@BPry - when upgrading PA-3020 to PA-460, how might one be able to satisfy the PanOS requirement as device state restoration is required for migrations, when configurations are heavily managed via panorama policies?
pa-3020 max ver- 9.1.x
pa-460 min ver - 10.1.x
Determine the target PAN‐OS release—Before you Migrate to New Firewalls, ensure that the old firewall is running the same PAN‐OS release and the same content release version as is installed on the new firewall. If the old firewall does not support the PAN‐OS release that is installed on the new firewall, you must ensure that the old firewall is no more than one feature release behind. For example, if the new firewall is running PAN‐OS 8.0, then the old firewall must be running or upgraded to a PAN‐OS 7.1 release before you migrate. If the old and new firewalls are not within one feature release, you cannot use the device state export and import process to migrate due to schema changes that occur from feature release to feature release.
... View more