Migration of Panorama which has NGFW Clustering to new Panorama

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Migration of Panorama which has NGFW Clustering to new Panorama

L2 Linker

This technical article provides an end-to-end workflow for migrating a Panorama management server in environments utilizing Next-Generation Firewall (NGFW) Clustering. Unlike traditional High Availability (HA), NGFW Clustering requires specific handling of the clustering plugin.

Technical Prerequisites & Compatibility

 

  • Software Alignment: The target Panorama must match the source's PAN-OS version and Panorama Clustering Plugin version or higher to avoid any config issues.
  • Licensing: Verify that the target Panorama has the necessary licenses to manage the specific number of cluster nodes.

 

 

  • Connectivity: Verify that the target Panorama has reachability to new firewall clusters.

Step 1:


On the source Panorama, navigate to Panorama > Operations.

Click Save named Panorama configuration snapshot to create a restore point .

Screenshot 2026-07-29 at 1.06.32 PM.png

 

 

 

 

 

Step 2:

Click Export named Panorama configuration snapshot and save the XML file externally .

 

Screenshot 2026-07-29 at 12.54.36 PM.png

 

Step 3:

 

Import the configuration XML via Panorama > Operations > Import named Panorama configuration snapshot .

 

Screenshot 2026-07-29 at 12.55.50 PM.png

 

 

Step 4:

 

Important:

 

Make sure to change the IP address of the management interface in the new Panorama when you import the configurations:

 

Screenshot 2026-07-29 at 12.58.36 PM.png

 

Step 5:

Click on Commit.



Make sure the devices show as Connected in the new Panorama as shown below:

Panorama > Summary

 

Screenshot 2026-07-29 at 1.00.44 PM.png

 

 

Note:

If the devices are not getting connected in Panorama, its most likely to the device registration key needs to be reset, please follow the below documentation to reset the keys:

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000wlJpCAI&lang=en_US

 

Step 6:


In the template stack make sure, the “Enable Clustering” is enabled or else it will throw an error:

 

Screenshot 2026-07-29 at 1.02.15 PM.png

 

Step 7:

 

Add the devices to the Clustering.

Panorama > Firewall Clusters:

 

Screenshot 2026-07-29 at 1.03.28 PM.png

 

Step 8:

 

Once done, click on commit on Panorama and the Cluster should show up as in sync in new Panorama:

 

Screenshot 2026-07-29 at 1.04.35 PM.png

 

 

 

 

 

 

0 REPLIES 0
  • 21 Views
  • 0 replies
  • 2 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!