Hi @Metgatz ,
I bet "load config partial" will do the trick. https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-cli-quick-start/use-the-cli/load-configurations/...
Export the config from the NGFW. Import to Panorama, but do not load. Run "load config partial" from the CLI of Panorama:
- Mode merge
- From NGFW file
- From security policy Xpath (from NGFW API browser)
- To running-config
- To device group security policy pre-rules Xpath (from Panorama API browser).
I've done load config partial a few times, but I can't remember if I moved from local to device group.
You could also use Expedition if (1) it was already (2) or you wanted to - set it up.
Thanks,
Tom
Help the community: Like helpful comments and mark solutions.