<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Firewall upgrade/replacement in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-upgrade-replacement/m-p/274983#M75207</link>
    <description>&lt;P&gt;What is the easiest way to replace old hardware(5050) with new(5520), that are in HA pair. Can i add 2 new firewalls to the HA group and failover. Or do i have to replace passive with new, make it active then remove the other.&lt;/P&gt;</description>
    <pubDate>Thu, 04 Jul 2019 21:36:29 GMT</pubDate>
    <dc:creator>raji_toor</dc:creator>
    <dc:date>2019-07-04T21:36:29Z</dc:date>
    <item>
      <title>Firewall upgrade/replacement</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-upgrade-replacement/m-p/274983#M75207</link>
      <description>&lt;P&gt;What is the easiest way to replace old hardware(5050) with new(5520), that are in HA pair. Can i add 2 new firewalls to the HA group and failover. Or do i have to replace passive with new, make it active then remove the other.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jul 2019 21:36:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-upgrade-replacement/m-p/274983#M75207</guid>
      <dc:creator>raji_toor</dc:creator>
      <dc:date>2019-07-04T21:36:29Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall upgrade/replacement</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-upgrade-replacement/m-p/275008#M75212</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/56221"&gt;@raji_toor&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;No. A platform upgrade will be a complete install/rip-and-replace. You can't add two different platforms into the same HA group, so what you are proposing simply won't work.&lt;/P&gt;&lt;P&gt;You'll want to migrate your configuration to the new 5250s and get those functional prior to the cutover date, and then when you've scheduled an outage you will actually perform the cutover to the new equipment.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jul 2019 02:33:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-upgrade-replacement/m-p/275008#M75212</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-07-05T02:33:44Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall upgrade/replacement</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-upgrade-replacement/m-p/275172#M75240</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp; I was hoping if PA had F5 like capability to add old and new hardware in same group and then activate the new ones.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jul 2019 21:38:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-upgrade-replacement/m-p/275172#M75240</guid>
      <dc:creator>raji_toor</dc:creator>
      <dc:date>2019-07-05T21:38:21Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall upgrade/replacement</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-upgrade-replacement/m-p/275291#M75249</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/56221"&gt;@raji_toor&lt;/a&gt;&amp;nbsp;Strictly speaking there is similar capability, which in fact is more flexible than the F5 solution.&amp;nbsp;If you have your firewalls fully managed by Panorama, then you can just add the new hardware to the same device groups and templates, and configuration will be syneced to the new appliences.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jul 2019 09:06:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-upgrade-replacement/m-p/275291#M75249</guid>
      <dc:creator>BatD</dc:creator>
      <dc:date>2019-07-08T09:06:03Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall upgrade/replacement</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-upgrade-replacement/m-p/298543#M78218</link>
      <description>&lt;P&gt;Dear All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can anyone please advise on any specific points to be taken care for a hardware replacements for a pair of firewall 5060 fully managed by Panorama &amp;amp; to be replaced with 5250.&amp;nbsp;&lt;/P&gt;&lt;P&gt;To me a high level plan looks like.&lt;/P&gt;&lt;P&gt;1. Prepare the new firewalls via importing device state with new mgmt ips to avoid any duplicate in network.&lt;/P&gt;&lt;P&gt;2. Test the failovers on the new pair.&lt;/P&gt;&lt;P&gt;3. Add the panorama server ip in the new firewalls.&lt;/P&gt;&lt;P&gt;4. Add the new serial numbers of the new firewalls to the Panorama under managed devices, match the threat &amp;amp; antivirus version, migrate the license?&lt;/P&gt;&lt;P&gt;5. Change the policy target to any in case of if any specific target group was selected.&lt;/P&gt;&lt;P&gt;6. Disconnect the secondary firewall to be replaced &amp;amp; power on the new 5560 unit.&lt;/P&gt;&lt;P&gt;7. Double check the priority on the firewalls to avoid any issues with taking over issues &amp;amp; make it the active.&lt;/P&gt;&lt;P&gt;8.Push the policy on the secondary firewall.&lt;/P&gt;&lt;P&gt;9. Create the device group.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any thing else needs to be taken care? Does anything related to master key is required?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2019 14:02:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-upgrade-replacement/m-p/298543#M78218</guid>
      <dc:creator>Gchander</dc:creator>
      <dc:date>2019-11-14T14:02:50Z</dc:date>
    </item>
  </channel>
</rss>

