236
•
Panorama
6.1
Administrator’s
Guide
©
Palo
Alto
Networks,
Inc.
Replace
an
RMA
Firewall
Troubleshooting
Tasks
on
the
Panorama
CLI:
You
cannot
perform
these
tasks
on
the
Panorama
web
interface.
(Skip
this
step
if
you
have
manually
exported
the
device
state
from
your
firewall.)
Step
6
Export
the
device
state
bundle
to
a
computer
using
SCP
or
TFTP.
The
export
command
generates
the
device
state
bundle
as
a
tar
zipped
file
and
exports
it
to
the
specified
location.
This
device
state
will
not
include
the
LSVPN
dynamic
configuration
(satellite
information
and
certificate
details).
Enter
one
of
the
following
commands:
scp export device-state device <old
serial#> to <login> @ <serverIP>: <path>
or,
tftp export device-state device <old
serial#> to <login> @ <serverIP>: <path>
Step
7
Replace
the
serial
number
of
the
old
firewall
with
that
of
the
new
replacement
firewall
on
Panorama.
By
replacing
the
serial
number
on
Panorama
you
allow
the
new
firewall
to
connect
to
Panorama
after
you
restore
the
configuration
on
the
firewall.
1.
Enter
the
following
command
in
operational
mode:
replace device old <old SN#> new <new
SN#>
2.
Go
in
to
configuration
mode
and
commit
your
changes.
configure
commit
3.
Exit
configuration
mode.
exit
Tasks
on
the
new
firewall:
You
can
use
the
firewall
web
interface
to
perform
these
tasks.
Step
8
Import
the
device
state
and
commit
the
changes
on
the
firewall.
1.
Access
the
web
interface
of
the
firewall.
2.
Select
Device > Setup > Operations
and
click
the
Import
Device State
link
in
the
Configuration
Management
section.
3.
Browse
to
locate
the
file
and
click
OK
.
4.
Click
Commit
to
save
you
changes
to
the
running
configuration
on
the
firewall.
5.
To
confirm
that
the
device
state
restored
includes
the
references
to
Panorama
pushed
polices
and
objects,
verify
that
a
little
green
icon
appears
beside
the
device
name.
Tasks
on
Panorama:
You
can
now
use
the
Panorama
web
interface
to
access
and
manage
the
replaced
firewall.
Step
9
Verify
that
you
successfully
restored
the
firewall
configuration.
1.
Access
the
Panorama
web
interface
and
select
Panorama >
Managed Devices
.
2.
Verify
that
the
Connected
column
for
the
new
firewall
has
a
check
mark.
Restore
the
Firewall
Configuration
after
Replacement
(Continued)