Configuration Migration Tool?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Configuration Migration Tool?

L1 Bithead

All,

Is there a tool to migrate the configuration of a 5050 running 8.1.11 to a 5220 running 9.0.x?

 

Regards,

 

John

1 accepted solution

Accepted Solutions

Cyber Elite
Cyber Elite

@John_Welby,

You can use expedition to do this, or you could simply export the configuration and import it directly on the firewall. Personally I like to use the installation of new hardware as a chance to manually go through and verify that everything in your rulebase is still needed, and cleanup any unused objects that may be handing out. For most people, this is easier to do in Expedition.

Just be mindful that your master password has to match to properly import all of the hashed values like phash and pre-shared keys. You'll also need to be mindful of the interface changes between a PA-5050 and PA-5220. Where the PA-5050 has copper interfaces from ethernet1/1 through ethernet1/12, your PA-5220 is only going to have ethernet1/1 through ethernet1/4. 

View solution in original post

4 REPLIES 4

L7 Applicator

The tool that we have formerly known as the "Migration Tool" is now known as Expedition. 

We have a bunch of information located there along with its own  discussion area here:

https://live.paloaltonetworks.com/t5/expedition/ct-p/migration_tool

 

I would recommend you check this out and then post there if you are unable to find out what you need. But you should be able to use that tool to do what you are asking.

 

LIVEcommunity team member
Stay Secure,
Joe
Don't forget to Like items if a post is helpful to you!

Cyber Elite
Cyber Elite

@John_Welby,

You can use expedition to do this, or you could simply export the configuration and import it directly on the firewall. Personally I like to use the installation of new hardware as a chance to manually go through and verify that everything in your rulebase is still needed, and cleanup any unused objects that may be handing out. For most people, this is easier to do in Expedition.

Just be mindful that your master password has to match to properly import all of the hashed values like phash and pre-shared keys. You'll also need to be mindful of the interface changes between a PA-5050 and PA-5220. Where the PA-5050 has copper interfaces from ethernet1/1 through ethernet1/12, your PA-5220 is only going to have ethernet1/1 through ethernet1/4. 

Thank you!

Will do.  Thanks!

  • 1 accepted solution
  • 2710 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!