- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Enhanced Security Measures in Place: To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.
01-21-2022 09:04 AM
Goal is to replicate the current configuration from production 5060 firewalls to replacement 5450s firewalls.
The intent is to use Panorama to bridge the OS difference between the 5060s (highest os 8.1.x) and 5450s (start with 10.1.x).
The 5060s are HA and on panorama for object sharing but the policies (security, nat, pbf) are localized. Both are required to be pushed to the new 5450s.
With this in mind, can a device config of the 5060s be imported into the same panorama under a different device group (remove the 5060s from existing and create new on import)? And will the import include both panorama objects and localized policies?
If the import is possible, the intent would be to move the 5060s back to their original device group and templates for production support. And then place the 5450s under the new imported 5060 group which would include both objects and policies to push to them for customization as needed in preparation for production replacement
The questions at hand:
Can this be done?
If so, how best to accomplish each step?
If not possible with about approach, then how to accomplish?
Looking for assistance here. Thank you, Michael
01-27-2022 03:54 PM
Thank you for the post @Michael_Cote
Overall your approach looks functional except of importing local configuration of 5060 into Panorama will import only Firewall's local configuration. I do not think you can import back what was previously pushed by Panorama. After you import 5060 into Panorama and create a new Device Group and Template, then I would clone existing Panorama configuration from existing Device Group to new Device Group you created by import. This step will not be necessary if the objects are inherited by Device Group hierarchy. After this step is done, you might have to make some changes in Template to match interfaces of 5450 as hardware of 5060 is different than 5450. After this step if there is no validation error, you can push Device Group and Template Stack to 5450 and have it all managed by Panorama.
Kind Regards
Pavel
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!