<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic PA 5050 &amp;amp; 5060 replacement with PA 5250 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pa-5050-amp-5060-replacement-with-pa-5250/m-p/298766#M78260</link>
    <description>&lt;DIV class="lia-message-subject lia-component-message-view-widget-subject"&gt;Firewall upgrade/replacement&lt;/DIV&gt;&lt;DIV class="lia-message-body lia-component-message-view-widget-body lia-component-body-signature-highlight-escalation lia-component-message-view-widget-body-signature-highlight-escalation"&gt;&lt;DIV class="lia-message-body-content"&gt;&lt;P&gt;Dear All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can anyone please advise on any specific points to be taken care for a hardware replacements for a pair of firewall 5060 fully managed by Panorama &amp;amp; to be replaced with 5250.&amp;nbsp;&lt;/P&gt;&lt;P&gt;To me a high level plan looks like.&lt;/P&gt;&lt;P&gt;1. Prepare the new firewalls via importing device state with new mgmt ips to avoid any duplicate in network.&lt;/P&gt;&lt;P&gt;2. Test the failovers on the new pair.&lt;/P&gt;&lt;P&gt;3. Add the panorama server ip in the new firewalls.&lt;/P&gt;&lt;P&gt;4. Add the new serial numbers of the new firewalls to the Panorama under managed devices, match the threat &amp;amp; antivirus version, migrate the license?&lt;/P&gt;&lt;P&gt;5. Change the policy target to any in case of if any specific target group was selected.&lt;/P&gt;&lt;P&gt;6. Disconnect the secondary firewall to be replaced &amp;amp; power on the new 5560 unit.&lt;/P&gt;&lt;P&gt;7. Double check the priority on the firewalls to avoid any issues with taking over issues &amp;amp; make it the active.&lt;/P&gt;&lt;P&gt;8.Push the policy on the secondary firewall.&lt;/P&gt;&lt;P&gt;9. Create the device group.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any thing else needs to be taken care? Does anything related to master key is required?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
    <pubDate>Fri, 15 Nov 2019 08:46:43 GMT</pubDate>
    <dc:creator>Gchander</dc:creator>
    <dc:date>2019-11-15T08:46:43Z</dc:date>
    <item>
      <title>PA 5050 &amp; 5060 replacement with PA 5250</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-5050-amp-5060-replacement-with-pa-5250/m-p/298766#M78260</link>
      <description>&lt;DIV class="lia-message-subject lia-component-message-view-widget-subject"&gt;Firewall upgrade/replacement&lt;/DIV&gt;&lt;DIV class="lia-message-body lia-component-message-view-widget-body lia-component-body-signature-highlight-escalation lia-component-message-view-widget-body-signature-highlight-escalation"&gt;&lt;DIV class="lia-message-body-content"&gt;&lt;P&gt;Dear All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can anyone please advise on any specific points to be taken care for a hardware replacements for a pair of firewall 5060 fully managed by Panorama &amp;amp; to be replaced with 5250.&amp;nbsp;&lt;/P&gt;&lt;P&gt;To me a high level plan looks like.&lt;/P&gt;&lt;P&gt;1. Prepare the new firewalls via importing device state with new mgmt ips to avoid any duplicate in network.&lt;/P&gt;&lt;P&gt;2. Test the failovers on the new pair.&lt;/P&gt;&lt;P&gt;3. Add the panorama server ip in the new firewalls.&lt;/P&gt;&lt;P&gt;4. Add the new serial numbers of the new firewalls to the Panorama under managed devices, match the threat &amp;amp; antivirus version, migrate the license?&lt;/P&gt;&lt;P&gt;5. Change the policy target to any in case of if any specific target group was selected.&lt;/P&gt;&lt;P&gt;6. Disconnect the secondary firewall to be replaced &amp;amp; power on the new 5560 unit.&lt;/P&gt;&lt;P&gt;7. Double check the priority on the firewalls to avoid any issues with taking over issues &amp;amp; make it the active.&lt;/P&gt;&lt;P&gt;8.Push the policy on the secondary firewall.&lt;/P&gt;&lt;P&gt;9. Create the device group.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any thing else needs to be taken care? Does anything related to master key is required?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 15 Nov 2019 08:46:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-5050-amp-5060-replacement-with-pa-5250/m-p/298766#M78260</guid>
      <dc:creator>Gchander</dc:creator>
      <dc:date>2019-11-15T08:46:43Z</dc:date>
    </item>
    <item>
      <title>Re: PA 5050 &amp; 5060 replacement with PA 5250</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-5050-amp-5060-replacement-with-pa-5250/m-p/298976#M78301</link>
      <description>&lt;P&gt;Excellent question&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here are steps from the Panorama 220 course.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Configure the management interface of the new firewall.&lt;BR /&gt;Review and update the PAN-OS software.&lt;BR /&gt;Review and update the dynamic updates.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Use the Palo Alto Networks Customer Support Portal to transfer license assignments from the serial number of the old firewall to the serial number of the new firewall&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From the Panorama command line, execute one of the following commands:&lt;BR /&gt;&amp;gt; scp export device-state device &amp;lt;old-serial#&amp;gt; to &amp;lt;login&amp;gt; @ &amp;lt;ServerIP&amp;gt;: &amp;lt;path&amp;gt;&lt;BR /&gt;&amp;gt; tftp export device-state device &amp;lt;old-serial#&amp;gt; to &amp;lt;login&amp;gt; @ &amp;lt;serverIP&amp;gt;: &amp;lt;path&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;To replace the serial number of the old firewall with the new one, execute the following commands:&lt;BR /&gt;&amp;gt; replace device old &amp;lt;old-serial#&amp;gt; new &amp;lt;new-serial#&amp;gt;&lt;BR /&gt;&amp;gt; configure&lt;BR /&gt;# commit&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Access the management user interface of the new firewall:&lt;BR /&gt;Import the device state.&lt;BR /&gt;Perform a commit after the import is complete.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On Panorama:&lt;BR /&gt;Select Commit &amp;gt; Commit and Push and Edit Selections in the Push Scope.&lt;BR /&gt;Select the Device Groups tab and select the device group that contains the new firewall.&lt;BR /&gt;Select Include Device and Network Templates.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 16 Nov 2019 18:45:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-5050-amp-5060-replacement-with-pa-5250/m-p/298976#M78301</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2019-11-16T18:45:23Z</dc:date>
    </item>
  </channel>
</rss>

