Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

Replacing PA-5220 with a PA-3410 and need the best practice to migrate over configuration

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Replacing PA-5220 with a PA-3410 and need the best practice to migrate over configuration

L0 Member

Replacing PA-5220 with a PA-3410 and need the best practice to migrate over the configuration. Obviously the network interfaces are different and will require some cleanup, that and I know to match the PAN OS in the devices to avoid possible complications. Having not done this before what else should I look out for?

 

Thank you!

6 REPLIES 6

Cyber Elite
Cyber Elite

you summarized all you need to take care of in this case:

- make sure both systems are on the same PAN-OS

- review your interfaces as the coper/fiber ratio is different on the 3400, you may need to move some interfaces around (you can rename them in the config file before importing onto the new device)

 

other then the above two, make sure the new device is fully updated to the latest content packages (antivirus, apps&threats, ...)  equal to or greater than the 5200

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

L1 Bithead

we have the same situation , with vsys configuration on pa5220 . But the problem is that the pa3410 is bought without vsys . what are the best solutions to migrate ? does we need to purchase vsys for sure on the pa3410 or we can mitigate this?

Cyber Elite
Cyber Elite

Hello @WalidIsmail ,

Can you clarify what you mean the pa3410 was purchased without vsys? This will help us respond to your inquiry better.

 

Regards,

L1 Bithead

we have only vsys1 in the pa3410

Cyber Elite
Cyber Elite

Hello,

That is how they all start out of the box. You need to add additional if you require them.

Regards,

L1 Bithead

Hello @OtakarKlier ,

 

yes , i know that , but lets say , in the purchase process we forgot to buy the vsys and there is no budget for it  ( example) . can for example push the configuration to panorama and then from panorama push it to the new firewall ? in this case what kind of consideration and limitation we will have?

  • 1602 Views
  • 6 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!