuration from PA-3020 and importing it to PA-460 will most likely result error. The difference in interfaces and hardware + different PAN-OS versions will prevent import and commit. Although there are ways to go around it, I believe it would be easier to bring PA-460 online with basic configuration to register it in Panorama, then push the configuration from Panorama. In this way, you can re-use existing configuration in Device Group / Template Stack. For Template, you will have to make modifications to accommodate differences in target device model like interfaces / HA setting,...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In order to assist further, could you please confirm whether PA-3020 is fully managed by Panorama or there is some configuration managed locally?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2022 13:20:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-to-pa-460-migration/m-p/516066#M107171</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2022-09-27T13:20:11Z</dc:date>
    </item>
    <item>
      <title>Re: PA-3020 to PA-460 Migration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-to-pa-460-migration/m-p/516072#M107172</link>
      <description>&lt;P&gt;Hi Pavel,&lt;/P&gt;
&lt;P&gt;Some of the configuration is managed locally.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Sanjay S&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2022 13:42:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-to-pa-460-migration/m-p/516072#M107172</guid>
      <dc:creator>sanjay.ramaiah</dc:creator>
      <dc:date>2022-09-27T13:42:27Z</dc:date>
    </item>
    <item>
      <title>Re: PA-3020 to PA-460 Migration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-to-pa-460-migration/m-p/516179#M107189</link>
      <description>&lt;P&gt;Please help on this asap i need to provide complete change plan by End of today. Could you please help the steps on how to migrate the device which is managed by Panorama. From Panorama templates are being pushed and most of the configuration of the device is managed locally.&lt;/P&gt;
&lt;P&gt;This is the first time planning the migration so please suggest the best way and best practices to follow please.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Sep 2022 07:28:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-to-pa-460-migration/m-p/516179#M107189</guid>
      <dc:creator>sanjay.ramaiah</dc:creator>
      <dc:date>2022-09-28T07:28:20Z</dc:date>
    </item>
    <item>
      <title>Re: PA-3020 to PA-460 Migration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-to-pa-460-migration/m-p/516202#M107191</link>
      <description>&lt;P&gt;Thank you for reply &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/236469"&gt;@sanjay.ramaiah&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;below answer is the best I can come up with considering limited knowledge of your environment.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For the migration of the local device configuration, probably the easiest way are below steps:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1.)&lt;/P&gt;
&lt;P&gt;Perform initial configuration of PA-460. Below links might be useful:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/getting-started/integrate-the-firewall-into-your-management-network/perform-initial-configuration" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/getting-started/integrate-the-firewall-into-your-management-network/perform-initial-configuration&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClN7CAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClN7CAK&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;By following config from above links, you will be able to SSH/GUI to new Firewall. From here you can move to actual configuration migration.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2.)&lt;/P&gt;
&lt;P&gt;SSH to PA-3020 and issue below commands. Ideally set logging session to text file.&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;&amp;gt; set cli config-output-format set&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&amp;gt; set cli pager off&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&amp;gt; configure&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;# show&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;then SSH to PA-460 and issue:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;gt; set cli scripting-mode on&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;gt; configure&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;then paste the configuration you got from PA-3020. You can paste commands in bulk, but watch out for any errors. Ideally instead of blindly copy &amp;amp; paste all configuration, paste only what is relevant and want to move across to PA-460.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Since you will be going from PAN-OS 8.1 to 10.X there are some syntax differences that might require you to configure some of the part of the configuration from scratch. Personally, I would take an opportunity to move as much configuration as possible to Panorama and push it from there. By having configuration In Template / Device Group, you can in the future easily re-use / standardize configuration. I feel this is a better way to do it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regarding Panorama part, please check below steps.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1.)&lt;/P&gt;
&lt;P&gt;Before you can onboard PA-460 to Panorama, you will have to make sure that Panorama runs the higher or the same PAN-OS version as managed Firewall. In your case, you are running PAN-OS 10.0.11 which is already end of life. PA-460 will be shipped either with 10.1.X or with 10.2.X, so Panorama upgrade is necessary.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2.)&lt;/P&gt;
