How to export firewall config along with pushed panorama policies using SCP

Announcements

ATTENTION Customers, All Partners and Employees: The Customer Support Portal (CSP) will be undergoing maintenance and unavailable on Saturday, November 7, 2020, from 11 am to 11 pm PST. Please read our blog for more information.

Reply
Highlighted
L1 Bithead

How to export firewall config along with pushed panorama policies using SCP

 

We tried 'scp export configuration' cmd to get firewall config. But it has only local policies.  Is there a way to get all (including shared) policies in config file using SCP protocol?

 

Thanks in Advance.

Highlighted
Cyber Elite

Which file exactly did you export out of the configuration option? The running-config.xml should include everything you are looking for, are you sure you chose the proper file? 

Highlighted
L1 Bithead

 

Thanks for the reply . I executed below cmd

 

scp export configuration remote-port 22 source-ip <PA_IP> from running-config.xml to username@scp_server:/

 

The file has only local policies. Do I need to change any configuration on Panorama? 

Highlighted
L3 Networker

You can run your command to export the configuration on the Panorma appliance (just like you did on the FW).  I would export both the Panorama and the FW.

Highlighted
L1 Bithead

 

Thank you. Will try that.

Highlighted
L7 Applicator

if you export the device state (scp export device-state), this will include the panorama config

panorama config is not stored in the running-config.xml

 

the device state will export a compressed file containing a few subfolders including the template xml and the pretrans xmls

Tom Piens - PANgurus.com
New to PAN-OS or getting ready to take the PCNSE? check out amazon.com/dp/1789956374
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!