Watchguard to Palo Alto Migration Options

Showing results for 
Show  only  | Search instead for 
Did you mean: 

Watchguard to Palo Alto Migration Options

L1 Bithead



I was wondering how people have got around migrating from Watchguard to Palo Alto, the migration tool (Expedition) is not an option, or is it? Is there a fairly automated way to do this?


L4 Transporter
Did you manage to migrate the Watchguard? Can you share your experience? I also javebWarchguard migration task and could not find any advise on how to do it. Shame that no one responded to your post.

I never migrated any wathguard, even never considered as an enterprise firewall, if you have a config that can be shared with us we can take a look to see how hard will be add it to Expedition. You can send it to fwmigrate at paloaltonetworks dot com


Hi @alestevez 

Thank you for your response. Watchguard has its market share in UK and some European countries. I had 3 migration requests over the last half a year, although I did it manually or building from scratch, but this current one seems to be more conifg which will need some automation. I will try to get a config to share. 

L1 Bithead

@BatD I ended up taking a mixed approach. The security policies on the Watchguard were less than a 100 so I got the table from the web interface and moved it to an Excel spreadsheet. From there worked out the address objects and address groups and put then in PANW format in a different spreadsheet.


Once I had the basic policy looking like a PANW policy, I used Pandevice ( to write a script and load the policies and objects onto the new firewalls.


The NATs on the other hand, was a completely manual process as I had to match all the possible traffic flows. It was a bit of a process but once I got the first FW correct the other 3 were fairly straight forward.


@alestevez I agree with you, Watchguards are not common on the enterprise but as businesses grow and mature they are moving to an enterprise platform, hence the question. PA-200 wouldn't be considered enterprise for example but they are good enough for remote sites or small business that want to take a step towards modern firewalls. I can get you a configuration file from one of the old boxes.

@Jonathan_C Please send to me to fwmigrate at paloaltonetworks dot com Thanks!

Hello Albert,


is there any secure way to send you the config and see if you can help me to migrate it to PAN?



We are sorry, but we do not support Watchguard yet, even it is in the roadmap.

In your case, you may have to contact Professional Services to give you support on it.

Hi @Kaliman, what I ended up doing with this was to get the objects and policies out of the Watchguard in a spreadsheet, then using pandevice wrote some code to push it programmatically to the PANW.


Once you have that, then fix the security profile groups. I was lucky enough the migration I worked on was on some small firewalls so the policy wasn't crazy complex


hope this helps

Thank you Jonathan

  • 9 replies
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!