nerdexam
Palo_Alto_Networks

PCNSE · Question #585

A company with already deployed Palo Alto firewalls has purchased their first Panorama server. The security team has already configured all firewalls with the Panorama IP address and added all the fir

The correct answer is C. Import Device Configuration to Panorama, followed by Export or Push Device Config Bundle.. When onboarding existing firewalls (with their own running configurations) into a new Panorama deployment, the correct workflow is: first use Panorama's 'Import Device Configuration' function (Panorama > Setup > Operations), which pulls each firewall's running configuration into

Submitted by kevin_r· Apr 18, 2026Deploy and Configure

Question

A company with already deployed Palo Alto firewalls has purchased their first Panorama server. The security team has already configured all firewalls with the Panorama IP address and added all the firewall serial numbers in Panorama. What are the next steps to migrate configuration from the firewalls to Panorama?

Options

  • AUse API calls to retrieve the configuration directly from the managed devices.
  • BExport Named Configuration Snapshot on each firewall followed by Import Named Configuration
  • CImport Device Configuration to Panorama, followed by Export or Push Device Config Bundle.
  • DUse the Firewall Migration plugin to retrieve the configuration directly from the managed devices.

How the community answered

(40 responses)
  • A
    8% (3)
  • B
    5% (2)
  • C
    73% (29)
  • D
    15% (6)

Explanation

When onboarding existing firewalls (with their own running configurations) into a new Panorama deployment, the correct workflow is: first use Panorama's 'Import Device Configuration' function (Panorama > Setup > Operations), which pulls each firewall's running configuration into Panorama as a device config bundle. After importing, you then use 'Export or Push Device Config Bundle' to organize and push those configurations under Panorama management (device groups and templates). Options A and D are incorrect because there is no native 'API retrieval' workflow or 'Firewall Migration plugin' for this task. Option B describes a manual XML snapshot export/import method that is not the recommended Panorama migration path.

Topics

#Panorama Management#Firewall Onboarding#Configuration Migration#Initial Panorama Setup

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice