Can we export Security Policies and Service Objects to from Firewall to Panorama?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Can we export Security Policies and Service Objects to from Firewall to Panorama?

L1 Bithead

Hi All, 

I have configured some security policies and service objects on my lab environment which consists of VM-100 Firewall for ESXi running PAN OS 8.1.0. Can I export my settings to production environment which consists of 8 ESXi hosts, Panorama and VM-500 for NSX per host. Would I be able to export securuty policies from VM-100 for ESXi to Panorama which in turn would be implemented in VM-500 for NSX? They are runnung same PAN OS but their models are differnet so could it cause any problems?   

2 REPLIES 2

Cyber Elite
Cyber Elite

@m.hassan96,

You could simply do this with the XML configuration of both configurations. You would simply take the <security/> entries that you actually want to migrate over and copy and paste it into the other configuration. Then, simply 'import' the configuration to the target system and 'load' the configuration that you've saved and ensure that it validates.

Something to think about when doing this is if your zones and addresses actually line up with your production environment in your lab. If not, you'll need to ensure that you've updated the configuration to whatever you need for your production system. 

@BPry Thanks for the help, will try that 

  • 2744 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!