Procedure to upgrade Firewall

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Procedure to upgrade Firewall

L0 Member

Hello all,

 


I need some help to understand the complete steps to migrate from my old firewall to new one. I have a required ti change the PA-3020 to PA-3410 in a production environment. This is being managed by Panaroma which has been updated to PA-OS 10.2.How can I minimize the outage during this change.

 

can anyone guid me stepwise approach for this change. I know the basic but would like to know the order of operations.

 

New firewall is already consoled and device state has been imported . I can see all configuration has been replicated but I came to know there is an issue of the old firewall is of lower version OS we may have to degrade the new ti the same level. But my configuration has been imported without any issue and without any degradation.

 

will appreciate your help 

1 REPLY 1

Cyber Elite
Cyber Elite

Hi @ssshehri ,

 

The nice thing about Panorama is that if you add a NGFW to the same device group and template, the same config is pushed.

 

This document -> https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CljGCAS recommends NOT adding the new NGFW to Panorama but replacing the old S/N.  Since your local config imported fine, the Panorama config will be pushed to the new NGFW as long as Panorama is PAN-OS 10.2 or higher.  It says the state will change to Connected once the NGFW is configured with the Panorama IP address.

 

Please let me know how this works!  Your request for a step-by-step process is a good idea, and we could use this thread to refine the process.

 

Thanks,

 

Tom

 

 

Help the community: Like helpful comments and mark solutions.
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!