- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
03-01-2017 12:53 PM
What is the correct way to migrate from a PA 2020 at PANOS currently at 6.1.16 (plan on upgrading to 7.0.14; the highest version show up in the avaliable releases) to a PA 820 at PANOS 8.0?
03-02-2017 06:35 AM - edited 03-02-2017 06:51 AM
Good point!
then the option is an extra step to use another device for the "config" upgrade from 7.1 to 8.0 upgrade.
All the new PA models can only run PANOS 8.x.
So this is your path:
ps: I don't recommend PANOS 8.0 for production at this moment.
03-01-2017 01:14 PM - edited 03-01-2017 01:25 PM
Hi,
l just recently migrated config from the 4020 > 3050 series. If you can upgrade 2020 to the latest 7.1.x PAN-OS. Make sure you got same dynamic ulr filtering enabled on the both firewall. Do config validation before the commin and look for the errors if any .You might need to change/tweak xml exported file manually in case some errors with the interfaces mismatch etc.
03-01-2017 01:36 PM
@TranceforLife nailed it. Just to add though as I'm not sure the 820 is going to be able to run anything less than 8.0? I would upgrade to whatever version you are going to run on the 820 before you attempt to migrate to the PA-820, while you can certainly complete the migration even if you are not running the same PANos version it's usually less prone to issues if you at least match the version number as close as possible.
03-02-2017 01:03 AM - edited 03-02-2017 01:05 AM
All the new PA models can only run PANOS 8.x.
So this is your path:
ps: I don't recommend PANOS 8.0 for production at this moment.
03-02-2017 04:42 AM
Unfortunelty 2000 series can only support up to 7.1 PAN-OS same as 4000:
03-02-2017 06:35 AM - edited 03-02-2017 06:51 AM
Good point!
then the option is an extra step to use another device for the "config" upgrade from 7.1 to 8.0 upgrade.
All the new PA models can only run PANOS 8.x.
So this is your path:
ps: I don't recommend PANOS 8.0 for production at this moment.
03-02-2017 07:17 AM
Thanks everyone for the information.
We don't have any other PA devices currently besides the PA-2020, so the migration may be difficult. It looks like I may need to manually recreate my config, unless PA support would be able to take a saved config and run it though devices they have to do the upgrades.
When do you think you would recommend the PANOS 8 in production? I am looking at replacing our PA-2020 by May. The renewal cost for a PA-2020 services and support are close to the same price as a new PA-820 with a year of services and support.
03-02-2017 09:34 AM
@itoffice, I don't think anybody could really help you figure out when people are willing to use it prime time. One thing to keep in mind is that, while 8.0 has issues, depending on what features you are running it may work perfectly fine for you. 7.1 wasn't stable in our environment until 7.1.4, but I had some environments which were running 7.1.1 without any issues, so it really all depends on the environment.
You do not have to do a direct migration from a 8.0 box to an 8.0 box. Converting the 7.1.x config that your 2020 is capable of running to the 8.0 running on the 820 is perfectly doable as long as you edit the config to match the interfaces that the 820 actually has. Think about it, any update performed to get to 8.0 is essentially taking a 7.1.x config and making it 8.0 capable. You may run into more issues simply because there are more moving parts to perform the migration than if you were going to a device running the same version, but this is certainly doable without an intermediate device.
04-17-2017 05:28 AM
We've upgraded from PA-2050 (panos 7.1, 1 vsys) to PA-820 (panos 8.0.1, 1 vsys) the following way:
Worked as expected after migrating the 7.1 config file to PA-820 (running panos 8.0.1). Features that worked as expected: globalprotect, ipsec tunneling, bgp routing.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!