Deploy new, or renew expiring master keys, to firewalls, log collectors, and WF-500
appliances from the Panorama™ management server.
| Where Can I Use This? | What Do I Need? |
- NGFW (Managed by Panorama)
|
- Device management license
|
Panorama, firewalls, Log Collectors, and WF-500 appliances use a
master key to encrypt sensitive elements in the configuration and they have a
default master key they use to encrypt passwords and configuration elements. As part
of a standard security practice, you should replace the default master key and
change the key on each individual firewall, Log Collector, WildFire appliance, and
Panorama before it expires.
To strengthen your security posture, configuring a unique master key for Panorama and for each managed firewall. By configuring unique master keys,
you can ensure that a compromised master key does not compromise the configuration
encryption of your entire deployment. Unique master keys are supported only for
Panorama and managed firewalls. Log Collectors and WildFire appliances must share
the same master key as Panorama. For Panorama or managed firewalls
in a high availability (HA) configuration, you must deploy the same master key for
both HA peers as the master key is not synchronized across HA peers. Similarly, for
Panorama andSD-WAN deployments, all devices
participating in the cluster must share the same master key to maintain cluster
synchronization.
AES-256-CBC is the default encryption algorithm for master keys because Panorama and
its managed devices must use the same encryption level. AES-256-GCM is supported
from PAN-OS 10.0 onwards. If all managed firewalls run PAN-OS 10.0 or
later, Panorama and all managed devices can use AES-256-GCM.
Palo Alto Networks recommends using AES 256-GCM level 2 for master key
encryption.
Configuring a unique master key also eases the operational burden of updating your
master keys. By configuring a unique master key for a managed firewall, you can
update each master key individually without the need to coordinate changing the
master key across a large number of managed firewalls.
When replacing a master key, you must enter the current master key value to
configure a new one.
Keep track of all master keys deployed to managed firewalls, Log Collectors, and
WildFire appliances — master keys cannot be recovered. If the current master key
is lost, the only recovery method is a factory reset.
Default Master Key Replacement
(PAN-OS 12.2.2 and later
releases)
The default master key is publicly known
and poses a critical security risk. Starting with PAN-OS 12.2.2, the system enforces
replacement of the default master key with a custom master key within a configurable
grace period.
When the system detects the default
master key, a 60-day grace period begins automatically. If you need additional time,
you can extend the grace period to a maximum of 120 days, but you must configure
this extension before the current grace period expires. This 120-day limit is
absolute and measured from the original trigger event — an upgrade, factory reset,
or first power-on. The extension does not add a new window from the date you
configure it. The system always calculates the final deadline from the date of the
original trigger event, regardless of when you configure the extension. You cannot
extend the grace period beyond 120 days under any circumstances.
After the grace period expires, the
system blocks all standard configuration commits, commit-all jobs, and HA
synchronization until you configure a custom master key. Auto-commits and dynamic
updates, including content and antivirus deployments, continue to operate normally
during this blocked state.
Palo Alto Networks strongly recommends
configuring a custom master key immediately after upgrading to PAN-OS 12.2.2. Do
not wait for the default grace period of 60 days to approach expiry.
The countdown begins when any
of the following trigger events are detected:
You upgrade a device to PAN-OS 12.2.2 or a later version.
You restore a device running PAN-OS 12.2.2 or a later version to
factory default settings.
You power on a new factory-default device running PAN-OS 12.2.2 or
a later version for the first time.
If a grace period timer is already running, upgrading or downgrading
between PAN-OS 12.2.2 and later versions does not restart the timer. If the
grace period has already expired and you downgrade to another PAN-OS 12.2.2 or
later release, the timer does not restart and commits fail immediately on the
downgraded version.
Manual Deployment of Master Key
Log in to the Panorama Web
Interface.
(
Best Practice) Select
Commit and
Commit and Push any pending configuration
changes.
Panorama must re-encrypt data using the new master key. To ensure all
configuration elements are encrypted with the new master key, you should
commit all pending changes before deploying the new master key.
Configure a unique master key for a managed firewall.
(
HA only) Disable Config Sync for managed firewalls.
This step is required before deploying a new master key to a firewall
HA pair.
Select and select the
Template containing the managed
firewall HA configuration.
Edit the HA Pair Settings Setup.
Disable (clear) Enable Config Sync and
click OK.
Commit and Commit and Push
your configuration changes.
Ensure there are no pending commits on the target managed firewalls
before deploying the master key.
A pending commit on the firewall may cause the master key
deployment to fail or produce inconsistent results. Commit any
pending firewall configuration changes before proceeding.
Select and
Deploy Master Key.
Select a managed firewall and
Change the master
key.
If you want to deploy a unique master key for a specific set of
managed firewalls, you can select those specific managed
firewalls as well.
