: Fast Delicensing in AWS Auto scaling Groups
Focus
Focus

Fast Delicensing in AWS Auto scaling Groups

Table of Contents

Fast Delicensing in AWS Auto scaling Groups

Automate VM-Series firewall license release in AWS Auto Scaling Groups to optimize cloud resources and ensure license availability.
When an AWS Auto Scaling Group (ASG) terminates a VM-Series firewall instance, the license is not automatically released, it stays in a consumed state in the Customer Support Portal (CSP) until you manually de-register it. Fast Delicensing, configured as part of the Panorama plugin for AWS, automates this process so that FW Flex credits are returned to your available pool within 30 minutes of each termination event.
The Fast Delicensing architecture involves several core components that interact to manage your VM-Series firewall licenses:
  • Palo Alto Networks Panorama - Serves as the centralized management platform for your VM-Series firewalls. It hosts cloud services plugins and manages configurations, device groups, and template stacks.
  • AWS Cloud Services Plugins - Plugins that interface with cloud providers to monitor scaling groups, detect instance termination events, and orchestrate the delicensing process.
  • AWS Auto Scaling Groups (ASG) - Native cloud services that dynamically manage your VM-Series firewall instances, automatically scaling them based on predefined metrics or health checks.
  • Customer Support Portal (CSP) - It releases VM-Series firewall licenses, making them available for other deployments in your network.
Once enabled, the Delicensing Manager periodically polls the ASGs you configure. It detects two types of termination events: scale-in events, where the ASG shrinks the fleet in response to reduced demand, and instance failures, where the ASG replaces a firewall that has failed its health probe.
These events are then cross-referenced with your Panorama's device list to confirm a disconnected state and retrieve the serial number. Once an instance is verified as terminated, the plugin sends an API request to the CSP for license release and removes the stale device entry from your Panorama's Device Group and Template Stack if configured.