<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PA-220 to PA-440 Migration Recommended Process in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pa-220-to-pa-440-migration-recommended-process/m-p/573174#M115277</link>
    <description>&lt;P&gt;Thank you, Tom.&amp;nbsp; I appreciate the assist.&lt;/P&gt;</description>
    <pubDate>Tue, 16 Jan 2024 12:51:53 GMT</pubDate>
    <dc:creator>EddieReyes</dc:creator>
    <dc:date>2024-01-16T12:51:53Z</dc:date>
    <item>
      <title>PA-220 to PA-440 Migration Recommended Process</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-220-to-pa-440-migration-recommended-process/m-p/572764#M115236</link>
      <description>&lt;P&gt;I need to migrate 2 stand alone PA-220s to PA-440s.&amp;nbsp; The current PA-220s are running PAN-OS 10.2.4-h2.&lt;/P&gt;
&lt;P&gt;I would like to know the recommended process for doing this.&lt;/P&gt;
&lt;P&gt;Can I backup the configuration and system state and restore it on the PA-440?&lt;/P&gt;
&lt;P&gt;Do I use Expedition to migrate the current config to the new firewall?&lt;/P&gt;
&lt;P&gt;Thank you in advance&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jan 2024 19:42:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-220-to-pa-440-migration-recommended-process/m-p/572764#M115236</guid>
      <dc:creator>EddieReyes</dc:creator>
      <dc:date>2024-01-11T19:42:39Z</dc:date>
    </item>
    <item>
      <title>Re: PA-220 to PA-440 Migration Recommended Process</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-220-to-pa-440-migration-recommended-process/m-p/572814#M115244</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/155299"&gt;@EddieReyes&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can backup and restore the configuration to the PA-440s. I have done it a few times.&amp;nbsp; It works great.&amp;nbsp; Once you load and commit, you can login with the PA-220 admin password.&amp;nbsp; You do not need to use Expedition, especially if your NGFWs are running the same PAN-OS.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You do not have to backup and restore system state, but that will work fine also.&amp;nbsp; Here is a good discussion on the differences between the two.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/general-topics/what-s-the-difference-between-each-of-export-backup-options/td-p/162108" target="_blank"&gt;https://live.paloaltonetworks.com/t5/general-topics/what-s-the-difference-between-each-of-export-backup-options/td-p/162108&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jan 2024 04:02:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-220-to-pa-440-migration-recommended-process/m-p/572814#M115244</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2024-01-12T04:02:51Z</dc:date>
    </item>
    <item>
      <title>Re: PA-220 to PA-440 Migration Recommended Process</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-220-to-pa-440-migration-recommended-process/m-p/573174#M115277</link>
      <description>&lt;P&gt;Thank you, Tom.&amp;nbsp; I appreciate the assist.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jan 2024 12:51:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-220-to-pa-440-migration-recommended-process/m-p/573174#M115277</guid>
      <dc:creator>EddieReyes</dc:creator>
      <dc:date>2024-01-16T12:51:53Z</dc:date>
    </item>
    <item>
      <title>Re: PA-220 to PA-440 Migration Recommended Process</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-220-to-pa-440-migration-recommended-process/m-p/576665#M115722</link>
      <description>&lt;P&gt;Tom:&lt;/P&gt;
&lt;P&gt;I was able to migrate one of the PA-220 to a PA-440 without problems.&lt;/P&gt;
&lt;P&gt;The other showed commit failures.&amp;nbsp; One of the failures is because the self signed certificates have a Block Private Key icon next to the Key check.&amp;nbsp; I tried manually exporting and importing the certs, but then i had a commit failure due to the Service Account password used under User ID.&amp;nbsp; Have you ever seen this?&lt;/P&gt;
&lt;P&gt;Thanks.&lt;BR /&gt;Eddie&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2024 18:37:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-220-to-pa-440-migration-recommended-process/m-p/576665#M115722</guid>
      <dc:creator>EddieReyes</dc:creator>
      <dc:date>2024-02-08T18:37:52Z</dc:date>
    </item>
    <item>
      <title>Re: PA-220 to PA-440 Migration Recommended Process</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-220-to-pa-440-migration-recommended-process/m-p/576666#M115723</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/155299"&gt;@EddieReyes&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes, I have!&amp;nbsp; The master key may be different for the 2 NGFWs, and the new FW cannot decrypt the hash.&amp;nbsp; Open configuration box in the GUI and retype the password.&amp;nbsp; Then commit.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2024 18:56:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-220-to-pa-440-migration-recommended-process/m-p/576666#M115723</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2024-02-08T18:56:04Z</dc:date>
    </item>
    <item>
      <title>Re: PA-220 to PA-440 Migration Recommended Process</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-220-to-pa-440-migration-recommended-process/m-p/576669#M115724</link>
      <description>&lt;P&gt;Tom:&lt;/P&gt;
&lt;P&gt;I am sorry to ask but which master key are we talking about.&amp;nbsp; I don't have a master key configured on either old or new firewall.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is it under Master Key and Diagnostics?&amp;nbsp; I am not using that.&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;
&lt;P&gt;Eddie&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2024 19:09:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-220-to-pa-440-migration-recommended-process/m-p/576669#M115724</guid>
