How to move a managed firewall from one Panorama to another

How to move a managed firewall from one Panorama to another

14028
Created On 05/08/24 15:01 PM - Last Modified 06/24/24 23:50 PM


Objective


This article describes the procedure to migrate a firewall that is already managed from one Panorama to another Panorama.

Environment


  • Panorama with Managed Firewalls
  • Supported PAN-OS


Procedure


  1. Export a named configuration snapshot and device state from the firewall. Always take backups before starting.
  • Device > Setup > Operations > Save named configuration snapshot
  • Device > Setup > Operations > Export named configuration snapshot
  • Device > Setup > Operations > Export device state
  1. Disable Panorama Policy and Objects
  • Device > Setup > Management > Panorama Settings
image.png
  1. Enable the box to Import Panorama Policy and Objects before disabling. If you do not select it, Panorama pushed settings will be lost:
image.png
  1. Repeat the same with Disable Device and Network Template
  2. Commit the changes to the firewall. All configuration will be local to the firewall.
  3. Perform a sc3 reset on the firewall. Log in to Firewall CLI and run the commands:
> request sc3 reset
> debug software restart process management-server
  1. Login to the new Panorama and follow the steps to add the firewall here
  2. Configure the firewall for the new Panorama IP and Auth Key. Be sure to re-enable the Panorama Policy and Objects and the Device and Network Template, by clicking the enable button:
  • Device > Setup > Management > Panorama Settings
image.png
  1. Commit your changes to the firewall
  2. Verify that the firewall is connected to Panorama
  3. Continue to import the firewall configuration to the new panorama following the admin guide:


Additional Information




Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000HD7pCAG&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language