- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
07-29-2026 01:07 PM
This technical article provides an end-to-end workflow for migrating a Panorama management server in environments utilizing Next-Generation Firewall (NGFW) Clustering. Unlike traditional High Availability (HA), NGFW Clustering requires specific handling of the clustering plugin.
On the source Panorama, navigate to Panorama > Operations.
Click Save named Panorama configuration snapshot to create a restore point .
Click Export named Panorama configuration snapshot and save the XML file externally .
Import the configuration XML via Panorama > Operations > Import named Panorama configuration snapshot .
Important:
Make sure to change the IP address of the management interface in the new Panorama when you import the configurations:
Click on Commit.
Make sure the devices show as Connected in the new Panorama as shown below:
Panorama > Summary
Note:
If the devices are not getting connected in Panorama, its most likely to the device registration key needs to be reset, please follow the below documentation to reset the keys:
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000wlJpCAI&lang=en_US
In the template stack make sure, the “Enable Clustering” is enabled or else it will throw an error:
Add the devices to the Clustering.
Panorama > Firewall Clusters:
Once done, click on commit on Panorama and the Cluster should show up as in sync in new Panorama:
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!

