Migrating from PA-5250 to PA-5410

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Migrating from PA-5250 to PA-5410

L1 Bithead

Hello folks,

 

i need to migrate from PA-5250 to PA-5410, the old devices are managed via panorama using stack and stack template, the new devices are reachable with no configuration other than the management.

What is the best way to move the configuration from the PA-5250 to the new PA-5410 with less effort?

Can i just add the 5410 in the existent template stack and push all the configuration?

Following a screenshot of the actual template stack.

I'm not expert in template so i need some help.

 

Thank you

PA.jpg

Bye

2 REPLIES 2

Cyber Elite
Cyber Elite

Hello @MAerre

 

thanks for post!

 

Yes, adding a new PA-5410 to existing Template Stack should be enough to push the configuration. I have done a few similar migrations in the past and except of some corner cases I have not faced any major issue.

 

Below are my thoughts how I would proceed with the migration.

 

1.) Make sure that new PA-5410 has all licenses / subscriptions activated. Also make sure that it has latest App/Threat package installed and running preferred PAN-OS.

 

2.) Add PA-5410 to the same Template Stack as PA-5250. Also do not forget to place PA-5410 to the same Device Group. Push Template and Device group configuration. If you are using Panorama also for collecting logs, do not forget to add PA-5410 to Panorama's log collector.

 

3.) Arrange maintenance window for cut over and move data plane cables from PA-5250 interfaces to PA-5410 interfaces. Be ready to clear ARP table in Layer 3 switch in the case GARP does not work.

 

4.) Clean up PA-5250 configuration from Panorama and decommission device.

 

Kind Regards

Pavel

Help the community: Like helpful comments and mark solutions.

Cyber Elite
Cyber Elite

Hi @MAerre ,

 

You should export and import the NGFW configuration 1st.  This will migrate any local configuration.  You will change the management IP address, of course.  Then you can connect it to Panorama; add it to the same device group and template stack; and push the config.  That should do it.

 

Thanks,

 

Tom

Help the community: Like helpful comments and mark solutions.
  • 75 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!