02-14-2023 01:52 AM - edited 02-14-2023 01:54 AM
Hello all,
I need some help to understand the complete steps to migrate from my old firewall to new one. I have a required ti change the PA-3020 to PA-3410 in a production environment. This is being managed by Panaroma which has been updated to PA-OS 10.2.How can I minimize the outage during this change.
can anyone guid me stepwise approach for this change. I know the basic but would like to know the order of operations.
New firewall is already consoled and device state has been imported . I can see all configuration has been replicated but I came to know there is an issue of the old firewall is of lower version OS we may have to degrade the new ti the same level. But my configuration has been imported without any issue and without any degradation.
will appreciate your help
02-14-2023 07:39 AM
Hi @ssshehri ,
The nice thing about Panorama is that if you add a NGFW to the same device group and template, the same config is pushed.
This document -> https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CljGCAS recommends NOT adding the new NGFW to Panorama but replacing the old S/N. Since your local config imported fine, the Panorama config will be pushed to the new NGFW as long as Panorama is PAN-OS 10.2 or higher. It says the state will change to Connected once the NGFW is configured with the Panorama IP address.
Please let me know how this works! Your request for a step-by-step process is a good idea, and we could use this thread to refine the process.
Thanks,
Tom
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!