- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
03-08-2023 03:38 PM
Hello everyone
I have two Palo PA-850s with software version 10.2.2 that are running in different locations. To merge all the services to one location, I must merge two Palos configurations from ACLs, NATs, and Interfaces to a single device (or the HA pair).
As far as I know, I can export the .xml config, edit it, and then import it to Palo, but does it merge with the old config or replace it?
Regards
John
03-08-2023 10:05 PM
Hi @john.mayer ,
If you import a new config it will replace the current config on the device. In the past, I found Expedition to be very useful. You can import the preferred firewall config as the base config and the secondary firewall config as the source configuration file. You will be able to move/edit interfaces, NAT rules, security policies, and services/objects. For more info, check the Expedition section we have within LiveCommunity.
03-09-2023 10:02 AM
Hello,
After you update the xml, remove the parts that you dont want to update. This way it will only update the parts you want to update.
Regards,
03-11-2023 04:48 PM
Hi @john.mayer ,
Another way you could do it is as follows:
If the sections are not too big, copying the set commands on the CLI from one NGFW to another is quick also.
Thanks,
Tom
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!