cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Who rated this post

Migration of Panorama which has NGFW Clustering to new Panorama

L2 Linker

This technical article provides an end-to-end workflow for migrating a Panorama management server in environments utilizing Next-Generation Firewall (NGFW) Clustering. Unlike traditional High Availability (HA), NGFW Clustering requires specific handling of the clustering plugin.

Technical Prerequisites & Compatibility

 

  • Software Alignment: The target Panorama must match the source's PAN-OS version and Panorama Clustering Plugin version or higher to avoid any config issues.
  • Licensing: Verify that the target Panorama has the necessary licenses to manage the specific number of cluster nodes.

 

 

  • Connectivity: Verify that the target Panorama has reachability to new firewall clusters.

Step 1:


On the source Panorama, navigate to Panorama > Operations.

Click Save named Panorama configuration snapshot to create a restore point .

Screenshot 2026-07-29 at 1.06.32 PM.png

 

 

 

 

 

Step 2:

Click Export named Panorama configuration snapshot and save the XML file externally .

 

Screenshot 2026-07-29 at 12.54.36 PM.png

 

Step 3:

 

Import the configuration XML via Panorama > Operations > Import named Panorama configuration snapshot .

 

Screenshot 2026-07-29 at 12.55.50 PM.png

 

 

Step 4:

 

Important:

 

Make sure to change the IP address of the management interface in the new Panorama when you import the configurations:

 

Screenshot 2026-07-29 at 12.58.36 PM.png

 

Step 5:

Click on Commit.



Make sure the devices show as Connected in the new Panorama as shown below:

Panorama > Summary

 

Screenshot 2026-07-29 at 1.00.44 PM.png

 

 

Note:

If the devices are not getting connected in Panorama, its most likely to the device registration key needs to be reset, please follow the below documentation to reset the keys:

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000wlJpCAI&lang=en_US

 

Step 6:


In the template stack make sure, the “Enable Clustering” is enabled or else it will throw an error:

 

Screenshot 2026-07-29 at 1.02.15 PM.png

 

Step 7:

 

Add the devices to the Clustering.

Panorama > Firewall Clusters:

 

Screenshot 2026-07-29 at 1.03.28 PM.png

 

Step 8:

 

Once done, click on commit on Panorama and the Cluster should show up as in sync in new Panorama:

 

Screenshot 2026-07-29 at 1.04.35 PM.png

 

 

 

 

 

 

Who rated this post