Deactivate VM

When you no longer need a BYOL instance of the VM-Series firewall, you can free up all active licenses (subscription licenses, model-based capacity licenses, and support entitlements) from the web interface, the CLI, or the XML API on the firewall or Panorama. The licenses are credited back to your account and you can use the same authorization codes on a different instance of the VM-Series firewall.
Deactivating a VM removes all the licenses/entitlements and places the VM-Series firewall in an unlicensed state; the firewall will not have a serial number and can support only a minimal number of sessions. Because the configuration on the firewall is left intact, you can re-apply a set of licenses and restore complete functionality on the firewall, if needed.
Make sure to deactivate licenses
before
you delete the VM-Series firewall. If you delete the firewall before deactivating the licenses, you have two options:
Managed by Panorama
—Deactivate the license from Panorama.
Not managed by Panorama
—Contact Palo Alto Networks Customer Support for deactivation assistance.

Deactivate the VM from the Firewall

Complete the following process to deactivate the VM license from the firewall.
  1. Log into the web interface and select
    Device
    Licenses
    .
  2. In the License Management section, select
    Deactivate VM
    .
    You can only see this option on a VM. It is not there on a physical firewall.
  3. Verify the list of licenses/entitlements to be deactivated on the firewall.
  4. Pick one of the following options to start deactivating the VM:
    • (Internet access to the Palo Alto Networks Licensing server
      ) Select
      Continue
      .
      You are prompted to reboot the firewall; on reboot the licenses are deactivated.
    • (No internet
      )—Select
      Complete Manually
      .
      Click the
      Export license token
      link to save the token file to your local computer. Here is a sample token filename: 20150128_1307_dact_lic.01282015.130737.tok
      You are prompted to reboot the firewall; on reboot the licenses are deactivated.
  5. (
    Manual Process—no internet
    ) Use the token file to register the changes with the Licensing server:
    1. Select
      Assets
      VM-Series Auth-Codes
      Deactivate License(s)
      .
    2. While logged in to the Palo Alto Networks Customer Support website, upload the token file to complete the deactivation.

Deactivate the VM from Panorama

Complete the following process to deactivate a VM license from Panorama.
  1. Log in to the Panorama web interface and select
    Panorama
    Device Deployment
    Licenses
    .
  2. Deactivate VMs
    and select the VM-Series firewall that you want to deactivate.
  3. Pick one of the following options to deactivate the VM:
    • Continue
      —If Panorama can communicate directly with the Palo Alto Networks Licensing servers and can register the changes. To verify that the licenses have been deactivated on the firewall, select
      Refresh on Panorama
      Device Deployment
      Licenses
      . The firewall is automatically rebooted.
    • Complete Manually
      —If Panorama does not have internet access, Panorama generates a token file.
      Click the
      Export license token
      link to save the token file to your local computer. Here is a sample token filename: 20150128_1307_dact_lic.01282015.130737.tok
      The successful completion message is displayed on-screen, and the firewall is automatically rebooted.
  4. (
    Manual process only
    —no internet
    ) Use the token file to register the changes with the licensing server.
    1. Select
      Assets
      VM-Series Auth-Codes
      Deactivate License(s)
      .
    2. Upload the token file to complete the deactivation.
  5. Remove the deactivated VM-Series firewall as a managed device on Panorama.
    1. Select
      Panorama
      Managed Devices
      .
    2. Select the firewall that you deactivated from the list of managed devices, and click
      Delete
      .
      Instead of deleting the firewalls, if you prefer, you can create a separate device group and assign the deactivated VM-Series firewalls to this device group.

Recommended For You