      <dc:creator>EddieReyes</dc:creator>
      <dc:date>2024-02-08T19:09:50Z</dc:date>
    </item>
    <item>
      <title>Re: PA-220 to PA-440 Migration Recommended Process</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-220-to-pa-440-migration-recommended-process/m-p/576671#M115725</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/155299"&gt;@EddieReyes&lt;/a&gt;,&amp;nbsp;could be you have an issue with the certificates for decryption&lt;/P&gt;
&lt;P&gt;I recommended to download de device state in Device &amp;gt; setup &amp;gt; operation &amp;gt; export device state and this option export the private key from PA220, and for PA-440 apply the same option, so now you will import the device state and the private key reside in the new firewall, then apply commit&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2024 19:23:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-220-to-pa-440-migration-recommended-process/m-p/576671#M115725</guid>
      <dc:creator>Alejandro_Hernandez</dc:creator>
      <dc:date>2024-02-08T19:23:24Z</dc:date>
    </item>
    <item>
      <title>Re: PA-220 to PA-440 Migration Recommended Process</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-220-to-pa-440-migration-recommended-process/m-p/576672#M115726</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/155299"&gt;@EddieReyes&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sorry that I wasn't clear!&amp;nbsp; Open the GUI configuration for "Service Account password used under User ID" and retype the password.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes, Master Key and Diagnostics.&amp;nbsp; The NGFW uses a default master key if it is not configured.&amp;nbsp; You do not need to do anything for it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2024 19:25:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-220-to-pa-440-migration-recommended-process/m-p/576672#M115726</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2024-02-08T19:25:42Z</dc:date>
    </item>
    <item>
      <title>Re: PA-220 to PA-440 Migration Recommended Process</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-220-to-pa-440-migration-recommended-process/m-p/576707#M115748</link>
      <description>&lt;P&gt;No apologies needed, Tom.&amp;nbsp; I really appreciate the help.&amp;nbsp; I ended up having to import the SSCerts and provide the UserID account password and preshared keys for S2S tunnels.&amp;nbsp; I was able to commit after that.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for sharing your expertise.&amp;nbsp; I appreciate it.&lt;/P&gt;
&lt;P&gt;Eddie&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2024 22:10:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-220-to-pa-440-migration-recommended-process/m-p/576707#M115748</guid>
      <dc:creator>EddieReyes</dc:creator>
      <dc:date>2024-02-08T22:10:02Z</dc:date>
    </item>
    <item>
      <title>Re: PA-220 to PA-440 Migration Recommended Process</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-220-to-pa-440-migration-recommended-process/m-p/576709#M115749</link>
      <description>&lt;P&gt;Thank you, Alejandro.&lt;/P&gt;
&lt;P&gt;I tried exporting and importing the device state, but the commit still failed like before.&amp;nbsp; &amp;nbsp;I tried several times and rebooted in between, but no cigar.&amp;nbsp;&amp;nbsp;&lt;SPAN&gt;I ended up having to import the SSCerts and provide the UserID account password and preshared keys for S2S tunnels.&amp;nbsp; I was able to commit after that.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Like Tom, thank you for sharing your expertise.&amp;nbsp; I appreciate that.&lt;/P&gt;
&lt;P&gt;Eddie&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2024 22:12:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-220-to-pa-440-migration-recommended-process/m-p/576709#M115749</guid>
      <dc:creator>EddieReyes</dc:creator>
      <dc:date>2024-02-08T22:12:57Z</dc:date>
    </item>
    <item>
      <title>Re: PA-220 to PA-440 Migration Recommended Process</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-220-to-pa-440-migration-recommended-process/m-p/583937#M116681</link>
      <description>&lt;P&gt;&amp;nbsp;I'm not aware of Expedition, is that a separate tool? Also, I'm wondering about how the interfaces will line us since they aren't one-for-one. For example, the 220s have 8 ethernet interfaces 1/2-1/8, but the 445s have 9 interfaces with the mgmt. interface being at 1/1 and the rest from 1/2-1/9.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Thanks for you input!&lt;/P&gt;</description>
      <pubDate>Tue, 16 Apr 2024 21:17:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-220-to-pa-440-migration-recommended-process/m-p/583937#M116681</guid>
      <dc:creator>jmatanane</dc:creator>
      <dc:date>2024-04-16T21:17:54Z</dc:date>
    </item>
    <item>
      <title>Re: PA-220 to PA-440 Migration Recommended Process</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-220-to-pa-440-migration-recommended-process/m-p/584016#M116688</link>
      <description>&lt;P&gt;Expedition is a Community supported Migration Tool.&lt;/P&gt;
&lt;P&gt;I have used it to migrate from 4 ASAs and 1 Sonicwall to Palo Alto Firewalls.&amp;nbsp; Those migrations went really well.&lt;/P&gt;
&lt;P&gt;Here is a link if you want to learn more:&amp;nbsp;&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/expedition/ct-p/migration_tool" target="_blank"&gt;https://live.paloaltonetworks.com/t5/expedition/ct-p/migration_tool&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Apr 2024 12:07:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-220-to-pa-440-migration-recommended-process/m-p/584016#M116688</guid>
      <dc:creator>EddieReyes</dc:creator>
      <dc:date>2024-04-17T12:07:08Z</dc:date>
    </item>
  </channel>
</rss>