Configure the master key in the
Master Key
dialog:
The dialog is divided into two sections:
Set up a new Master Key — configure the master key
credentials and validity settings:
Enter the Current Master Key
if one is already set on the device. If you are
replacing the default master key, the field is
pre-populated with a masked value (*);
leave it as-is or clear it before entering the new
key.
(Optional) Enable (check) Stored
on HSM if the master key is encrypted
on a Hardware Security Module (HSM).
Enter the New Master Key and
Confirm New Master Key.
Configure the Lifetime in
Days and
Hours (ranges from 1 hour
to 18,250 days).
Configure the Time for
Reminder in
Days and
Hours (ranges from 1 hour
to 365 days).
Auto-renewal & Grace Period — this section is
informational only. It states: "To simplify management,
you can enable auto-renewal and customize the grace
period under Master Key and Diagnostics in your template
or template stack." Auto-renewal and grace period
settings are not configurable in this dialog. Configure them
separately under , navigating to in the relevant template or template
stack.
Click OK.
The new master key is
automatically pushed to your managed firewalls after you click
OK. Proceed only if you are certain you
are ready to change the master key for your managed
firewalls.
Verify that the master key was deployed successfully to all selected
managed firewalls.
A System log generates when you deploy a new master key from
Panorama.
Before verifying via system logs, check the task status in the
task manager to confirm whether the deployment succeeded or
failed.
(
Optional) Configure master key renewal options for your
managed firewalls.
This step configures master key renewal settings (auto-renew
interval), not the master key itself. Configure this to
automatically renew the master key deployed on the managed firewalls
associated with the selected template. Otherwise, the master key
expires per the configured lifetime and you must deploy a new
one.
Select and select the
Template containing the target
managed firewalls.
Edit the Master Key settings and
configure the Auto Renew With Same Master
Key setting.
Click OK.
Commit and Commit and Push
All Changes to push to all managed
devices.
Configure the master key on Panorama.
(
HA only) Disable the HA configuration for Panorama.
This step is required to successfully change the master for both
Panorama HA peers. You are unable to commit configuration changes on
the secondary HA peer when Panorama is in an HA configuration.
Select and edit the HA Setup.
Disable (uncheck) Enable HA and click
OK.
Commit and Commit to
Panorama.
Select and
Commit your changes to apply
the HA configuration change before proceeding.
Commit the HA disable change to Panorama before configuring the
master key. This ensures Panorama is in a clean state before the
master key is applied.
Select and configure the master key.
If renewing a master key, enter the Current Master
Key. If you are replacing the default master
key with a new master key, do not specify a
Current Master Key.
Configure the New Master Key and
Confirm Master Key.
Configure the master key Lifetime and
Time for Reminder.
Click OK.
The new master key is
automatically committed to Panorama after you click
OK. Proceed only if you are
certain you are ready to change the master key on
Panorama.
(
Optional) Configure the Panorama master key to automatically
renew.
Configure this setting to automatically renew the master key deployed
on Panorama. Otherwise, the master key expires per the configured
master key lifetime and you must deploy a new master key.
Select and edit the Master
Key setting.
Configure the Auto Renew With Same Master
Key setting.
Click OK.
Select and
Commit your changes.
(
HA only) Repeat this step to configure an identical master
key on the secondary HA peer.
You must manually configure an identical master key on the primary
and secondary HA peers when Panorama is in an HA configuration. The
master key is not synchronized between the primary and secondary HA
peers.
If the secondary Panorama HA peer is in a passive state, you
cannot commit configuration changes directly on it. You must
first perform a manual failover to promote the passive peer to
active state before configuring the master key. After the
failover completes, configure the same master key on this peer
to ensure commits and HA synchronization succeed when the peer
transitions back to its original role.
Deploy the master key to Log Collectors.
The master key configured for your Log Collectors must be identical to the
master key configured for Panorama.
Select and
Deploy Master Key.
Select all devices and
Change the master key.
Configure the master key:
If renewing a master key, enter the Current Master
Key. If you are replacing the default master
key with a new master key, do not specify a
Current Master Key.
Specify the New Master Key and
Confirm Master Key.
Configure the master key Lifetime and
Time for Reminder.
Click OK.
The new master key is
automatically pushed to your Log Collectors after you click
OK. Proceed only if you are
certain you are ready to change the master key for your Log
Collectors.
Verify that the master key was deployed successfully to all selected
devices.
A System log generates when you deploy a new master key from
Panorama.
Deploy the master key to managed WildFire appliances.
The master key configured your WildFire appliances must be identical to the
master key configured for Panorama.
Select and
Deploy Master Key.
Select all devices and
Change the master key.
Configure the master key:
If renewing a master key, enter the Current Master
Key. If you are replacing the default master
key with a new master key, do not specify a
Current Master Key.
Specify the New Master Key and
Confirm Master Key.
