09-24-2020 02:15 PM
Customer is replacing a 2 pair of 5050's multi-vsys with 2 pair of 5250's. All of the configurations are local to the firewall with the exception of objects which are managed by Panorama. The final plan will be to have Panorama manage the firewalls appropriately. The 5050's will still be in place for a while after migrating to the 5250's. What is the best option to migrate. I've seen different scenarios. Is it best to add the firewalls to Panorama and place in the same device-group as the 5050's and do load-config-partials for the local config or just import the xml file into the 5250's? I also have the device state of the 5050's.
09-25-2020 01:53 AM
if you intend to completely manage all aspects of the 5250's through panorama, you may want to import the 5050 config into panorama and assign it to a new templates/template stack/device group, then share the 'old' objects template in the new template stack
09-25-2020 01:02 PM
Just to make the transition a bit easier, I would recommend the PAN's be on the same code version.
09-25-2020 01:03 PM
Agreed. The 5050's are 8.1.11 and so is Panorama.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!