Migrate existing rules/objects from one device group to another

Reply
L3 Networker

Migrate existing rules/objects from one device group to another

Does anyone have a good set of steps to convert / migrate a policy from one device group to another, including all objects/groups/etc?

L2 Linker

Re: Migrate existing rules/objects from one device group to another

I've done this in Panorama without using Expedition, by loading partial configs from one DG to another by loading a partial configuration from the source device group in the running-config as per https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-move-or-copy-objects-in-configura...

 

You need to start with the dependencies i.e. tags, addresses, address groups, apps, app groups, profiles, profile groups etc. then you can copy the policy. You can copy all pre- or post- rules at once by using the pre-rules or post-rules Xpath.

 

 

I found an old tech note for PAN-OS 6 quite helpful for this process https://live.paloaltonetworks.com/t5/Tech-Note-Articles/Panorama-Device-Migration/ta-p/62527 even though the device migration process is largely automated today.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!