Configure the master key Lifetime and
Time for Reminder.
Click OK.
The new master key is
automatically pushed to your WildFire appliances after you
click OK. Proceed only if you are
certain you are ready to change the master key for your
WildFire appliances.
Verify that the master key was deployed successfully to all selected
devices.
A System log generates when you deploy a new master key from
Panorama.
(
HA Panorama only) Reconfigure the Panorama HA configuration.
Repeat this step for both the primary and secondary Panorama HA peers.
Select and edit the HA Setup.
Enable (check)
Enable HA and click
OK.
Commit and
Commit to
Panorama.
(
HA Firewalls only) Enable config sync for managed firewalls.
Select and select the
Template containing
the managed firewall HA configuration.
Edit the HA Pair Settings
Setup.
Enable (check)
Enable Config Sync and click
OK.
Commit and Commit and Push
your configuration changes.
Automatic Deployment of Master Key to Managed Firewalls
PAN-OS 12.2.2 and later releases
PAN-OS 12.2.2 introduces an automated alternative way to deploy a master key to
managed firewalls. After you configure a device master key on Panorama and
enable automatic deployment for the associated device group, Panorama
provisions the custom master key to every newly registering firewall on its first
connection. Once configured, this process requires no further manual intervention as
your network scales. This is the recommended approach for managing master keys
across a growing fleet of managed firewalls.
It is configured entirely on Panorama — the auto-deploy configuration block
does not appear on individual firewalls.
You need to meet the following two conditions for the auto-deploy workflow to
work simultaneously:
- A device master key must be configured in the Master Key
Configuration for Auto Deployed Devices section on
Panorama.
- The Automatically push content when software device/VM or
container or ZTP registers to Panorama checkbox must be
enabled in the Template Stack associated with the target firewalls.
Panorama needs to be running PAN-OS version 12.2.2 or later. Managed
firewalls can be on earlier PAN-OS versions, provided they support legacy
master-key functionality.
Palo Alto Networks recommends the following order after upgrading Panorama to
PAN-OS 12.2.2. First, configure a custom master key for
Panorama itself
(see
Manage the Master Key from Panorama), and
then configure the device master key for auto-deployment in this procedure. This
ensures both Panorama and all newly onboarded firewalls immediately move off the
default master key.
Select .
The following screen appears:
In the
Master Key Configuration for Auto Deployed
Devices section, click
Edit (gear
icon).
It shows a read-only Status of
Set or Unset. On a
Panorama freshly upgraded to PAN-OS 12.2.2, the status defaults to
Unset.
Enter a
New Master Key and
Confirm New Master
Key.
There is no Current Master Key field in this dialog.
This dialog sets the common key that will be pushed to auto-deployed
firewalls; it does not change the master key of any already-connected
device.
Configure the
Lifetime in
Days
and
Hours (ranges from 1 hour to 18,250 days).
Configure the
Time for Reminder in
Days and
Hours (ranges from 1
hour to 365 days).
Click
OK to apply the auto-deployment master key
configuration.
No commit is required. The auto-deployment master key configuration is
applied immediately as an operational command when you click
OK.
Enable the automatic content push checkbox in the Template Stack to activate
auto-deployment of the master key to newly registering firewalls.
Select .
Select the Template Stack associated with the target auto-deployed
firewalls and click
Edit.
The device master key is associated with the Template Stack,
not an individual Template, because this is where devices are
associated in Panorama.
In the
Template Stack dialog, select the
Automatically push content when software device/VM or
container or ZTP registers to Panorama checkbox.
This checkbox is a hard prerequisite for master key
auto-deployment. Without it enabled in the associated template
stack, Panorama will not push the device master key
when a new firewall registers — even if the master key is
configured in the Master Key Configuration for Auto
Deployed Devices section.
Click
OK.
Select
Commit to Panorama and then
Commit and Push to apply the updated template
stack configuration to managed firewalls.
Onboard the target firewalls to the same Template Stack where
you enabled the checkbox.
The auto-deployment of the master key applies only to firewalls whose serial
numbers are registered under the Template Stack configured in the previous
step. During device onboarding, add the firewall serial number to Panorama and associate it with that Template Stack. Firewalls that
connect to Panorama under a different Template Stack, or with no
Template Stack association, will not receive the auto-deployed master
key.
Verify that the master key was automatically deployed to a newly onboarded
firewall.
Select .
Locate the newly onboarded firewall. Check the two new status
columns:
- Default Master Key Enabled — should show
No (custom key is now active).
- Days Remaining to Configure Custom Master
Key — should show Not
Applicable.
(
Optional) Login to the
firewall web interface to
confirm directly.
Select.
Confirm that a custom master key is configured and the
Default Master Key Grace Period
field is hidden — this confirms the device is no
longer using the default master key and grace period
enforcement is no longer applicable.