<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Migrate Config between PA-500 and PA-2050 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/migrate-config-between-pa-500-and-pa-2050/m-p/150359#M49935</link>
    <description>&lt;P&gt;As a little wrap up: Yes you need a support contract to update a machine. Couldn't get the 2050 to the same OS-lvl as the 500 since updates couldn't be loaded in the 2050. Our vendor only could provide us with update-packages for the 500.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just copied the config step by step with an xml editor and had to ship around some missing functions and changing numbers and structure of the xml (e.g. pan OS 4 can only handle 10 proxy-ips per tunnel but we had sometimes way more). Config ist now up and running.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your help &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 30 Mar 2017 10:11:41 GMT</pubDate>
    <dc:creator>lenmar</dc:creator>
    <dc:date>2017-03-30T10:11:41Z</dc:date>
    <item>
      <title>Migrate Config between PA-500 and PA-2050</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/migrate-config-between-pa-500-and-pa-2050/m-p/148818#M49653</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we own a PA-500 Firewall but are some Versions behind in the OS. Now we want to update it but got an downtime estmiate from our local Palo-Alto vendor from 8 hours. (From Version 5 to &lt;span class="lia-unicode-emoji" title=":smiling_face_with_sunglasses:"&gt;😎&lt;/span&gt; Since we have some 24/7 Callcenters in house that's not an option to have such a long downtime.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have the option to get a used PA-2050 for pretty cheap and I'd like to know if it's possible to migrate the Config hassle-free between those two Firewalls over the Config-snapshot-export/import or if there are any problems between different models. This way we could just copy the config and let the second model run for the time needed for the update.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for any advice someone could give me&lt;/P&gt;</description>
      <pubDate>Wed, 22 Mar 2017 11:58:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/migrate-config-between-pa-500-and-pa-2050/m-p/148818#M49653</guid>
      <dc:creator>lenmar</dc:creator>
      <dc:date>2017-03-22T11:58:27Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate Config between PA-500 and PA-2050</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/migrate-config-between-pa-500-and-pa-2050/m-p/148826#M49654</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) Both devices must be on the&amp;nbsp;same PAN-OS&lt;/P&gt;&lt;P&gt;2) Physical&amp;nbsp;interfaces mapping must match&lt;/P&gt;&lt;P&gt;3) Make sure your licences are activated on the 2050, especially&amp;nbsp;URL filtering (if you use any)&lt;/P&gt;&lt;P&gt;4) Export config from the&amp;nbsp;500 and import it to the 2050&lt;/P&gt;&lt;P&gt;5) Use the&amp;nbsp;option "validate changes" &amp;nbsp;before commit. This will give you a good indication if there are any errors&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SS.png" style="width: 402px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/8311iE2C31AC3655F4C04/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="SS.png" alt="SS.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;6) Send GARP out when the devices are swapped&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Mar 2017 13:21:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/migrate-config-between-pa-500-and-pa-2050/m-p/148826#M49654</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-03-22T13:21:50Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate Config between PA-500 and PA-2050</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/migrate-config-between-pa-500-and-pa-2050/m-p/148835#M49660</link>
      <description>&lt;P&gt;Thank you very much!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I just have some follow up questions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is a support-contract a requirement to update the os-version? Because the used 2050 is end-of-life and according to the "second-market-policy" of Palo Alto, end of life devices dont get any new license activations or support. So we couldnt get it to the same version if thats required.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Mar 2017 13:20:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/migrate-config-between-pa-500-and-pa-2050/m-p/148835#M49660</guid>
      <dc:creator>lenmar</dc:creator>
      <dc:date>2017-03-22T13:20:15Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate Config between PA-500 and PA-2050</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/migrate-config-between-pa-500-and-pa-2050/m-p/148836#M49661</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/37163"&gt;@TranceforLife&lt;/a&gt;&amp;nbsp;gave you all of the right technical details of what you would need to do. You will need to edit the configuration to get the interfaces to line up since you gain interfaces on the PA-2050 that you wouldn't have had on the PA-500; that is simple enough to do.&amp;nbsp;&lt;/P&gt;&lt;P&gt;One thing that I would bring up is if you really want to be purchasing a used PA-2050 to bring things in line, or if you would benefit from getting an additional PA-500 and having an HA setup? The PA-2050 if a pretty decent upgrade over the PA-500 but you are locking yourself into the same exact issue that you have currently; eventually you are going to be severely out of date again and you will have to repeat the process.