Activate a License for Panorama-Managed Prisma Access China Through Common Services
Table of Contents
Expand all | Collapse all
Activate a License for Panorama-Managed Prisma Access China
Through Common Services
Common Services
Learn how to activate your single tenant Panorama-managed
Prisma Access China license.
Where Can I Use
This? | What Do I Need? |
---|---|
|
|
This process applies to only single tenant Panorama-managed Prisma Access China license
activation. The Panorama you use to manage Prisma Access China must be installed and
located in mainland China. If it is a hardware appliance, it
must be based in mainland China; if it is a VM-series Panorama, the processing location must be in
mainland China. These license activation instructions assume that you have already
deployed your VM-series or hardware
Panorama with the China-specific Panorama image.
Make sure that you have reviewed the requirements and prerequisites for configuring a Prisma Access China
deployment. Be aware that the CLI commands must be completed prior to
generating your one-time password (OTP).
- After you receive an email from Palo Alto Networks identifying the license you are activating, including all your add-ons and capacities, selectGet Started with Prisma SASEin your email to begin the activation process.
- Log in with your email address.
- If you have a Palo Alto Networks Customer Support account, then enter the email address you used when you registered for that account and selectNext.
- If you do not have a Palo Alto Networks Customer Support account, then.Create a New AccountPasswordNext
The service uses this email address for the user account assigned to the tenant that you use for this license. This tenant, and any others created by this email address, will have theMultitenant Superuserrole. - Choose theCustomer Support Accountnumber that you want to use to claim the license.
- ChoosePanoramamanagement for your setup and management method.
- SelectCreate Newfrom the Panorama drop-down and copy the Panorama Serial Number for use in step 16.
- Add-onsare enabled by default based on your contract.
- Level 1 support includes the following add-ons:
- Additional SC for Private App Access
- Site-to-Site and User-to-Site Access
- Level 2 support includes the following add-ons:
- Additional SC for Private App Access
- Site-to-Site and User-to-Site Access
- CASB Bundle for PA China
- DLP (individual)
- IoT Security for PA China
- SaaS Inline (individual)
- SelectCloud Identity Engineregardless if you intend to use it now or if you might use it in the future.
- Agree to the Terms and Conditions.
- Activate Now. The products and add-ons that you are activating (such as Prisma Access China or Cortex Data Lake) are now provisioned. As the subscriptions are activating, the progress status will display. You now have a tenant provisioned with instances of the products that you purchased. The tenant has one user — the Customer Support account that you used when you began this process.
- After the provisioning is complete, you receive an email confirmation.
- In the Serial Number field of the Panorama UI, enter the serial number that you copied from the license activation page, and then selectOK.Panorama will become unresponsive after you select OK. If it does not return after a few minutes, refresh your browser.
- Change the Panorama update server location to the update server in China.
- In Panorama, go toand click the gear to edit thePanoramaSetupServicesSettings.
- Change the update server toupdates.paloaltonetworks.cn.
- Update the DNS servers and NTP servers to the servers of your choice.
- Perform a local commit to Panorama from.CommitCommit to Panorama
- Upgrade the Cloud Services plugin to the minimum required version.
- From the Panorama that manages Prisma Access, selectand clickPanoramaPluginsCheck Nowto display the latest Cloud Services plugin updates.
- Downloadthe plugin version you want to install.
- After downloading the plugin,Installit.
- Open a CLI session with the Panorama appliance and enter the following commands to make sure that the Panorama appliance points to the CSP that contains Prisma Access China and Panorama Assets to retrieve its one-time password (OTP):debug plugins cloud_services set-csp-endpoint api.sb.prismaaccess.comdebug plugins cloud_services set-csp-trusted-endpoint api-trusted.sb.prismaaccess.comrequest certificate secure-bridge enableIf you do not enter these commands, the Panorama appliance will not be able to retrieve the OTP or certificate.
- Generate your one-time password (OTP) fromfor setting up Panorama.Common ServicesTenant ManagementTenant nameGenerate OTP
- After you validate your OTP, the Cloud Services page will become available. However, it might take up to two hours for the China region of CDL to show up under Settings; until it does, you can't save your configuration.