- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
08-11-2022 02:08 AM
Hello,
Hi Brothers,
Existing PA-500 (PAN-OS 8.1.17) and New PA-3220 (PAN-OS 8.1.17)
I tried to export the running config from FW (PA-500) as XML format and import it into the new FW (PA-3220)
Shows me a lot of error and warning as there is a lot of discrepancies as following
Details
Validation Error:
deviceconfig -> high-availability -> interface -> ha1 -> port 'ethernet1/7' is not an allowed keyword
deviceconfig -> high-availability -> interface -> ha1 -> port is invalid
deviceconfig -> high-availability -> interface -> ha1 is invalid
deviceconfig -> high-availability -> interface is invalid
deviceconfig -> high-availability is invalid
deviceconfig is invalid
tag -> Static NAT 'Static NAT' is already in use
tag -> Hide NAT 'Hide NAT' is already in use
tag -> NONAT 'NONAT' is already in use
tag -> Static NAT 'Static NAT' is already in use
tag -> Hide NAT 'Hide NAT' is already in use
tag -> NONAT 'NONAT' is already in use
tag is invalid
vsys is invalid
devices is invalid
Config 'WHDEV':
GlobalProtect App Dynamic Configuration misses information for 'uninstall'.
(Module: sslvpn)
Configuration is invalid
Warnings
Duplicate certificate subject found:
/CN=*.whitedriveproducts.com
Certificate WH_PTGW_Cert in shared expired on Apr 12 23:59:59 2022 GMT
vsys1
Warning: certificate chain not correctly formed in certificate wildcard.whitedriveproducts.com
vsys1: Rule 'whitedriveproducts.sharepoint.com' application dependency warning:
Application 'ms-office365-base' requires 'web-browsing' be allowed, but 'web-browsing' is denied in Rule 'deny_host_hopts02.wh.corp_all_other'
vsys1: Rule 'whitedriveproducts.sharepoint.com_external_resources' application dependency warning:
Is there any recommended solution to solve the issue or should i do it manually?
08-15-2022 08:54 AM
Hello there.
It appears that the 3220 already has a configuration on it. Why else would be errors like "tag already in use"
I would ensure that you have NO configuration on 3220 (other than mgmt IP), i.e, a blank config.
If it was me, I would clean up the configuration (expired certificate would be deleted) and other manual steps and then I would try commit. These errors look very simple to fix. Five minutes of work at the most.
Good luck.
08-16-2022 02:03 AM
is the pa500 have a lot configuration?
if no, you can do it manually,
otherwise, you can try using palo alto migration tool (expedition)
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!