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BTW: Just as a side not I really hope your vendor is not recomendding you upgrade to 8 already if you can't afford downtime. I would strongly advise that you stop at the latest 7.1.* and not continue to 8 if you have 24/7 callcenters that can't live with downtime. PANos 8 is still very much early in it's lifecycle and has enough bugs in the build that I wouldn't run it in production, let alone production in a 24/7 enviroment.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Mar 2017 13:27:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/migrate-config-between-pa-500-and-pa-2050/m-p/148836#M49661</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-03-22T13:27:21Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate Config between PA-500 and PA-2050</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/migrate-config-between-pa-500-and-pa-2050/m-p/148844#M49663</link>
      <description>&lt;P&gt;If you do have access to the support portal &amp;nbsp;(using the account from another device) you "might" be able to download the&amp;nbsp;PAN-OS manually and install&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Mar 2017 13:29:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/migrate-config-between-pa-500-and-pa-2050/m-p/148844#M49663</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-03-22T13:29:25Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate Config between PA-500 and PA-2050</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/migrate-config-between-pa-500-and-pa-2050/m-p/148861#M49666</link>
      <description>&lt;P&gt;The used PA-2050 is not meant to stay online longer than the update progress needs. It's just a quarter of the money our vendor would take to send us a technican who would do the upgrade AND he wouldnt bring a second device to have the smallest downtime possible. The added power is not really needed and since it's EoL we couldn't get any licences onto the machine (we only have threat prevention as far I'm informed)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So we would just keep it to have a backup and for future os-updates.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The point with the 8 is good to know. Thanks for that and your input.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Mar 2017 13:40:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/migrate-config-between-pa-500-and-pa-2050/m-p/148861#M49666</guid>
      <dc:creator>lenmar</dc:creator>
      <dc:date>2017-03-22T13:40:37Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate Config between PA-500 and PA-2050</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/migrate-config-between-pa-500-and-pa-2050/m-p/148890#M49681</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/58504"&gt;@lenmar&lt;/a&gt;&amp;nbsp;honestly I would start looking at another vendor at that point. We always had 'emergency' replacement equipment on hand that was generally equipment either used for demonstaration or equipment left from upgrades. We commonly used this in these types of situations to minimize downtime with a very small or no fee. It doesn't really sound like your vendor is giving you a 'value add' at all.&lt;/P&gt;&lt;P&gt;The config migration may get a little more complicated at that point but your vendor should be able to grab panOS files for whatever exact version you are running on the pa-500 so that you can match on the pa-2050. Then migrate the config and put it in place and you would be up and running. If they can't get you the files then you would have to do an indirect migration; you can do it by either rebuilding your current config on the PA-2050 and it really shouldn't cause any issues, or you could munipulate the XML directly it just gets to be more work. If you a pretty complicated/large config on the PA-500 then I would look at an XML munipulation upgrade to prevent you from having to actually rebuild the configuration at all, if it's a smaller config then it would likely be less time consuming to actually rebuild the config from hand on the PA-2050.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Mar 2017 14:42:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/migrate-config-between-pa-500-and-pa-2050/m-p/148890#M49681</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-03-22T14:42:54Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate Config between PA-500 and PA-2050</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/migrate-config-between-pa-500-and-pa-2050/m-p/150359#M49935</link>
      <description>&lt;P&gt;As a little wrap up: Yes you need a support contract to update a machine. Couldn't get the 2050 to the same OS-lvl as the 500 since updates couldn't be loaded in the 2050. Our vendor only could provide us with update-packages for the 500.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just copied the config step by step with an xml editor and had to ship around some missing functions and changing numbers and structure of the xml (e.g. pan OS 4 can only handle 10 proxy-ips per tunnel but we had sometimes way more). Config ist now up and running.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your help &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Mar 2017 10:11:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/migrate-config-between-pa-500-and-pa-2050/m-p/150359#M49935</guid>
      <dc:creator>lenmar</dc:creator>
      <dc:date>2017-03-30T10:11:41Z</dc:date>
    </item>
  </channel>
</rss>

