Unlink the Cloud NGFW from Palo Alto Networks Management
Table of Contents
Expand all | Collapse all
-
- About Cloud NGFW for AWS
- Getting Started from the AWS Marketplace
- Register Your Cloud NGFW Tenant with a Palo Alto Networks Support Account
- Cloud NGFW for AWS Pricing
- Cloud NGFW Credit Distribution and Management
- Cloud NGFW for AWS Free Trial
- Cloud NGFW for AWS Limits and Quotas
- Subscribe to Cloud NGFW for AWS
- Locate Your Cloud NGFW for AWS Serial Number
- Cross-Account Role CFT Permissions for Cloud NGFW
- Invite Users to Cloud NGFW for AWS
- Manage Cloud NGFW for AWS Users
- Deploy Cloud NGFW for AWS with the AWS Firewall Manager
- Enable Programmatic Access
- Terraform Support for Cloud NGFW AWS
- Provision Cloud NGFW Resources to your AWS CFT
- Configure Automated Account Onboarding
- Usage Explorer
- Create a Support Case
- Cloud NGFW for AWS Certifications
- Cloud NGFW for AWS Privacy and Data Protection
-
-
- Prepare for Panorama Integration
- Link the Cloud NGFW to Palo Alto Networks Management
- Unlink the Cloud NGFW from Palo Alto Networks Management
- Associate a Linked Panorama to the Cloud NGFW Resource
- Use Panorama for Cloud NGFW Policy Management
- View Cloud NGFW Logs and Activity in Panorama
- View Cloud NGFW Logs in Strata Logging Service
- Tag Based Policies
- Configure Zone-based Policy Rules
- Enterprise Data Loss Prevention (E-DLP) Integration with Cloud NGFW for AWS
-
- Strata Cloud Manager Policy Management
Unlink the Cloud NGFW from Palo Alto Networks Management
Unlink Cloud NGFW from Panorama.
Before unlinking your Cloud NGFW resource from the Panorama virtual appliance, Palo
Alto Networks recommends that you delete or disassociate Cloud Device Groups
that are associated with the Cloud NGFW resource or regions. See Delete a Cloud Device Group or Disassociate a Cloud Device Group from a
Resource for more information.
To unlink a Panorama virtual appliance from a Cloud NGFW resource:
- Choose the region, for example, us-east-1, in the firewall or rulestacks page.In the Cloud NGFW console, select Integrations.On the Integrations page, locate the Actions section. A previously linked Panorama appears greyed out.Click the Unlink icon to begin the unlinking process.If a HA pair is configured, both pairs are unlinked.When you unlink a Panorama virtual appliance from your Cloud NGFW tenant, you may be prompted to delete one or more Cloud Device Groups that are associated with the Cloud NGFW resource or region from which you are unlinking. In such cases an error message appears listing the Cloud Device Groups that are associated with the Cloud NGFW resource that is linked to Panorama. Either Delete a Cloud Device Group or Disassociate a Cloud Device Group from a Resource before unlinking. If you do not have access to Panorama to remove these Cloud Device Groups, click Force Unlink.Confirm the unlinking process. If you Panorama is associated with a Strata Logging Service account, that association is terminated and logs are pruned after the retention period.After confirming the unlinking request, the Integrations page changes to provide status for the Cloud NGFW resource.Palo Alto Networks recommends that you remove Monitoring Definitions configured on Panorama.The Force unlink option will not remove Monitoring Definitions automatically from Panorama.You can see the tenant monitoring definitions and delete them running the following commands only on CLI:request plugins dau plugin-name cloud_services unblock-device-push yes request plugins dau plugin-name cloudconnector unblock-device-push yes request plugins dau plugin-name vm_series unblock-device-push yes request plugins dau plugin-name aws unblock-device-push yes