Self-Service Enhanced Factory Reset (EFR)
Focus
Focus
Next-Generation Firewall

Self-Service Enhanced Factory Reset (EFR)

Table of Contents

Self-Service Enhanced Factory Reset (EFR)

Learn about the self-service Enhanced Factory Reset (EFR) feature for remediating compromised hardware NGFWs.
Where Can I Use This?What Do I Need?
  • Supported NGFWs (see list of supported platforms)
  • PAN-OS 12.2.2 and PAN-OS 12.1.11 or later
  • USB flash drive (16 GB minimum)
  • EFR image and PAN-OS images downloaded from the Customer Support Portal
Advanced cyberattacks can compromise network security infrastructure. The self-service Enhanced Factory Reset (EFR) provides a way to perform a remediation of a compromised NGFW by performing a complete cleanup of the system. This procedure is recommended when you are concerned about potential persistent compromise.
EFR wipes system disk and formats log disk. Line cards are not affected.
Chain of trust: All EFR boot components are cryptographically signed with a Palo Alto Networks signing key. The chain of trust is maintained during the self-service EFR process starting from BIOS. If any component fails signature verification, the boot stops. This ensures that only authentic Palo Alto Networks® recovery tools can execute on the system.
Interactive process: EFR runs as an interactive process accessed from the physical console. Before starting the disk wipe, the firewall reads the PAN-OS images you placed on the USB drive, checks their integrity and compatibility with your specific firewall model and PAN-OS version, and displays the results. You must confirm before the wipe begins. If an error is detected, you can abort or retry without rebooting.
Recovery logging: EFR logs the complete recovery process to the firewall (
less panrepo-log usb-efr.log
). After a successful EFR, a record is also appended to history logs (
less panrepo-log
                    history.log
) (keyword: efr_images). These logs support forensic review after an incident.
The USB port protection setting does not impact USB-based self-service factory reset (EFR), which requires enabling boot time access to the USB port.
Supported Platforms
Self-service EFR requires an updated BIOS that supports USB boot. This BIOS update is embedded in PAN-OS 12.2.2 and PAN-OS 12.1.11 and is automatically installed when you upgrade to PAN-OS 12.2.2, 12.1.11 or later.
The following hardware NGFWs support self-service EFR for PAN-OS 12.2.2 or later:
PlatformEFR Image File
  • PA-440
  • PA-450
  • PA-460
  • PA-445
  • PA-455
  • PA-450R
  • PA-450R-5G
  • PA-455-5G
  • PA-455R-5G
PanOS_400-EFR-1.0.0.img.gz
  • PA-505
  • PA-510
PanOS_500s-EFR-1.0.0.img.gz
  • PA-1410
  • PA-1420
PanOS_1400-EFR-1.0.0.img.gz
  • PA-3410
  • PA-3420
  • PA-3430
  • PA-3440
PanOS_3400-EFR-1.0.0.img.gz
  • PA-5450
PanOS_5400-EFR-1.0.0.img.gz
  • PA-5410
  • PA-5420
  • PA-5430
PanOS_5400f-EFR-1.0.0.img.gz
  • PA-5540
  • PA-5550
  • PA-5560
  • PA-5570
  • PA-5580
PanOS_5500-EFR-1.0.0.img.gz
The following hardware NGFWs support self-service EFR for PAN-OS 12.1.11 or later:
PlatformEFR Image File
  • PA-410
  • PA-415
  • PA-415-5G
  • PA-410R
  • PA-410R-5G
PanOS_400-EFR-1.0.0.img.gz
Self-service EFR is not supported on VM-Series, CN-Series, Cloud NGFW, or M-Series appliances. For virtual NGFWs and Panorama, use the standard option of replacing or redeploying the instance with a clean image.