Set up and launch the PA-400 Series firewall in either
Zero Touch Provisioning (ZTP) mode or Standard mode depending on
your deployment needs.
On first startup, the PA-400 Series firewall
boots into Zero Touch Provisioning (ZTP) mode by default. ZTP mode
allows you to automate the provisioning process of a new firewall
that is added to a Panorama™ management server. To learn more about
ZTP, see
ZTP Overview. You can
also bring the PA-400 Series firewall online in standard mode. See
the instructions below to learn how to boot in ZTP or standard mode.
If you have already booted up the firewall
and selected the wrong mode, you must perform a factory reset or
private-data-reset before continuing.
Before
you can successfully add a ZTP firewall to Panorama, you must ensure
that a Dynamic Host Configuration Protocol (DHCP) server is deployed on
the network. A DHCP server is required to successfully onboard a
ZTP firewall to Panorama. The ZTP firewall is unable to connect
to the Palo Alto Networks ZTP service to facilitate onboarding without
a DHCP server.
ZTP mode is disabled
if FIPS-CC mode is enabled. If the firewall boots with FIPS-CC mode
enabled, the firewall will automatically boot in standard mode.