PAN-OS® 8.1.2 provides a new feature to scrub swap memory
on FIPS-enabled firewalls and appliances.
New Certifications Feature
FIPS Scrub Option
If you need to decommission
or send in a FIPS-enabled Palo Alto Networks firewall or appliance
for repair, you can now scrub the swap memory to remove all cryptographic
security parameter (CSP) information from the swap partition(s).
Beginning with PAN-OS 8.1.2, you can add the scrub option to the
shutdown or restart CLI command as follows:
[restart | shutdown] system with-swap-scrub [dod | nnsa]
the scrub completes, a
log is generated
that indicates the status of the scrub.