Prepare a bootable USB flash drive with the EFR image and PAN-OS images required for
a self-service Enhanced Factory Reset.
| Where Can I Use This? | What Do I Need? |
- Supported NGFWs (see list of supported platforms)
|
- PAN-OS 12.2.2 and PAN-OS 12.1.11 or later
- USB flash drive (16 GB minimum)
- A Windows, Linux, or macOS computer with a USB port
- EFR image and PAN-OS images downloaded from the Customer
Support Portal
|
Before performing a self-service Enhanced Factory Reset (EFR), you must prepare a
bootable USB flash drive that contains the EFR image for your firewall platform
family and the PAN-OS images you want to reinstall.
When preparing the USB drive, follow these rules for the PAN-OS images you place in
the IMAGES folder:
- The USB drive can contain a maximum of two PAN-OS images: one base image and
one maintenance release (MR) image.
- A base image is required. An MR image is optional but if included, the
corresponding base image must also be present.
- The base image and MR image must be from the same release train (same
major.minor version). For example, PAN-OS 12.2.2 and PAN-OS 12.2.5 for the
same model are compatible, but PAN-OS 12.1.2 and PAN-OS 12.2.2 are not.
- Both images must match the platform family of the firewall being recovered.
- EFR cannot be used to upgrade to a new major.minor release. For example, if
the firewall is running 12.2.x, you can only reinstall 12.2.x images.
Before you begin:
- Save all firewall configuration, HA state, and cluster configurations before the
EFR process. The EFR wipes the system disk completely. You must manually reapply
your configuration after the firewall restores.
- Identify your firewall's platform family and the PAN-OS version currently
running on the device (review
show system info
or
Dashboard > General
Information).