<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: failed panorama migration in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/failed-panorama-migration/m-p/237344#M68001</link>
    <description>&lt;P&gt;If you export config from Panorama then you can load it into firewall candicate config using previously mentioned command load device-state.&lt;/P&gt;&lt;P&gt;This will give you capability to verify that whole config is correct before you commit it into firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After you commit in firewall it is then safe to commit from Panorama and you don't have issues where your firewall has broken config.&lt;/P&gt;</description>
    <pubDate>Fri, 26 Oct 2018 19:14:29 GMT</pubDate>
    <dc:creator>Raido_Rattameister</dc:creator>
    <dc:date>2018-10-26T19:14:29Z</dc:date>
    <item>
      <title>failed panorama migration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failed-panorama-migration/m-p/237318#M67988</link>
      <description>&lt;P&gt;hi&lt;/P&gt;&lt;P&gt;i attempted to migrate an HA pair to Panorama which went bad. I had only pushed to passive and when i tried to make it active, everything went down.&lt;/P&gt;&lt;P&gt;had to make the previously active firewall actve again, and load last save on passive to recover the passive firewall&lt;/P&gt;&lt;P&gt;now, after after disabling panorama setting in firewall&amp;gt;device&amp;gt;setup, i have firewall rules starting from 100, instead of 1, and commit on standby fw fails bunch of "already in use" messages during validation.&lt;/P&gt;&lt;P&gt;it seems the firewall has duplicate rules and objects, only thing is i cant see them to try and delete them!&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;</description>
      <pubDate>Fri, 26 Oct 2018 17:20:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failed-panorama-migration/m-p/237318#M67988</guid>
      <dc:creator>josggf</dc:creator>
      <dc:date>2018-10-26T17:20:51Z</dc:date>
    </item>
    <item>
      <title>Re: failed panorama migration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failed-panorama-migration/m-p/237326#M67989</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/89373"&gt;@josggf&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Did you save and export a named config backup from both the active and passive before starting the Panorama work? If so, I would disable Panorama policies, objects, templates etc, load those configs and start from scratch.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you didn't make any manual backups, your best bet is to revert to a previous configuration version. (Device -&amp;gt; Setup -&amp;gt; Load Configuration Version) and start from scratch.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As for why it failed in the first place; it's hard to say but I would definitely follow the below instructions. It sounds as though there may have been an issue with the device config bundle stage.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/80/panorama/panorama_adminguide/manage-firewalls/transition-a-firewall-to-panorama-management/migrate-a-firewall-ha-pair-to-panorama-management" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/80/panorama/panorama_adminguide/manage-firewalls/transition-a-firewall-to-panorama-management/migrate-a-firewall-ha-pair-to-panorama-management&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Luke.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Oct 2018 17:36:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failed-panorama-migration/m-p/237326#M67989</guid>
      <dc:creator>LukeBullimore</dc:creator>
      <dc:date>2018-10-26T17:36:56Z</dc:date>
    </item>
    <item>
      <title>Re: failed panorama migration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failed-panorama-migration/m-p/237327#M67990</link>
      <description>&lt;P&gt;thanks for responding&lt;/P&gt;&lt;P&gt;i do have save .xml for both firewalls. both on the firewall and on my local pc.&lt;/P&gt;&lt;P&gt;infact, the active firewall is fine, no duplicate rules as well as rule number starts from 1&lt;/P&gt;&lt;P&gt;i was able to restore HA and access to the passive firewall via revert to last saved config&lt;/P&gt;&lt;P&gt;i can attemp again, but the question is, how will it different from last time, is restoring via named config any different than revert to last saved config? as revert to last saved config broguht back the firewall with duplicate rules which i cant see&lt;/P&gt;</description>
      <pubDate>Fri, 26 Oct 2018 17:42:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failed-panorama-migration/m-p/237327#M67990</guid>
      <dc:creator>josggf</dc:creator>
      <dc:date>2018-10-26T17:42:02Z</dc:date>
    </item>
    <item>
      <title>Re: failed panorama migration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failed-panorama-migration/m-p/237334#M67993</link>
