End-of-Life (EoL)

Create and Apply a Subscription-Only Auth Code

If you have already deployed VM-Series firewalls using a perpetual or ELA license bundle, you can use Software NFGW credits to add subscriptions to your existing deployment.
When adding subscriptions, keep the following in mind:
  • Only select subscriptions that are not included in your existing bundle.
  • Ensure that your VM-Series model and PAN-OS version support the subscription you want to add.
  • Do not apply more than one subscription-only auth code to a firewall.
  • A subscription-only license cannot be used as a renewal for an existing subscription.
  • The firewall on which you are applying the auth code must be able to access the Palo Alto Networks licensing server.
  1. If you already have a credit pool, log into the account, and from the dashboard, select
    Assets
    Software NGFW Credits
    Create Deployment Profile
    .
    If you have just activated a credit pool you see the
    Create Deployment Profile
    form.
  2. Click
    Next
    . A subscription-only deployment profile can only be used on VM-Series firewalls with
  3. VM-Series profile.
    1. Profile Name
      .
      Name the profile.
    2. Number of Firewalls
      .
      Enter the number of firewalls this profile deploys, assuming you have sufficient credits. You do not have to deploy them all at once.
    3. Firewall Model
      :
      Choose the VM-Series model of the VM-Series firewalls to which you are adding subscriptions.
      You can only apply the subscription-only auth code to VM-Series firewall of the chosen model.
    4. Security Use Case:
      Choose a use case.
    5. Customize Subscriptions
      .
      After selecting a use case, you can add or remove security services.
  4. (
    optional
    ) Hover over the question mark following
    Protect more, save more
    to see how your credit allocation affects savings.
  5. Click
    Calculate Estimated Cost
    to view the credit total, and the number of credits available before the deployment.
    (
    optional
    ) Hover over the question mark following the estimate to view the credit breakdown for each component.
  6. Create the Deployment Profile
    .
    You might have to wait several seconds for the profile to appear in the
    Current Deployment Profiles
    tab list. Before the allocation is complete, the
    Credits Consumed/Allocated
    column shows 0 and
    Update Pending
    . Scroll to the bottom and go to the last page to find your profile.
    To view your deployment profile later on, click the
    Details
    button on the parent credit pool and select
    Current Deployment Profiles
    .
    • Note the Auth Code for your profile on the far right; subscription-only auth codes start with D.
    • The
      Credits Consumed/Allocated
      column shows 0 and
      Update Pending
      before the allocation is complete.
    • The
      Audit Trail
      tab shows
      Credit Transactions
      and the
      Deployment Profiles
      you manage. You can also search for a profile by time in this tab.
      Use search to locate your profile, and expand the row to view the configuration you specified when you created the profile.
  7. Apply the subscription-only auth code to your firewall.
    1. Log in to the CSP with your account credentials.
    2. Select
      Assets
      Software NFGW Credits
      .
      Locate your credit pool and view
      Details
      .
    3. View
      Current Deployment Profiles
      and choose a profile.
      You will use the auth code from this profile on any firewall of the model specified when you created your deployment profile. An auth code for a subscription-only license begins with the letter D.
    4. Log in to the VM-Series firewall web interface.
    5. Verify the Palo Alto Networks update server configuration.
      1. Select
        Device
        Setup
        Services
        .
      2. Confirm that
        Update Server
        is set to
        updates.paloaltonetworks.com
        .
      3. Confirm that
        Verify Update Server Identity
        is selected.
    6. Select
      Device
      Licenses
      .
      1. Select the
        Activate feature using authorization code
        link.
      2. Enter the subscription-only auth code from the deployment profile.
      3. Click
        OK
        to confirm the license application.The firewall contacts the Palo Alto Networks update server and consumes the tokens required for your subscription-only license.
  8. Verify that the license is successfully activated.
    On the
    Device
    Licenses
    page, verify that the license is successfully activated. For example, after activating the Threat Prevention license, you should see that the license is valid:

Recommended For You