Migrate a non-PA-7500 Series firewall with a Panorama non-clustering template to a
PA-7500 Series firewall with a Panorama clustering template.
| Where Can I Use This? | What Do I Need? |
- NGFW (Managed by PAN-OS or Panorama)
|
|
In preparation for configuring NGFW clustering on a PA-7500 Series firewall, this
task describes how to migrate from a non-PA-7500 Series firewall with an existing
Panorama non-clustering template (that has an Ethernet interface reference) to
PA-7500 Series firewall with a Panorama clustering template (that has a cluster
Ethernet interface reference). The migration process also converts a device group
that references an Ethernet interface to a device group that references a cluster
Ethernet interface.
This migration process is supported in PAN-OS 11.1.5 and later releases.
The system does not support the migration of multi-vsys regular templates to
multi-vsys cluster templates.
Perform the following prerequisites before you begin migration:
- In order to migrate a template to a clustering template, the local firewall
configuration must be available as a template and device group in Panorama. If
that isn't the case, migrate all firewall local configurations to Panorama by
following the procedure in Migrate a Firewall to Panorama
Management.
- NGFW clustering doesn't support multiple virtual systems. If your original
configuration has Multi Virtual System Capability
enabled, perform the following steps:
- Convert the multi-vsys configuration to a single virtual system and
remove the other virtual systems.
If you have
a local configuration in , remove the configuration.
- Disable Multi Virtual System Capability in the
template configuration.
- On the firewall, from , select Disable Panorama Policy and
Objects and Disable Device and Network
Template to remove the Panorama pushed configuration.
(You don't need to commit.)
- In the Panorama Template Stack for the firewall, set Default VSYS to
vsys1.
- In Panorama, push the device group to the firewall, and select
include Device and Network Templates. (This
will push both the device group and template to the firewall.)
After completing the prerequisites, you're ready to perform the migration using
Panorama. This task illustrates an example migration.