<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Replace  a PA-3060  with a PA-5220  keeping configuration the same in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/replace-a-pa-3060-with-a-pa-5220-keeping-configuration-the-same/m-p/167298#M53442</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I believe you still can do it (it never hurts &lt;SPAN&gt;&amp;nbsp;to try&lt;/SPAN&gt;&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt; )&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Make sure:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) Both units are on the&amp;nbsp;same PAN-OS release before exporting the existing config from the 3060 device&lt;/P&gt;&lt;P&gt;2) Both units have the same licences&amp;nbsp;&lt;/P&gt;&lt;P&gt;3) If interfaces name/mapping are different you might need to modify .xml file manually, save it and import it into the new 5020 unit.&lt;/P&gt;&lt;P&gt;4) Validate config&amp;nbsp;before&amp;nbsp;commit with "Validate Commit" option.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="valid.JPG" style="width: 674px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/10463iE24F70E3802353BD/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="valid.JPG" alt="valid.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If there are any errors, export candidate config in .xml&amp;nbsp;file from 5020 unit and modify it again. Repeat the process until&amp;nbsp;you can successfully validate the config then do a "commit"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have done this before (between other mdels), so it should work for you too&lt;/P&gt;</description>
    <pubDate>Wed, 19 Jul 2017 21:40:47 GMT</pubDate>
    <dc:creator>TranceforLife</dc:creator>
    <dc:date>2017-07-19T21:40:47Z</dc:date>
    <item>
      <title>Replace  a PA-3060  with a PA-5220  keeping configuration the same</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/replace-a-pa-3060-with-a-pa-5220-keeping-configuration-the-same/m-p/167282#M53440</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are&amp;nbsp; replacing a&amp;nbsp; 3060&amp;nbsp; with a&amp;nbsp; 5220&amp;nbsp;, I do understand that Tech Support dosen't recommend to move configuration file&lt;/P&gt;&lt;P&gt;between two different&amp;nbsp; models.&lt;/P&gt;&lt;P&gt;Are there any items that can be transferred , and not have to recreate all of it ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jul 2017 20:54:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/replace-a-pa-3060-with-a-pa-5220-keeping-configuration-the-same/m-p/167282#M53440</guid>
      <dc:creator>kardasopoulos1</dc:creator>
      <dc:date>2017-07-19T20:54:56Z</dc:date>
    </item>
    <item>
      <title>Re: Replace  a PA-3060  with a PA-5220  keeping configuration the same</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/replace-a-pa-3060-with-a-pa-5220-keeping-configuration-the-same/m-p/167298#M53442</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I believe you still can do it (it never hurts &lt;SPAN&gt;&amp;nbsp;to try&lt;/SPAN&gt;&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt; )&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Make sure:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) Both units are on the&amp;nbsp;same PAN-OS release before exporting the existing config from the 3060 device&lt;/P&gt;&lt;P&gt;2) Both units have the same licences&amp;nbsp;&lt;/P&gt;&lt;P&gt;3) If interfaces name/mapping are different you might need to modify .xml file manually, save it and import it into the new 5020 unit.&lt;/P&gt;&lt;P&gt;4) Validate config&amp;nbsp;before&amp;nbsp;commit with "Validate Commit" option.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="valid.JPG" style="width: 674px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/10463iE24F70E3802353BD/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="valid.JPG" alt="valid.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If there are any errors, export candidate config in .xml&amp;nbsp;file from 5020 unit and modify it again. Repeat the process until&amp;nbsp;you can successfully validate the config then do a "commit"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have done this before (between other mdels), so it should work for you too&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jul 2017 21:40:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/replace-a-pa-3060-with-a-pa-5220-keeping-configuration-the-same/m-p/167298#M53442</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-07-19T21:40:47Z</dc:date>
    </item>
    <item>
      <title>Re: Replace  a PA-3060  with a PA-5220  keeping configuration the same</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/replace-a-pa-3060-with-a-pa-5220-keeping-configuration-the-same/m-p/167322#M53444</link>
      <description>&lt;P&gt;I've done this recently. &amp;nbsp;The two areas you'll likely run into problems: &amp;nbsp;1.) High Availability configuration. &amp;nbsp;The 5220 uses the HSCI port for HA2/HA3 traffic, where the 3060 used dedicated HA2 interfaces for session-sync, and dataplane interfaces for HA3 traffic. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, the 5220 requires one of the dataplane ports to be configured as a "Log Interface" for external log forwarding. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Other than that, most of the other things seemed to transfer over just fine. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I took a slightly different approach, I took a 5220 "empty" configuration as a base configuration, and then cut things out of the older firewall's .xml config file and pasted it into the 5200's config file. &amp;nbsp;It wasn't too much work... Didn't have to touch firewall objects, or policies, etc. &amp;nbsp;Those were exactly the same. &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jul 2017 21:47:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/replace-a-pa-3060-with-a-pa-5220-keeping-configuration-the-same/m-p/167322#M53444</guid>
      <dc:creator>jvalentine</dc:creator>
      <dc:date>2017-07-19T21:47:17Z</dc:date>
    </item>
    <item>
      <title>Re: Replace  a PA-3060  with a PA-5220  keeping configuration the same</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/replace-a-pa-3060-with-a-pa-5220-keeping-configuration-the-same/m-p/200345#M59276</link>
      <description>&lt;P&gt;Can someone confirm that 5220 requires HSCI port for data link between both firewalls in Active/Passive configuration. I am trying to configure using the HA2 port but I do not even have option other than HSCI.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Feb 2018 20:23:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/replace-a-pa-3060-with-a-pa-5220-keeping-configuration-the-same/m-p/200345#M59276</guid>
      <dc:creator>Inamul</dc:creator>
      <dc:date>2018-02-13T20:23:31Z</dc:date>
    </item>
    <item>
      <title>Re: Replace  a PA-3060  with a PA-5220  keeping configuration the same</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/replace-a-pa-3060-with-a-pa-5220-keeping-configuration-the-same/m-p/200350#M59277</link>
      <description>&lt;P&gt;If you want to use the management plane for HA2, then yes, you have to use HSCI.&lt;/P&gt;&lt;P&gt;The other possibility is that you use a dataplane port and configure it as Type HA. As soon as you do that you could choose that port in the HA configuration.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Feb 2018 21:08:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/replace-a-pa-3060-with-a-pa-5220-keeping-configuration-the-same/m-p/200350#M59277</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-02-13T21:08:29Z</dc:date>
    </item>
    <item>
      <title>Re: Replace  a PA-3060  with a PA-5220  keeping configuration the same</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/replace-a-pa-3060-with-a-pa-5220-keeping-configuration-the-same/m-p/219624#M63408</link>
      <description>&lt;P&gt;Hi, when you said: "&lt;SPAN&gt;&amp;nbsp;5220 requires one of the dataplane ports to be configured as a "Log Interface" - is this a requirement or option? I could not find anything in the 5220 documentation. I&amp;nbsp;am planning 5220 and this will be big difference. Can the log forwarding be done over the Management interface?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jun 2018 08:42:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/replace-a-pa-3060-with-a-pa-5220-keeping-configuration-the-same/m-p/219624#M63408</guid>
      <dc:creator>BatD</dc:creator>
      <dc:date>2018-06-28T08:42:55Z</dc:date>
    </item>
    <item>
      <title>Re: Replace  a PA-3060  with a PA-5220  keeping configuration the same</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/replace-a-pa-3060-with-a-pa-5220-keeping-configuration-the-same/m-p/219712#M63421</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/74884"&gt;@BatD&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Log Forwarding by default is done by the management interface. The PA-5220 can forward logs via a different interface by configuring a Service Route. I believe that that part of the answer isn't correct, you don't need any special 'Log Interface' unless you are using a 7000 series chassis.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jun 2018 14:44:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/replace-a-pa-3060-with-a-pa-5220-keeping-configuration-the-same/m-p/219712#M63421</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-06-28T14:44:44Z</dc:date>
    </item>
  </channel>
</rss>

