234
•
Panorama
6.1
Administrator’s
Guide
©
Palo
Alto
Networks,
Inc.
Replace
an
RMA
Firewall
Troubleshooting
–
Serial
number
—You
must
enter
the
serial
number
on
the
Support
portal
to
transfer
the
licenses
from
the
old
firewall
to
your
replacement
firewall.
You
will
also
enter
this
information
on
Panorama,
to
replace
all
references
to
the
older
serial
number
with
the
serial
number
of
the
replacement
firewall.
–
(Recommended)
PAN
‐
OS
version
and
the
content
database
version
—Installing
the
same
software
and
content
database
versions,
including
the
URL
database
vendor
allows
you
to
create
the
same
state
on
the
replacement
firewall.
If
you
decide
to
install
the
latest
version
of
the
content
database,
you
may
notice
differences
because
of
updates
and
additions
to
the
database.
To
verify
the
versions
installed
on
the
firewall,
access
the
firewall
system
logs
stored
on
Panorama.
Prepare
the
replacement
firewall
for
deployment.
Before
you
import
the
device
state
bundle
and
restore
the
configuration,
you
must:
–
Verify
that
the
replacement
firewall
is
of
the
same
model
and
is
enabled
for
similar
operational
capability.
Consider
the
following
operational
features:
does
it
need
to
be
enabled
for
multi
‐
virtual
systems,
support
jumbo
frames,
or
be
enabled
to
operate
in
CC
or
FIPS
mode?
–
Configure
network
access,
transfer
the
licenses,
and
install
the
appropriate
PAN
‐
OS
version
and
the
content
database
version.
You
must
use
the
Panorama
CLI
to
complete
this
firewall
replacement
process.
This
CLI
‐
based
workflow
is
available
for
the
superuser
and
panorama
‐
admin
user
roles.
If
you
have
an
LSVPN
configuration,
and
are
replacing
a
Palo
Alto
Networks
firewall
deployed
as
a
satellite
device
or
as
an
LSVPN
portal,
the
dynamic
configuration
information
that
is
required
to
restore
LSVPN
connectivity
will
not
be
available
when
you
restore
the
partial
device
state
generated
on
Panorama.
If
you
have
been
following
the
recommendation
to
frequently
generate
and
export
the
device
state
for
firewalls
in
an
LSVPN
configuration,
use
the
device
state
that
you
have
previously
exported
from
the
firewall
itself
instead
of
generating
one
on
Panorama.
If
you
have
not
manually
exported
the
device
state
from
the
firewall,
and
need
to
generate
a
partial
device
state
on
Panorama,
the
missing
dynamic
configuration
impacts
the
firewall
replacement
process
as
follows:
–
If
the
firewall
you
are
replacing
is
a
portal
device
that
is
explicitly
configured
with
the
serial
number
of
the
satellite
devices
(
Network
>
GlobalProtect
>
Portals
>
Satellite
Configuration
),
when
restoring
the
firewall
configuration,
although
the
dynamic
configuration
is
lost,
the
portal
firewall
will
be
able
to
authenticate
the
satellite
devices
successfully.
The
successful
authentication
will
populate
the
dynamic
configuration
information
and
LSVPN
connectivity
will
be
reinstated.
–
If
you
are
replacing
a
satellite
firewall
,
the
satellite
firewall
will
not
be
able
to
connect
and
authenticate
to
the
portal.
This
connection
failure
occurs
either
because
the
serial
number
was
not
explicitly
configured
on
the
firewall
(
Network
>
GlobalProtect
>
Portals
>
Satellite
Configuration
)
or
because
although
the
serial
number
was
explicitly
configured,
the
serial
number
of
the
replaced
firewall
does
not
match
that
of
the
old
firewall.
To
restore
connectivity,
after
importing
the
device
state
bundle,
the
satellite
administrator
must
log
in
to
the
firewall
and
enter
the
credentials
(username
and
password)
for
authenticating
to
the
portal.
When
this
authentication
occurs,
the
dynamic
configuration
required
for
LSVPN
connectivity
is
generated
on
the
portal.
However,
if
the
firewall
was
configured
in
a
high
availability
configuration,
after
restoring
the
configuration,
the
firewall
will
automatically
synchronize
the
running
configuration
with
its
peer
and
attain
the
latest
dynamic
configuration
required
to
function
seamlessly.