| Where Can I Use This? | What Do I Need? |
Onboarding a Next-Generation Firewall to a Device Security China tenant
differs from the standard onboarding workflow. Firewalls in China connect to
regional Strata Logging Service endpoints and authenticate with a
China-specific certificate chain.
Before you set up your firewall for Device Security in a China tenant, complete
these steps:
Onboard your tenant through Cloud Identity Engine, Strata Logging Service, and
the Device Security activation link.
-
Upgrade your firewall to run PAN-OS version 11.1.9 or later,
or version 11.2.6 or later.
On a VM-Series firewall, use a standard
VM-Series license to get the serial number. Don't use any
VM-Series license that includes Strata Logging Service
before you fetch the device certificate.