- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
07-29-2026 01:07 PM
This technical article provides an end-to-end workflow for migrating a Panorama management server in environments utilizing Next-Generation Firewall (NGFW) Clustering. Unlike traditional High Availability (HA), NGFW Clustering requires specific handling of the clustering plugin.
On the source Panorama, navigate to Panorama > Operations.
Click Save named Panorama configuration snapshot to create a restore point .
Click Export named Panorama configuration snapshot and save the XML file externally .
Import the configuration XML via Panorama > Operations > Import named Panorama configuration snapshot .
Important:
Make sure to change the IP address of the management interface in the new Panorama when you import the configurations:
Click on Commit.
Make sure the devices show as Connected in the new Panorama as shown below:
Panorama > Summary
Note:
If the devices are not getting connected in Panorama, its most likely to the device registration key needs to be reset, please follow the below documentation to reset the keys:
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000wlJpCAI&lang=en_US
In the template stack make sure, the “Enable Clustering” is enabled or else it will throw an error:
Add the devices to the Clustering.
Panorama > Firewall Clusters:
Once done, click on commit on Panorama and the Cluster should show up as in sync in new Panorama: