Hi Mate, Export the device state from the PA-220 and import and load through the CLI to the PA-400 series, that will have the merged configuration from Panorama. Make sure Panorama is running 10.1.x if adding in a PA-440. Connect the PA-440 to Panorama (point towards and add in auth key). Remove the PA-220 from the templates and device groups, and check the box for the PA-400 series. If mission critical network I would look for a maintenance window. // Import device state (firewall only) Import the device state information that was exported using the Export device state option. This includes the current running config, Panorama templates, and shared policies. If the device is a Global Protect Portal, the export includes the Certificate Authority (CA) information and the list of satellite devices and their authentication information. // https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClRcCAK best regards Rob
... View more