ZTP is designed to simplify and automate the onboarding of new
firewalls to Strata Cloud Manager. ZTP streamlines the initial firewall
deployment process by allowing network administrators to ship managed firewalls
directly to their branches and automatically add the firewall to their tenant
after the ZTP firewall successfully connects to the Palo Alto Networks ZTP
service. This allows businesses to save on time and resources when deploying new
firewalls at branch locations by removing the need for IT administrators to
manually provision the new managed firewall. After successful onboarding, Strata Cloud Manager provides the means to configure and manage your
firewalls.
The ZTP cloud service supports a direct
internet connection via Ethernet or cellular interfaces (exclusively for 5G
hardware) to successfully onboard a firewall to Strata Cloud Manager. It
supports Generation 5 firewalls with standalone cellular connections or a
combination of Ethernet and cellular interfaces. This allows automated
provisioning for remote sites relying on mobile data.
If only cellular 1/1 is connected, it is automatically
configured as the management interface. If both cellular 1/1 or Ethernet 1/1 are
connected, Ethernet 1/1 serves as the primary management interface. If the
Ethernet link goes down, the firewall fails over to cellular 1/1 for management
access.
The ZTP cloud service does not support an explicit web proxy. It cannot onboard a
ZTP firewall to Strata Cloud Manager if an explicit web proxy is configured as
a gateway to the internet for your firewalls and Strata Cloud Manager.
Review and subscribe to
ZTP Service Status events to be notified about
scheduled maintenance windows, outages, and workarounds.