Can I transfer my VM firewalls between deployment profiles?

Can I transfer my VM firewalls between deployment profiles?

9860
Created On 03/29/23 10:13 AM - Last Modified 05/28/26 08:28 AM


Question


Can I transfer my VM firewalls between deployment profiles? 

Environment


Customer Support Portal and VM dashboard

Answer


VMs are linked to the auth code in the deployment profile. Thus, a VM has to be separated from a deployment profile and then attached to another.

The VM transfer between deployment profiles is a deactivation - activation process because the VM managed by its (D1234) auth code is tied to the Deployment Profile and carries its feature and support licenses it was created for. The target deployment profile (auth code D5678) you would transfer the VM may have been set up for different license features. 

The article shows the VM deactivation - activation steps in CSP (and License database). 

Source deployment profile your VM is currently mapped to (Auth Code D1234)

Image 2023. 03. 29. at 11.54 3.jpg

Target deployment profile you want the VM to be mapped to (Auth Code D5678)

Image 2023. 03. 29. at 11.54 2.jpg

If you need to map the same VM to another Deployment Profile, follow these simple steps on CSP:

1. Deactivate the firewall from Source deployment profile (D1234)
2. Register the firewall with the same UUID and CPUID  to Target deployment profile (D5678)

Image 2023. 03. 29. at 12.02.jpg

After reboot, the VM will come up with feature licenses from the new (target) Deployment Profile (D5678) and in CSP you will find the VM under Software NGFW Devices under the new auth code.
The VM configurations will stay intact. 


Note:
The serial number of the VM firewall may possibly change, and thus appropriate changes may be needed on the panorama side. The following steps may be needed on panorama if the serial number changes:

> replace device old <old SN#> new <new SN#>
> configure
# commit


 



Additional Information


See also
Can I transfer my Panorama device between deployment profiles?
Register the VM-Series Firewall (Software NGFW Credits)
Deactivate a Firewall  
Create a Deployment Profile
 


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000kHYrCAM&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail