Has anyone used Panorama to import a configuration from HA 5060s to use on new generation 5450s?

Showing results for 
Show  only  | Search instead for 
Did you mean: 
Please sign in to see details of an important advisory in our Customer Advisories area.

Has anyone used Panorama to import a configuration from HA 5060s to use on new generation 5450s?

L0 Member

Goal is to replicate the current configuration from production 5060 firewalls to replacement 5450s firewalls.


The intent is to use Panorama to bridge the OS difference between the 5060s (highest os 8.1.x)  and 5450s (start with 10.1.x).

The 5060s are HA and on panorama for object sharing but the policies (security, nat, pbf) are localized. Both are required to be pushed to the new 5450s.


With this in mind, can a device config of the 5060s be imported into the same panorama under a different device group (remove the 5060s from existing and create new on import)? And will the import include both panorama objects and localized policies?


If the import is possible, the intent would be to move the 5060s back to their original device group and templates for production support. And then place the 5450s under the new imported 5060 group which would include both objects and policies to push to them for customization as needed in preparation for production replacement


The questions at hand: 

Can this be done?

If so, how best to accomplish each step?

If not possible with about approach, then how to accomplish?


Looking for assistance here. Thank you, Michael



Cyber Elite
Cyber Elite

Thank you for the post @Michael_Cote


Overall your approach looks functional except of importing local configuration of 5060 into Panorama will import only Firewall's local configuration. I do not think you can import back what was previously pushed by Panorama. After you import 5060 into Panorama and create a new Device Group and Template, then I would clone existing Panorama configuration from existing Device Group to new Device Group you created by import. This step will not be necessary if the objects are inherited by Device Group hierarchy. After this step is done, you might have to make some changes in Template to match interfaces of 5450 as hardware of 5060 is different than 5450. After this step if there is no validation error, you can push Device Group and Template Stack to 5450 and have it all managed by Panorama.


Kind Regards


Help the community: Like helpful comments and mark solutions.
  • 1 replies
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!