How to Import and Export Address and Address Objects
Created On 09/25/18 17:39 PM - Last Modified 11/03/21 02:53 AM
This document describes how to import and export address and address objects from one firewall to another without having to redefine them manually. This document can be used in scenarios where multiple Palo Alto Networks firewalls at different sites want to leverage an existing address/ address-group configuration.
- Palo Alto Firewall.
- Verify from the existing firewall, that Address and Address-objects exists using GUI: Objects > Addresses and GUI: Objects > Address Groups
- From the CLI, set the configuration output format to 'set' and extract address and address/group information:
> set cli config-output-format set > configure Entering configuration mode  # show address set address google fqdn google.com set address google description "FQDN address object for google.com"set address mgmt-L3 ip-netmask 10.66.18.0/23 set address mgmt-L3 description "IP Netmask address object for mgmt-L3" set address trust-L3 ip-netmask 10.66.20.0/23 set address untrust-L3 ip-netmask 10.66.24.0/23 set address dmz-L3 ip-netmask 10.66.22.0/23  # show address-group set address-group Inside static [ dmz-L3 mgmt-L3 trust-L3 ] set address-group Outside static [ google untrust-L3 ] 
- Copy all the 'set' commands from the above output to a Notepad file, and edit as desired for other firewalls. For address-groups, make sure that the entire set command is copied/pasted including the '[ ]' part
- Login into the CLI of other firewalls, move the CLI config-output-format to 'set' and paste the commands into the configuration mode and commit the configuration.
> set cli config-output-format set > configure # <paste all the set commands here> # commit