Learn about the self-service Enhanced Factory Reset (EFR) feature for remediating
compromised hardware NGFWs.
| Where Can I Use This? | What Do I Need? |
- Supported NGFWs (see list of supported platforms)
|
- PAN-OS 12.2.2 and PAN-OS 12.1.11 or later
- USB flash drive (16 GB minimum)
- EFR image and PAN-OS images downloaded from the Customer
Support Portal
|
Advanced cyberattacks can compromise network security infrastructure. The
self-service Enhanced Factory Reset (EFR) provides a way to perform a remediation of
a compromised NGFW by performing a complete cleanup of the system. This procedure is
recommended when you are concerned about potential persistent compromise.
EFR wipes system disk and formats log disk. Line cards
are not affected.
Chain of trust: All EFR boot components are cryptographically signed with a
Palo Alto Networks signing key. The chain of trust is maintained during the
self-service EFR process starting from BIOS. If any component fails signature
verification, the boot stops. This ensures that only authentic Palo Alto Networks®
recovery tools can execute on the system.
Interactive process: EFR runs as an interactive process accessed from the
physical console. Before starting the disk wipe, the firewall reads the PAN-OS
images you placed on the USB drive, checks their integrity and compatibility with
your specific firewall model and PAN-OS version, and displays the results. You must
confirm before the wipe begins. If an error is detected, you can abort or retry
without rebooting.
Recovery logging: EFR logs the complete recovery process to the firewall
(
less panrepo-log usb-efr.log
). After a successful EFR, a record is
also appended to history logs (
less panrepo-log
history.log) (keyword:
efr_images).
These logs support forensic review after an incident.
The USB port protection setting does not impact
USB-based self-service factory reset (EFR), which requires enabling boot time access
to the USB port.
Supported Platforms
Self-service EFR requires an updated BIOS that supports USB boot. This BIOS update is
embedded in PAN-OS 12.2.2 and PAN-OS 12.1.11 and is automatically installed when you
upgrade to PAN-OS 12.2.2, 12.1.11 or later.
The following hardware NGFWs support self-service EFR for PAN-OS 12.2.2 or later:
| Platform | EFR Image File |
- PA-440
- PA-450
- PA-460
- PA-445
- PA-455
- PA-450R
- PA-450R-5G
- PA-455-5G
- PA-455R-5G
| PanOS_400-EFR-1.0.0.img.gz |
|
| PanOS_500s-EFR-1.0.0.img.gz |
|
| PanOS_1400-EFR-1.0.0.img.gz |
- PA-3410
- PA-3420
- PA-3430
- PA-3440
| PanOS_3400-EFR-1.0.0.img.gz |
|
| PanOS_5400-EFR-1.0.0.img.gz |
|
| PanOS_5400f-EFR-1.0.0.img.gz |
- PA-5540
- PA-5550
- PA-5560
- PA-5570
- PA-5580
| PanOS_5500-EFR-1.0.0.img.gz |
The following hardware NGFWs support self-service EFR for PAN-OS 12.1.11 or
later:
| Platform | EFR Image File |
- PA-410
- PA-415
- PA-415-5G
- PA-410R
- PA-410R-5G
| PanOS_400-EFR-1.0.0.img.gz |
Self-service EFR is not supported on VM-Series, CN-Series, Cloud NGFW, or M-Series
appliances. For virtual NGFWs and Panorama, use the standard option of replacing or
redeploying the instance with a clean image.