PANORAMA CHANGE HARDWARE

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

PANORAMA CHANGE HARDWARE

L3 Networker

Hello world,

I must change a cluster  PA2050 by PA5020 (with the same configuration) and this PA are Managed by Panorama. ( all policies objects are created on Panorama but not policies)

Somebody know how to make this change? which steps?

thanks for your help

Regards

1 accepted solution

Accepted Solutions

L4 Transporter

As said above, should be pretty straight forward from 2050 to 5020, as they have the same number of ports.

If your object are pushed through Panorama, but you're policies are local, you will need to push the object from Panorama to the new device first.  Panorama objects are not included in the config file when you do a backup locally on the device.

Then you should be able to just load a config backup from you old device on the new device.

- Tor

View solution in original post

5 REPLIES 5

L4 Transporter

Alle,

We should be able to take the same policy configured for what was in place (2050) and apply it to the new (5020) assuming that they will be running the same version. If you were going from the 5020 to the 2050, I'd say this would be a little more difficult.

Should be straight forward...

let me know if we can clarify anything more specific you run into.

Thanks!

Please do not forget to mark and 'Helpful' or 'Correct' replies.

L4 Transporter

As said above, should be pretty straight forward from 2050 to 5020, as they have the same number of ports.

If your object are pushed through Panorama, but you're policies are local, you will need to push the object from Panorama to the new device first.  Panorama objects are not included in the config file when you do a backup locally on the device.

Then you should be able to just load a config backup from you old device on the new device.

- Tor

L7 Applicator

I would use the following steps:

  • Configure the basic management setup on the new PA
  • Add this to Panorama
  • Add the new PA to the same group and template as the current
  • Push the Panorama settings
  • Export the existing PA configuration
  • Save the new PA state for potential rollback
  • Import and apply the existing PA settings to the new PA
  • Edit the mgmt address and host names back to the new PA settings
  • commit the changes and confirm the configurations look good
  • Schedule a cable swing for the production interfaces from old to new PA
Steve Puluka BSEET - IP Architect - DQE Communications (Metro Ethernet/ISP)
ACE PanOS 6; ACE PanOS 7; ASE 3.0; PSE 7.0 Foundations & Associate in Platform; Cyber Security; Data Center

thks for your help

I follow this steps and all it's ok !

Glad to hear all went well.  We like the uneventful cuts.

Steve Puluka BSEET - IP Architect - DQE Communications (Metro Ethernet/ISP)
ACE PanOS 6; ACE PanOS 7; ASE 3.0; PSE 7.0 Foundations & Associate in Platform; Cyber Security; Data Center
  • 1 accepted solution
  • 5796 Views
  • 5 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!