Automatic Deployment of Master Key to Managed Firewalls
Focus
Focus
Panorama

Automatic Deployment of Master Key to Managed Firewalls

Table of Contents


Automatic Deployment of Master Key to Managed Firewalls

PAN-OS 12.2.2 and later releases
PAN-OS 12.2.2 introduces an automated alternative way to deploy a master key to managed firewalls. After you configure a device master key on Panorama and enable automatic deployment for the associated device group, Panorama provisions the custom master key to every newly registering firewall on its first connection. Once configured, this process requires no further manual intervention as your network scales. This is the recommended approach for managing master keys across a growing fleet of managed firewalls.
It is configured entirely on Panorama — the auto-deploy configuration block does not appear on individual firewalls.
You need to meet the following two conditions for the auto-deploy workflow to work simultaneously:
  1. A device master key must be configured in the Master Key Configuration for Auto Deployed Devices section on Panorama.
  2. The Automatically push content when software device/VM or container or ZTP registers to Panorama checkbox must be enabled in the Template Stack associated with the target firewalls.
Panorama needs to be running PAN-OS version 12.2.2 or later. Managed firewalls can be on earlier PAN-OS versions, provided they support legacy master-key functionality.
Palo Alto Networks recommends the following order after upgrading Panorama to PAN-OS 12.2.2. First, configure a custom master key for Panorama itself (see Manage the Master Key from Panorama), and then configure the device master key for auto-deployment in this procedure. This ensures both Panorama and all newly onboarded firewalls immediately move off the default master key.
  1. Select PanoramaMaster Key and Diagnostics.
    The following screen appears:
  2. In the Master Key Configuration for Auto Deployed Devices section, click Edit (gear icon).
    It shows a read-only Status of Set or Unset. On a Panorama freshly upgraded to PAN-OS 12.2.2, the status defaults to Unset.
  3. Enter a New Master Key and Confirm New Master Key.
    There is no Current Master Key field in this dialog. This dialog sets the common key that will be pushed to auto-deployed firewalls; it does not change the master key of any already-connected device.
  4. Configure the Lifetime in Days and Hours (ranges from 1 hour to 18,250 days).
  5. Configure the Time for Reminder in Days and Hours (ranges from 1 hour to 365 days).
  6. Click OK to apply the auto-deployment master key configuration.
    No commit is required. The auto-deployment master key configuration is applied immediately as an operational command when you click OK.
  7. Enable the automatic content push checkbox in the Template Stack to activate auto-deployment of the master key to newly registering firewalls.
    1. Select PanoramaTemplates.
    2. Select the Template Stack associated with the target auto-deployed firewalls and click Edit.
      The device master key is associated with the Template Stack, not an individual Template, because this is where devices are associated in Panorama.
    3. In the Template Stack dialog, select the Automatically push content when software device/VM or container or ZTP registers to Panorama checkbox.
      This checkbox is a hard prerequisite for master key auto-deployment. Without it enabled in the associated template stack, Panorama will not push the device master key when a new firewall registers — even if the master key is configured in the Master Key Configuration for Auto Deployed Devices section.
    4. Click OK.
    5. Select Commit to Panorama and then Commit and Push to apply the updated template stack configuration to managed firewalls.
  8. Onboard the target firewalls to the same Template Stack where you enabled the checkbox.
    The auto-deployment of the master key applies only to firewalls whose serial numbers are registered under the Template Stack configured in the previous step. During device onboarding, add the firewall serial number to Panorama and associate it with that Template Stack. Firewalls that connect to Panorama under a different Template Stack, or with no Template Stack association, will not receive the auto-deployed master key.
  9. Verify that the master key was automatically deployed to a newly onboarded firewall.
    1. Select PanoramaManaged DevicesSummary.
    2. Locate the newly onboarded firewall. Check the two new status columns:
      • Default Master Key Enabled — should show No (custom key is now active).
      • Days Remaining to Configure Custom Master Key — should show Not Applicable.
    3. (Optional) Login to the firewall web interface to confirm directly.
      1. SelectDeviceMaster Key and Diagnostics.
      2. Confirm that a custom master key is configured and the Default Master Key Grace Period field is hidden — this confirms the device is no longer using the default master key and grace period enforcement is no longer applicable.