The following elements work together to allow you to quickly onboard newly deployed ZTP
firewalls by automatically adding them to Strata Cloud Manager using the ZTP service.
Customer Support Portal (CSP) Account—The ZTP service uses the
Palo Alto Networks Customer Support Portal to register
the firewall with your account and identify the tenants that you can associate
with your ZTP firewall.
Tenant—The Strata Cloud Managertenant the ZTP firewall will be
associated with. This is a logical container for your apps and devices.
Business Administrator or higher role activates a ZTP firewall by visiting the
ZTP activation URL and the firewall
serial number and claim key. If you have more than one tenant or CSP account,
you can select which one you want to associate with the firewall.
The ZTP firewall registers with the CSP and with the Strata Cloud Manager tenant
specified during activation.
A ZTP firewall successfully registered with the ZTP service automatically appears in
Strata Cloud Manager (Settings > Firewall Setup > Device
Management).
When the firewall connects to the internet, the ZTP firewall requests a device
certificate from the CSP in order to connect to the ZTP service.
The ZTP service pushes the Strata Cloud Manager FQDN and the ZTP configuration
to the firewall.
The ZTP firewall connects to Strata Cloud Manager.