Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

Migrate from PA-500 to PA-220

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Migrate from PA-500 to PA-220

L1 Bithead

Hi All,

 

We are planning to migrate from PA-500 to PA-220, and there are some concerns to verify.

 

KosalaBandara_0-1618979777307.png

Here are our current versions.  My concerns are,

 

1) How we can match the OS/Content versions with the new PA-220?

2) What will be the migration procedure from PA-500 to PA-220?

 

2 accepted solutions

Accepted Solutions

L0 Member

Hi,

1) You can match OS on PA-220 with the OS on PA-500. So install version 8.1.6 on PA-220 and latest content releases on both firewalls. You can also upgrade PA-500 to latest OS and match it on PA-220.


2) You can export running config from PA-500 and import it into PA-220. Just be sure it is on same PAN OS so there wont be any problems.

 

View solution in original post

Cyber Elite
Cyber Elite

you will need to downgrade the pa-220 to 8.1 as the pa-500 does not support 9.0. download both the base image and 8.1.18 (so you don't run into early 8.1 bugs)

upgrade both devices to the latest content package (if TP license has expired on the pa-500 for example, grab the -apps- version so you only load the appications, this doesn't require a license)

 

then 'save named configuration' and export, then import, load and commit on the pa-220 and you should be good to go

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

View solution in original post

6 REPLIES 6

L0 Member

Hi,

1) You can match OS on PA-220 with the OS on PA-500. So install version 8.1.6 on PA-220 and latest content releases on both firewalls. You can also upgrade PA-500 to latest OS and match it on PA-220.


2) You can export running config from PA-500 and import it into PA-220. Just be sure it is on same PAN OS so there wont be any problems.

 

Cyber Elite
Cyber Elite

Hello,

I think the PA-220 comes with 9 code already loaded. I would upgrade the PA-220 to the recommend release of the train its on then upgrade the PA-500 to match. Then transfer the code.

 

Just my thoughts.

Cyber Elite
Cyber Elite

you will need to downgrade the pa-220 to 8.1 as the pa-500 does not support 9.0. download both the base image and 8.1.18 (so you don't run into early 8.1 bugs)

upgrade both devices to the latest content package (if TP license has expired on the pa-500 for example, grab the -apps- version so you only load the appications, this doesn't require a license)

 

then 'save named configuration' and export, then import, load and commit on the pa-220 and you should be good to go

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

Thanks Luka,

Thanks Reaper

Good morning team.

Question and if it is required to go from a PA-500 to a PA-220 records, how could the process of exporting and importing records be carried out, for example the logs

 

  • 2 accepted solutions
  • 4709 Views
  • 6 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!