Offline Licensing for an ESXi HSF Cluster
Focus
Focus
Prisma AIRS

Offline Licensing for an ESXi HSF Cluster

Table of Contents

Offline Licensing for an ESXi HSF Cluster

Use offline license profiles to activate HSF cluster nodes in air-gapped environments without internet connectivity to the Customer Support Portal.
Where Can I Use This?What Do I Need?
  • Prisma AIRS
  • Software NGFW Credits
  • HSF subscription license
  • Software Firewall License plugin installed on Panorama
  • Software Firewall Orchestration plugin installed on Panorama
  • Customer Support Portal deployment profile with Air Gap licensing enabled
  • Panorama Air-Gap License JSON file
HSF offline licensing lets you deploy and license HSF cluster nodes in environments that have no direct internet access to the Customer Support Portal. Instead of authenticating each node online, you configure Panorama as a local offline license server using the Software Firewall License plugin. Panorama distributes licenses to cluster nodes using an Air-Gap License JSON file you download from the Customer Support Portal in advance and upload to the plugin.
Offline licensing requires separate license profiles for P-Nodes and S-Nodes. Because P-Nodes and S-Nodes typically have different vCPU footprints, separate profiles let you size credits precisely for each node type. For example, if your deployment uses 8-vCPU P-Nodes and 4-vCPU S-Nodes, you create two authentication codes in Customer Support Portal — one per node type — and configure a separate offline license profile for each. You select both profiles when configuring the HSF deployment in the Software Firewall Orchestration plugin.
The offline license profile selection cannot be changed after initial deployment. To increase capacity, change subscriptions, or add features, you update the existing profile.