Get the device certificate to activate the site licenses on the VM-Series
firewalls.
| Where Can I Use This? | What Do I Need? |
|
|
VM-Series License Customer Support Portal (CSP) account with one of the following user roles: Super User, Standard User, Limited User, Threat Researcher, AutoFocus Trial Role, Group
Super User, Group Standard User, Group Limited User, Group Threat Researcher, Authorized
Support Center (ASC) User, and ASC Full Service User. - Superuser access to the VM-Series firewall
|
The firewall requires a device certificate to retrieve the site license entitlements and
securely access cloud services such as WildFire, AutoFocus, and Cortex Data Lake. There are
three methods for applying a site license to your VM-Series firewall—One-time password,
autoregistration PIN, and through Panorama for managed firewalls. Each password or PIN is
generated on the
Customer Support Portal and unique to your Palo Alto Networks support
account. The method you use depends on the license type used to deploy your firewall and if your
firewalls are managed by Panorama. To successfully install the device certificate, the VM-Series
firewall requires an outbound internet connection, and the following fully qualified domain
names (FQDN) and ports must be allowed on your network.
One-time password (OTP)—For VM-Series firewalls previously registered with the Palo Alto
Networks licensing server, you must generate a one-time password on the Customer Support
Portal and apply it to your VM-Series firewall. Use this method for VM-Series firewalls with a
BYOL or ELA license in small-scale, unmanaged deployments and manually deployed VM-Series
firewalls managed by Panorama.
Registration PIN—This method allows you to apply a site license to your VM-Series firewall
at initial startup. Use this method for VM-Series firewalls with usage-based licenses (PAYG),
that you bootstrap at launch or with any type of automated deployment, regardless of license
type. The autoregistration PIN enables you to automatically register your usage-based
firewalls at launch with the Customer Support Portal and retrieve site licenses.
For the VM-Series firewall on NSX-T, you can add the autoregistration PIN to your service
definition configuration so the device certificate is fetched by the firewall upon initial boot
up. See the service definition configuration for
NSX (North-South) and
NSX (East-West) for more information. If you upgrade
previously-deployed firewalls to PAN-OS version that supports device certificates, you can apply
a device certificate to those firewalls individually using a one-time password.
Use one-time passwords and autoregistration PINs before they expire. If you don't, you must
return to the Customer Support Portal to generate a new one.
https://api.paloaltonetworks.com http://apitrusted.paloaltonetworks.com https://certificatetrusted.paloaltonetworks.com https://certificate.paloaltonetworks.com
|
TCP 443
|