- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
09-11-2024 02:25 AM
Hello folks,
i need to migrate from PA-5250 to PA-5410, the old devices are managed via panorama using stack and stack template, the new devices are reachable with no configuration other than the management.
What is the best way to move the configuration from the PA-5250 to the new PA-5410 with less effort?
Can i just add the 5410 in the existent template stack and push all the configuration?
Following a screenshot of the actual template stack.
I'm not expert in template so i need some help.
Thank you
Bye
09-11-2024 04:56 AM
Hello @MAerre
thanks for post!
Yes, adding a new PA-5410 to existing Template Stack should be enough to push the configuration. I have done a few similar migrations in the past and except of some corner cases I have not faced any major issue.
Below are my thoughts how I would proceed with the migration.
1.) Make sure that new PA-5410 has all licenses / subscriptions activated. Also make sure that it has latest App/Threat package installed and running preferred PAN-OS.
2.) Add PA-5410 to the same Template Stack as PA-5250. Also do not forget to place PA-5410 to the same Device Group. Push Template and Device group configuration. If you are using Panorama also for collecting logs, do not forget to add PA-5410 to Panorama's log collector.
3.) Arrange maintenance window for cut over and move data plane cables from PA-5250 interfaces to PA-5410 interfaces. Be ready to clear ARP table in Layer 3 switch in the case GARP does not work.
4.) Clean up PA-5250 configuration from Panorama and decommission device.
Kind Regards
Pavel
09-11-2024 05:00 AM
Hi @MAerre ,
You should export and import the NGFW configuration 1st. This will migrate any local configuration. You will change the management IP address, of course. Then you can connect it to Panorama; add it to the same device group and template stack; and push the config. That should do it.
Thanks,
Tom
09-12-2024 01:52 AM
Hello @PavelK,
thank you for you advises; following this procedure will configure the same interfaces used on the PA-5250 to PA-5410?
once i push the configuration will the actual management settings be overwritten on PA-5410?
Thank you
09-12-2024 05:02 AM
Hi @MAerre ,
Yes, the procedure will configure the same interfaces. Interfaces 5-8 are SFP+ on the PA-5200 and copper on the PA-5400. You may need to change those. If those interfaces are configured in a template, you may need a new template.
I strongly recommend adding step 1 to @PavelK 's list export and import the config from the old to the new NGFW. You may have some items configured locally. This process will only migrate the local configuration on the NGFW. You will need to change the management interface before commit.
Thanks,
Tom
09-12-2024 07:13 AM
Thanks @TomYoung ,
tommorrow i'll do the configuration and let you know if it works or not 😉
meanwhile thanks for the advice
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!