      <description>&lt;P&gt;If you import firewall(s() into Panorama do not commit from Panorama.&lt;/P&gt;&lt;P&gt;If something goes bad then it is a struggle.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Disable config sync in firewalls.&lt;/P&gt;&lt;P&gt;Device &amp;gt; High Availability &amp;gt;General&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Import config from firewall to Panorama (I guess this part is done already).&lt;/P&gt;&lt;P&gt;Do any changes needed.&lt;/P&gt;&lt;P&gt;Commit to Panorama&lt;/P&gt;&lt;P&gt;Push config to passive firewall.&lt;/P&gt;&lt;P&gt;Panorama &amp;gt; Setup &amp;gt; Operations &amp;gt; Export or push device config bundle&lt;/P&gt;&lt;P&gt;Choose firewall and click Export&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Log into firewall cli.&lt;/P&gt;&lt;P&gt;#load device-state&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Verify that all rules are in place (if not then just revert to running config to get back to clean state. reboot will do the trick also as pushed config is not committed).&lt;/P&gt;&lt;P&gt;#commit&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Perform step on second fw.&lt;/P&gt;&lt;P&gt;Enable config sync in firewalls.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Oct 2018 18:25:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failed-panorama-migration/m-p/237334#M67993</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2018-10-26T18:25:19Z</dc:date>
    </item>
    <item>
      <title>Re: failed panorama migration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failed-panorama-migration/m-p/237337#M67994</link>
      <description>&lt;P&gt;thanks,&lt;/P&gt;&lt;P&gt;this is good info, i will follow this process to commit locally from firewall&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;but the problem right now is to bring the passive firewall to a normal state, remove duplicate rules, which were pushed from panorama, are hidden in firewall, and cant be removed&lt;/P&gt;</description>
      <pubDate>Fri, 26 Oct 2018 18:32:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failed-panorama-migration/m-p/237337#M67994</guid>
      <dc:creator>josggf</dc:creator>
      <dc:date>2018-10-26T18:32:04Z</dc:date>
    </item>
    <item>
      <title>Re: failed panorama migration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failed-panorama-migration/m-p/237339#M67996</link>
      <description>&lt;P&gt;What if you disable Panorama in passive firewall.&lt;/P&gt;&lt;P&gt;Device &amp;gt; Setup &amp;gt; Management &amp;gt; Panorama Settings&lt;/P&gt;&lt;P&gt;Disable Panorama Policy and Objects&lt;/P&gt;&lt;P&gt;Disable Device and Network Template&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then go to active firewall.&lt;/P&gt;&lt;P&gt;Dashboard &amp;gt; High Availability&amp;nbsp;&lt;/P&gt;&lt;P&gt;You should be able to syncronize changes from there.&lt;/P&gt;&lt;P&gt;Be sure to push sync changes link from firewall that has correct ruleset &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Oct 2018 18:38:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failed-panorama-migration/m-p/237339#M67996</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2018-10-26T18:38:22Z</dc:date>
    </item>
    <item>
      <title>Re: failed panorama migration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failed-panorama-migration/m-p/237340#M67997</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When you add HA pair firewalls into Panorama, you need to disable HA config synchronisation during the process.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At present it seems&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/89373"&gt;@josggf&lt;/a&gt;'s configuration isn't committable (or by the sounds of it), so won't be able to do the commit to enable config sync &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I had this exact same problem before - so speaking from past experiences here &lt;span class="lia-unicode-emoji" title=":face_with_tongue:"&gt;😛&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Oct 2018 18:41:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failed-panorama-migration/m-p/237340#M67997</guid>
      <dc:creator>LukeBullimore</dc:creator>
      <dc:date>2018-10-26T18:41:39Z</dc:date>
    </item>
    <item>
      <title>Re: failed panorama migration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failed-panorama-migration/m-p/237342#M67999</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/52796"&gt;@LukeBullimore&lt;/a&gt;&amp;nbsp;yeah config sync has to be disabled. I mentioned this in my first post.&lt;/P&gt;&lt;P&gt;But I never again commit first time from Panorama even if it is single firewall. Have seen empty config without any ruleset after commit so it is always safe to load device-state from cli and commit then.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Oct 2018 18:46:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failed-panorama-migration/m-p/237342#M67999</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2018-10-26T18:46:08Z</dc:date>
    </item>
    <item>
      <title>Re: failed panorama migration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failed-panorama-migration/m-p/237343#M68000</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I thought the purpose of the device config bundle was to intentionally push a blank config, so that you wouldn't get any duplicate issues when trying to push the Panorama config?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are you saying that "Export" option instead of "Push &amp;amp; Commit" for device config bundle, then load device state gets around this?&lt;/P&gt;&lt;P&gt;But then surely Panorama would still be out of sync so when you try to push to device group/template commits will fail due to duplicates etc?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Oct 2018 19:05:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failed-panorama-migration/m-p/237343#M68000</guid>
