How to export firewall config along with pushed panorama policies using SCP


ATTENTION Customers, All Partners and Employees: The Customer Support Portal (CSP) will be undergoing maintenance and unavailable on Saturday, November 7, 2020, from 11 am to 11 pm PST. Please read our blog for more information.

L1 Bithead

How to export firewall config along with pushed panorama policies using SCP


We tried 'scp export configuration' cmd to get firewall config. But it has only local policies.  Is there a way to get all (including shared) policies in config file using SCP protocol?


Thanks in Advance.

Cyber Elite

Which file exactly did you export out of the configuration option? The running-config.xml should include everything you are looking for, are you sure you chose the proper file? 

L1 Bithead


Thanks for the reply . I executed below cmd


scp export configuration remote-port 22 source-ip <PA_IP> from running-config.xml to username@scp_server:/


The file has only local policies. Do I need to change any configuration on Panorama? 

L3 Networker

You can run your command to export the configuration on the Panorma appliance (just like you did on the FW).  I would export both the Panorama and the FW.

L1 Bithead


Thank you. Will try that.

L7 Applicator

if you export the device state (scp export device-state), this will include the panorama config

panorama config is not stored in the running-config.xml


the device state will export a compressed file containing a few subfolders including the template xml and the pretrans xmls

Tom Piens -
New to PAN-OS or getting ready to take the PCNSE? check out
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!