PAN-OS 12.2.2 and later releases
PAN-OS 12.2.2 introduces an automated alternative way to deploy a master key to
managed firewalls. After you configure a device master key on Panorama and
enable automatic deployment for the associated device group, Panorama
provisions the custom master key to every newly registering firewall on its first
connection. Once configured, this process requires no further manual intervention as
your network scales. This is the recommended approach for managing master keys
across a growing fleet of managed firewalls.
It is configured entirely on Panorama — the auto-deploy configuration block
does not appear on individual firewalls.
You need to meet the following two conditions for the auto-deploy workflow to
work simultaneously:
- A device master key must be configured in the Master Key
Configuration for Auto Deployed Devices section on
Panorama.
- The Automatically push content when software device/VM or
container or ZTP registers to Panorama checkbox must be
enabled in the Template Stack associated with the target firewalls.
Panorama needs to be running PAN-OS version 12.2.2 or later. Managed
firewalls can be on earlier PAN-OS versions, provided they support legacy
master-key functionality.
Palo Alto Networks recommends the following order after upgrading Panorama to
PAN-OS 12.2.2. First, configure a custom master key for
Panorama itself
(see
Manage the Master Key from Panorama), and
then configure the device master key for auto-deployment in this procedure. This
ensures both Panorama and all newly onboarded firewalls immediately move off the
default master key.