How to migrate a Panorama Managed CNGFW (AWS) Resource with SLS Integration to a new Panorama HA Pair

How to migrate a Panorama Managed CNGFW (AWS) Resource with SLS Integration to a new Panorama HA Pair

514
Created On 12/09/25 18:53 PM - Last Modified 05/27/26 23:09 PM


Objective


How to migrate a Panorama Managed Firewall Resource with SLS Integration to a new Panorama HA Pair



Environment


  • AWS plugin: 5.4.1
  • Cloudconnector: 2.1.0
  • Cloudservices: 5.1.0
  • AWS Cloud NGFW integration



Procedure


Note: Traffic impact is during the actions being executed, as during that time, the FW will not be associated with the Panorama.

 1. Update expired device certificate on old Panorama.
     a. Install the Panorama Device Certificate

 2. Failover to old panorama

 3. On Old Panorama navigate to the AWS Plugin >> Resources section. Change the associated Device Group to
      "None" Save and Commit 
     
       ** This will cause traffic disruption for AWS CNGFW

 4. On the Cloud NGFW Console > Firewalls Page > Select FW region > select your Firewall, Go to Firewall
     settings -> Policy Management -> Select Local Rulestack and then click Save.

 5. Monitor the status of FW for the Rulestack commit to be completed. Proceed after the status is SUCCESS.

 6. On the Cloud NGFW console > Integrations > unlink any integrations with old/new panorama.

 7. Bring up a new Panorama HA pair successfully, running the same PANOS and Plugin versions as old one.
     Recommend the following plugins installed: 
     AWS - 5.4.1(or latest) Cloudconnector - 2.1.0 (or latest) Cloudservices - 5.1.0 (or latest) 

 8. On Panoramas, both Old and New need to be in the same TSG and have SLS connected, needs to be
     completed for both Panoramas:

     a. Link Panorama with SLS:
        1. Log in to the hub and launch the Strata Logging Service app.
        2. Select the Strata Logging Service instance to which you would like to move the devices.
        3. Click Inventory > Panorama Appliances > Manage Panorama Inventory.
        4. In the Device Associations page, click Add Device.
        5. Select the device you want to onboard and save changes.
        6. In the Licensed Products selection column, select Strata Logging Service. 
            (Ensure that the TSGID of SLS is the same as the TSGID associated with old Panorama.)
        7. Continue to associate product with devices:
            A. In the Device Association page, select Associate Products.
            B. In the Licensed Products selection column, select Strata Logging Service.
            C. Select the devices you want to associate with the product and save the changes.

    b. Activate SLS on Panorama 
        i. On SLS, click Inventory > Panorama Appliances > Generate OTP to create the one-time password used to
           onboard Panorama-managed firewalls to your Strata Logging Service instance. Panorama uses this OTP to
           install the logging service certificate.
       ii. On panorama, click on Panorama tab > cloudservices plugin on left pane > Configuration > Click Verify >
           add the OTP. Once added, under the status tab > verify the Strata Logging status shows ‘OK’.

 9. Ensure Cloud NGFW console user email is also the super user for the CSP in which the both Panoramas are
     registered.

10. On the Cloud NGFW console > Integrations > Add Policy Manager > Input Link name and Primary &
      Secondary Serial Number > Continue.
      a. To Confirm, Cloud NGFW tenant is linked to Panorama. Go to Panorama tab > AWS Plugins > Cloud NGFW
          > Tenants → Cloud NGFW should be seen.

11. On the Cloud NGFW > Firewalls Page, select your Firewall, Go to Firewall settings -> Policy Management ->
      Panorama > select the link (integrated in step 8). Click Save.
     a. On Panorama, click Panorama tab > AWS Plugins > Cloud NGFW > Resources -> Firewalls should be seen.

12. On Panorama, associate a Cloud DG to this Firewall and then do a push to FW.
     a. Monitor the commit status on the Panorama. Panorama > AWS Plugin > Cloud NGFW > Resources ->
         check last committed state.
     b. On the Cloud NGFW console, monitor the Global Rulestack Status on Status in Firewalls Page.
     c. Once the DG push is successful, on the CNGFW console > navigate to Region where FW is created >     
         Rulestack -> click on View XML for Cloud DG and verify the config pushed from Panorama

Note: In case of Failures, please collect TSF from the Panorama.


** Removing old panorama integration and FWs when SLS already exists in TSF **
    Note: Traffic impact is during the actions being executed, as during that time, the FW will not be
               associated with the Panorama.


 1. On Active Panorama, navigate to the AWS Plugin >> Resources section. Change the associated Device Group
      to "None." Perform Commit

     ** This will cause traffic disruption for AWSs CNGFW approximately 3-5 minutes.
   
      a. This should sync to the peered panorama, verify on that peer.


 2. On the Cloud NGFW > Firewalls Page > Select FW region > select your Firewall, Go to Firewall settings ->
     Policy Management -> Select Local Rulestack and then click Save.
 
 3. Monitor the status of FW for the Rulestack commit to be completed. Proceed after the status is SUCCESS.

 4. On the Cloud NGFW console > Integrations > unlink any integrations with old/new panorama.
 
 5. Double check following Plugin versions:
     a. AWS - 5.4.1(latest)
     b. Cloudconnector - 2.1.0(latest)
     c. Cloudservices - 5.1.0
 
 6. Ensure device certificate is installed on the panorama.

 7. Reverify that SLS is working on panorama.

 8. Ensure Cloud NGFW console user email is also the super user for the CSP in which the both Panoramas are
     registered.

 9. On the Cloud NGFW console > Integrations > Add Policy Manager > Input Link name and Primary Serial
    Number(Panorama Serial Number) > Continue.
     a. To Confirm, Cloud NGFW tenant is linked to Panorama. Go to Panorama tab > AWS Plugins > Cloud NGFW
         > Tenants → Cloud NGFW should be seen.

10. On the Cloud NGFW > Firewalls Page, select your Firewall, Go to Firewall settings -> Policy Management ->
      Panorama > select the link (integrated in step 8). Click Save.
     a. On Panorama, click Panorama tab > AWS Plugins > Cloud NGFW > Resources -> Firewalls should be seen.

11. On Panorama, associate a Cloud DG to this Firewall and then do a push to FW.
      ** This requires 2–5 minutes to complete, during which all rules will be removed from the firewall
           instances.

          Note: Traffic flow through the CNGFW will cease again upon completion, lab testing suggests
                     approximately 3–5 minutes for your configuration


     a. Monitor the commit status on the Panorama
     b. On the Cloud NGFW console, monitor the Global Rulestack Status on Status in Firewalls Page.

     Note: In case of Failures, please collect TSF from the Panorama.



Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA1Ki000000kAe8KAE&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail