Migration Issue from PA-500 (HA-Active/passive) to PA-3220 with HA-Active/Passive

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Migration Issue from PA-500 (HA-Active/passive) to PA-3220 with HA-Active/Passive

Hello,

 

Hi Brothers,

 

Existing PA-500 (PAN-OS 8.1.17) and New PA-3220 (PAN-OS 8.1.17)

 

I tried to export the running config from FW (PA-500) as XML format and import it into the new FW (PA-3220)

 

Shows me a lot of error and warning as there is a lot of discrepancies as following 

Details
Validation Error:
deviceconfig -> high-availability -> interface -> ha1 -> port 'ethernet1/7' is not an allowed keyword
deviceconfig -> high-availability -> interface -> ha1 -> port is invalid
deviceconfig -> high-availability -> interface -> ha1 is invalid
deviceconfig -> high-availability -> interface is invalid
deviceconfig -> high-availability is invalid
deviceconfig is invalid
tag -> Static NAT 'Static NAT' is already in use
tag -> Hide NAT 'Hide NAT' is already in use
tag -> NONAT 'NONAT' is already in use
tag -> Static NAT 'Static NAT' is already in use
tag -> Hide NAT 'Hide NAT' is already in use
tag -> NONAT 'NONAT' is already in use
tag is invalid
vsys is invalid
devices is invalid
Config 'WHDEV':
GlobalProtect App Dynamic Configuration misses information for 'uninstall'.
(Module: sslvpn)
Configuration is invalid
Warnings
Duplicate certificate subject found:
/CN=*.whitedriveproducts.com
Certificate WH_PTGW_Cert in shared expired on Apr 12 23:59:59 2022 GMT
vsys1
Warning: certificate chain not correctly formed in certificate wildcard.whitedriveproducts.com
vsys1: Rule 'whitedriveproducts.sharepoint.com' application dependency warning:
Application 'ms-office365-base' requires 'web-browsing' be allowed, but 'web-browsing' is denied in Rule 'deny_host_hopts02.wh.corp_all_other'
vsys1: Rule 'whitedriveproducts.sharepoint.com_external_resources' application dependency warning:

 

Is there any recommended solution to solve the issue or should i do it manually? 

 

 

2 REPLIES 2

Cyber Elite
Cyber Elite

Hello there.

It appears that the 3220 already has a configuration on it.  Why else would be errors like "tag already in use"
I would ensure that you have NO configuration on 3220 (other than mgmt IP), i.e, a blank config.
If it was me, I would clean up the configuration (expired certificate would be deleted) and other manual steps and then I would try commit.  These errors look very simple to fix.  Five minutes of work at the most.

 

Good luck.

Help the community: Like helpful comments and mark solutions

L2 Linker

is the pa500 have a lot configuration?
if no, you can do it manually,

otherwise, you can try using palo alto migration tool (expedition)

 

  • 1394 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!