      <dc:creator>LukeBullimore</dc:creator>
      <dc:date>2018-10-26T19:05:09Z</dc:date>
    </item>
    <item>
      <title>Re: failed panorama migration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failed-panorama-migration/m-p/237344#M68001</link>
      <description>&lt;P&gt;If you export config from Panorama then you can load it into firewall candicate config using previously mentioned command load device-state.&lt;/P&gt;&lt;P&gt;This will give you capability to verify that whole config is correct before you commit it into firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After you commit in firewall it is then safe to commit from Panorama and you don't have issues where your firewall has broken config.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Oct 2018 19:14:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failed-panorama-migration/m-p/237344#M68001</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2018-10-26T19:14:29Z</dc:date>
    </item>
    <item>
      <title>Re: failed panorama migration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failed-panorama-migration/m-p/237371#M68005</link>
      <description>&lt;P&gt;i actually have done that&lt;/P&gt;&lt;P&gt;active firewall, which has the correct ruleset, show all good&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;Running Config&lt;/TD&gt;&lt;TD&gt;&lt;IMG src="https://ip1.i.lithium.com/d954081bfa8159fd3d134fab663921420db2619a/68747470733a2f2f31302e3136392e32332e392f696d616765732f677265656e5f6c65642e706e67" border="0" /&gt;&lt;/TD&gt;&lt;TD&gt;Synchronized&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;i do still have config-sync disabled, as i think enabling it could cause more problems&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;just looking for a way to fix the passive fw somehow&lt;/P&gt;</description>
      <pubDate>Fri, 26 Oct 2018 20:06:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failed-panorama-migration/m-p/237371#M68005</guid>
      <dc:creator>josggf</dc:creator>
      <dc:date>2018-10-26T20:06:40Z</dc:date>
    </item>
    <item>
      <title>Re: failed panorama migration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failed-panorama-migration/m-p/237375#M68007</link>
      <description>&lt;P&gt;Can you try if in current state it allows you to export config from Panorama to firewall and then load device-state from cli?&lt;/P&gt;</description>
      <pubDate>Fri, 26 Oct 2018 20:45:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failed-panorama-migration/m-p/237375#M68007</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2018-10-26T20:45:22Z</dc:date>
    </item>
    <item>
      <title>Re: failed panorama migration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failed-panorama-migration/m-p/237401#M68013</link>
      <description>&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;unfortunately, i removed everything from panorama&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;but from your message, i got this idea&lt;/P&gt;&lt;P&gt;import both firewalls again, and try to export&amp;nbsp;active fw device group to passive fw again. theres a delete on the firewall that happens at this stage right, maybe it will fix things&lt;/P&gt;</description>
      <pubDate>Fri, 26 Oct 2018 22:05:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failed-panorama-migration/m-p/237401#M68013</guid>
      <dc:creator>josggf</dc:creator>
      <dc:date>2018-10-26T22:05:51Z</dc:date>
    </item>
    <item>
      <title>Re: failed panorama migration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failed-panorama-migration/m-p/237402#M68014</link>
      <description>&lt;P&gt;You can try following&lt;/P&gt;&lt;P&gt;Import active fw to Panorama.&lt;/P&gt;&lt;P&gt;Commit to Panorama.&lt;/P&gt;&lt;P&gt;Export to passive device.&lt;/P&gt;&lt;P&gt;Load device config on passive.&lt;/P&gt;&lt;P&gt;Change any settings that is different in passive (mgmt ip, hostname, HA settings etc)&lt;/P&gt;&lt;P&gt;Commit to firewall.&lt;/P&gt;&lt;P&gt;If successful so far then commit to firewall from Panorama.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Oct 2018 22:14:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failed-panorama-migration/m-p/237402#M68014</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2018-10-26T22:14:08Z</dc:date>
    </item>
    <item>
      <title>Re: failed panorama migration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failed-panorama-migration/m-p/379691#M89601</link>
      <description>&lt;P&gt;Hostname, mgmt ip and HA settings are local to FW and must not be pushed from Panorama or edited to be different before pushing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Alternatively, you can remove HA from being pushed via Panorama so HA settings are not pushed (there is a remove HA settings option at the bottom in High Availability in Panorama). Hostname and Mgmt ips are anyways not pushed by panorama.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jan 2021 22:56:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failed-panorama-migration/m-p/379691#M89601</guid>
      <dc:creator>gurjarn</dc:creator>
      <dc:date>2021-01-13T22:56:13Z</dc:date>
    </item>
  </channel>
</rss>

