Configure Offline Licensing for an HSF Cluster
Focus
Focus
Prisma AIRS

Configure Offline Licensing for an HSF Cluster

Table of Contents

Configure Offline Licensing for an HSF Cluster

Set up Panorama as an offline license server and assign Air-Gap license profiles to P-Nodes and S-Nodes in your HSF deployment.
Where Can I Use This?What Do I Need?
  • Prisma AIRS
  • Software NGFW Credits
  • HSF subscription license
  • Software Firewall License plugin installed on Panorama
  • Software Firewall Orchestration plugin installed on Panorama
  • Customer Support Portal deployment profile with Air Gap licensing enabled
  • Panorama Air-Gap License JSON file
Configure offline licensing when your HSF cluster nodes can't reach the Customer Support Portal directly during deployment. Panorama acts as a local license server, distributing licenses from Air-Gap profiles to each cluster node at bootstrap time.
  1. Prepare offline license profiles in Customer Support Portal.
    1. Log in to the Customer Support Portal and confirm the credit pool shows Eligible for Air-Gap licenses: Yes.
    2. Create your HSF deployment profile or open an existing one.
      • Enable the Offline NGFWs checkbox on the deployment profile.
      • Choose the precise vCPU count for P-Nodes and S-Nodes. Oversubscribing or undersubscribing vCPUs prevents offline licensing from functioning correctly.
      • Create separate authentication codes for P-Nodes and S-Nodes sized to match their respective vCPU counts.
      • Verify your HSF subscription is valid to avoid service disruption. When you generate authentication codes, the firewall count must align with the sum of P-Nodes and S-Nodes in your deployment. You can over-provision for upcoming expansions or autoscaling requirements, but the license count must never be less than the total number of nodes active in the cluster.
      • For deployments leveraging autoscaling, the S-Node license profile must be sized to accommodate the maximum node capacity defined in your configuration.
    3. Download the Panorama Air-Gap License JSON file for every deployment profile from your active credit pool.
      Ensure the JSON file content accurately reflects the firewall count and vCPU configuration. If discrepancies exist, re-download the file. Deployment profile updates are instantaneous on the Customer Support Portal, but license provisioning may require additional time to complete. Files downloaded immediately after a change might be incomplete or contain stale data.
  2. Install the Software Firewall License plugin on Panorama if it is not already installed.
  3. Upload the Air-Gap License JSON to Panorama.
    1. In Panorama, select PanoramaPluginsSW Firewall LicenseOffline License.
    2. Select Enable Offline License.
    3. Click Add.
    4. In Name, enter a name for the license profile.
    5. Click Browse and select the Air-Gap License JSON file you downloaded from the Customer Support Portal.
    6. Click OK and commit the change.
    7. Repeat the preceding substeps for the second license profile (for the other node type).
  4. Configure the HSF deployment to use offline licensing.
    1. In Panorama, select PanoramaPluginsSWFW OrchestrationDeployments.
    2. Create a new HSF deployment or open an existing one.
    3. In the Bootstrap Cluster section, for Licensing Type, choose Offline.
    4. For P-Node Offline License Profile, choose the P-Node license profile you created in the previous step.
    5. For S-Node Offline License Profile, choose the S-Node license profile you created in the previous step.
      The offline license profile selection cannot be changed after deployment. Verify that the correct profiles are selected before you deploy.
    6. Complete any remaining deployment configuration and click Deploy.
  5. Commit and deploy your configuration changes.
    1. Click Commit, then Commit and Push to push configuration changes to Panorama and your managed cluster nodes.
    2. After deployment, click Show Devices in the License Manager to verify that all P-Nodes and S-Nodes show a valid license status.
    3. Click Offline LicenseView Details to view the details of the uploaded offline license.