&lt;P&gt;After you complete Panorama upgrade, you can register Firewall in Panorama. You can follow this link:&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/panorama/10-1/panorama-admin/manage-firewalls/add-a-firewall-as-a-managed-device" target="_blank"&gt;https://docs.paloaltonetworks.com/panorama/10-1/panorama-admin/manage-firewalls/add-a-firewall-as-a-managed-device&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3.)&lt;/P&gt;
&lt;P&gt;Personally, I would clone current Template/Template Stack of existing PA-3020 and made necessary modifications. Since PA-460 seems to have the same function, I would place it to the same Device Group. After these settings are in place, I would push this to PA-460. If there is no error, I would plan for cut over.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;4.)&lt;/P&gt;
&lt;P&gt;Personally, on the day of cut over, I would announce maintenance window and move cable across from PA-3020 to PA-460. You did not mention whether you have HA pairs, if yes, I would plan cut over differently with less downtime. Since device is already per-configured either locally or from Panorama, the migration day should be only about cabling and troubleshooting.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It is likely that during preparation for this migration you will come across all sorts of issues or errors. You can share it here, if I know the solution I will follow up with it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Wed, 28 Sep 2022 08:47:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-to-pa-460-migration/m-p/516202#M107191</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2022-09-28T08:47:31Z</dc:date>
    </item>
    <item>
      <title>Re: PA-3020 to PA-460 Migration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-to-pa-460-migration/m-p/523427#M108395</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hi, That's great information.&lt;/P&gt;
&lt;P&gt;May I know what if I don't have Panoroma in my environment and would like to migrate the config over to PA460.&lt;/P&gt;
&lt;P&gt;My current box PA3020 running with 9.1.7 and new box PA460 will be in 10.1.6 and whats the easiest way to do migration. Thanks.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Dec 2022 21:46:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-to-pa-460-migration/m-p/523427#M108395</guid>
      <dc:creator>Kuldeep_Bishnoi</dc:creator>
      <dc:date>2022-12-06T21:46:10Z</dc:date>
    </item>
    <item>
      <title>Re: PA-3020 to PA-460 Migration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-to-pa-460-migration/m-p/523432#M108397</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/259680"&gt;@Kuldeep_Bishnoi&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I will answer your question, but it is best to start a new discussion when slightly changing the topic.&amp;nbsp; This question comes up a lot on this community.&amp;nbsp; I can think of 5 ways to do it:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Panorama if you have it.&amp;nbsp; Add the new NGFW to the same template and device group as your old NGFW.&amp;nbsp; As &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192693"&gt;@PavelK&lt;/a&gt; said, Panorama must be greater or equal PAN-OS.&lt;/LI&gt;
&lt;LI&gt;Expedition if you are familiar with it.&amp;nbsp; The PANW migration tool:&amp;nbsp; &lt;A href="https://live.paloaltonetworks.com/t5/expedition/ct-p/migration_tool" target="_blank" rel="noopener"&gt;https://live.paloaltonetworks.com/t5/expedition/ct-p/migration_tool&lt;/A&gt; saves a lot of time with migrations.&lt;/LI&gt;
&lt;LI&gt;Find a spare PA NGFW that supports both 9.1 and 10.1 and use it.&amp;nbsp; In most cases any PA NGFW will do.&amp;nbsp; In rare cases, a few features will be missing if you use a lower end model.&amp;nbsp; You could even borrow a standby unit.&lt;/LI&gt;
&lt;LI&gt;Use the CLI as &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192693"&gt;@PavelK&lt;/a&gt; suggested.&lt;/LI&gt;
&lt;LI&gt;Import the old PAN-OS XML file and be prepared to work through a TON of commit errors.&amp;nbsp; Some sections can be fixed on the CLI.&amp;nbsp; Others will need to be deleted and recreated.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Tue, 06 Dec 2022 23:35:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-to-pa-460-migration/m-p/523432#M108397</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2022-12-06T23:35:55Z</dc:date>
    </item>
    <item>
      <title>Re: PA-3020 to PA-460 Migration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-to-pa-460-migration/m-p/546448#M111691</link>
      <description>&lt;P&gt;Thank you&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192693"&gt;@PavelK&lt;/a&gt;&amp;nbsp; this helped me in the migration and migrated all the locations successfully.&lt;/P&gt;
&lt;P&gt;Not sure why i am not able to accept this as a solution.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jun 2023 07:32:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-to-pa-460-migration/m-p/546448#M111691</guid>
      <dc:creator>Sanjay_Ramaiah</dc:creator>
      <dc:date>2023-06-20T07:32:26Z</dc:date>
    </item>
    <item>
      <title>Re: PA-3020 to PA-460 Migration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-to-pa-460-migration/m-p/546451#M111692</link>
      <description>&lt;P&gt;Hey &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/249853"&gt;@Sanjay_Ramaiah&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;It looks you have used different account when you first posted your question. I have accepted &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192693"&gt;@PavelK&lt;/a&gt;&amp;nbsp; answer as solution on your behalf.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jun 2023 08:46:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-to-pa-460-migration/m-p/546451#M111692</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2023-06-20T08:46:16Z</dc:date>
    </item>
  </channel>
</rss>

