Offline Licensing for an ESXi HSF Cluster
Use offline license profiles to activate HSF cluster nodes in air-gapped
environments without internet connectivity to the Customer Support Portal.
| Where Can I Use This? | What Do I Need? |
|
|
- Software NGFW Credits
- HSF subscription license
- Software Firewall License plugin installed on Panorama
- Software Firewall Orchestration plugin installed on Panorama
- Customer Support Portal deployment profile with Air Gap licensing
enabled
- Panorama Air-Gap License JSON file
|
HSF offline licensing lets you deploy and license HSF cluster nodes in environments that
have no direct internet access to the Customer Support Portal. Instead of authenticating
each node online, you configure Panorama as a local offline license server using the
Software Firewall License plugin. Panorama distributes licenses to cluster nodes using
an Air-Gap License JSON file you download from the Customer Support Portal in advance
and upload to the plugin.
Offline licensing requires separate license profiles for P-Nodes and S-Nodes. Because
P-Nodes and S-Nodes typically have different vCPU footprints, separate profiles let you
size credits precisely for each node type. For example, if your deployment uses 8-vCPU
P-Nodes and 4-vCPU S-Nodes, you create two authentication codes in Customer Support
Portal — one per node type — and configure a separate offline license profile for each.
You select both profiles when configuring the HSF deployment in the Software Firewall
Orchestration plugin.
The offline license profile selection cannot be
changed after initial deployment. To increase capacity, change subscriptions, or add
features, you
update the existing profile.