Migrate existing rules/objects from one device group to another

Showing results for 
Show  only  | Search instead for 
Did you mean: 
Please sign in to see details of an important advisory in our Customer Advisories area.

Migrate existing rules/objects from one device group to another

L3 Networker

Does anyone have a good set of steps to convert / migrate a policy from one device group to another, including all objects/groups/etc?


L2 Linker

I've done this in Panorama without using Expedition, by loading partial configs from one DG to another by loading a partial configuration from the source device group in the running-config as per https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-move-or-copy-objects-in-configura...


You need to start with the dependencies i.e. tags, addresses, address groups, apps, app groups, profiles, profile groups etc. then you can copy the policy. You can copy all pre- or post- rules at once by using the pre-rules or post-rules Xpath.



I found an old tech note for PAN-OS 6 quite helpful for this process https://live.paloaltonetworks.com/t5/Tech-Note-Articles/Panorama-Device-Migration/ta-p/62527 even though the device migration process is largely automated today.

  • 1 replies
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!