How to move a managed firewall from one Panorama to another
14028
Created On 05/08/24 15:01 PM - Last Modified 06/24/24 23:50 PM
Objective
This article describes the procedure to migrate a firewall that is already managed from one Panorama to another Panorama.
Environment
- Panorama with Managed Firewalls
- Supported PAN-OS
Procedure
- Export a named configuration snapshot and device state from the firewall. Always take backups before starting.
- Device > Setup > Operations > Save named configuration snapshot
- Device > Setup > Operations > Export named configuration snapshot
- Device > Setup > Operations > Export device state
- Disable Panorama Policy and Objects
- Device > Setup > Management > Panorama Settings
- Enable the box to Import Panorama Policy and Objects before disabling. If you do not select it, Panorama pushed settings will be lost:
- Repeat the same with Disable Device and Network Template
- Commit the changes to the firewall. All configuration will be local to the firewall.
- Perform a sc3 reset on the firewall. Log in to Firewall CLI and run the commands:
> request sc3 reset
> debug software restart process management-server
- Login to the new Panorama and follow the steps to add the firewall here
- Configure the firewall for the new Panorama IP and Auth Key. Be sure to re-enable the Panorama Policy and Objects and the Device and Network Template, by clicking the enable button:
- Device > Setup > Management > Panorama Settings
- Commit your changes to the firewall
- Verify that the firewall is connected to Panorama
- Continue to import the firewall configuration to the new panorama following the admin guide: