Replace a panorama managed device with a new device (different model)

Reply
Highlighted
L0 Member

Replace a panorama managed device with a new device (different model)

Hi All,

We need to replace old PA2020 (PAN-OS 5.0.10) that is managed via Panorama (PAN-OS 6.0) with new PA3020.

Referring to Panorama adminstrator guide 6.0, "How do I replace Panorama or a managed device in the event of a hadrware failure/RMA?"

Questions:

1) Can device state export from a PA2020 be import into PA3020 (new device)

2) Should we use Panorama CLI "replace device old <old SN#> new <new SN#>"

or

Manually add this new PA3020 SN# to Panorama. Then issue Panorama CLI "rename device-group <Groupname> device <OLD SN#> to <new SN#>

3) Any other steps that we need, beside those mentioned in Panorama admin guide?

L6 Presenter

Re: Replace a panorama managed device with a new device (different model)

Hello J,

#1. Normally there should not be any issue with importing device state as long as you have same no of configured ports and same PAN-OS

#2. There is no replace command to replace serial no. Common practice is to consider it as a new device and start a new configuration. Delete the old device.

You dont have to worry about device group, Add serial no, and then add the device to same device group and template.

Or you can do following.

"Manually add this new PA3020 SN# to Panorama. Then issue Panorama CLI "rename device-group <Groupname> device <OLD SN#> to <new SN#>"

#3 Not sure.

Regards,

Hardik Shah

Highlighted
L6 Presenter

Re: Replace a panorama managed device with a new device (different model)

#3 This is enough, if setup doesnt work than more troubleshooting is required.

Highlighted
L0 Member

Re: Replace a panorama managed device with a new device (different model)

Noted.

Anyway Panorama does support CLI "replace" (below link), but it's not document in PAN-OS CLI reference guide....

Command Line Interface Reference Guide Release 5.1

Highlighted
L7 Applicator

Re: Replace a panorama managed device with a new device (different model)

You can use the steps in the Panorama admin guide.  This does assume the models are the same interface configuration.


“Replace a Managed Device with a New Device” on p.102 of the Panorama Admin Guide

https://live.paloaltonetworks.com/docs/DOC-5057

Steve Puluka BSEET - IP Architect - DQE Communications (Metro Ethernet/ISP)
ACE PanOS 6; ACE PanOS 7; ASE 3.0; PSE 7.0 Foundations & Associate in Platform; Cyber Security; Data Center
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!