Configure the Master Key Panorama and PAN-OS
Focus
Focus
Next-Generation Firewall

Configure the Master Key Panorama and PAN-OS

Table of Contents


Configure the Master Key Panorama and PAN-OS

Ensure there are no pending configuration changes before starting this procedure. Commit any pending changes prior to configuring the master key.
  1. (HA only) Disable configuration synchronization.
    This step is required before deploying a new master key to any NGFW HA pair.
    Before deploying a new master key to any NGFW in an HA pair, disable Config Sync.
    If Panorama is in a passive HA configuration, a failover to make Panorama active is required before proceeding. Configure the master key only on the active Panorama peer.
    1. Select DeviceHigh AvailabilityGeneral and edit the Setup.
    2. Disable (clear) Enable Config Sync and then click OK.
    3. Commit your configuration changes.
  2. Select DeviceMaster Key and Diagnostics and edit the Master Key section.
    In the Master Key dialog, select the Master Key checkbox to activate the master key configuration fields. The fields are greyed out until the checkbox is selected.
  3. Enter the Current Master Key if one exists.
  4. Define a new New Master Key, and then Confirm New Master Key. The key must contain exactly 16 characters.
    Record and store your master key in a secure, access-controlled location. You will need this key to perform future key rotations, restore configurations, or recover from HA failover scenarios. If the master key is lost, the device cannot be recovered without a full factory reset, resulting in complete loss of your running configuration.
    For devices participating in a high availability (HA) configuration, you must configure the same master key on both HA peers. HA synchronization fails if the master keys do not match.
  5. To specify the master key Lifetime, enter the number of Days or Hours after which the key expires.
    Configure a new master key before the current key expires. If the master key expires, the NGFW or Panorama automatically reboots in Maintenance mode causing a network traffic outage. Then, you must reset the NGFW to factory default settings.
    Set the Lifetime to two years or less, depending on how many encryptions the device performs. The more encryptions a device performs, the shorter the Lifetime you should set. The critical consideration is to not run out of unique encryptions before you change the master key. Each master key can provide up to 232 unique encryptions based on the master key value and the Initialization Vector (IV) value. After 232 unique encryptions, encryptions repeat (are no longer unique), which is a security risk.
    Set a Time for Reminder value (see next step) for the master key and when the reminder notification occurs, change the master key.
  6. Enter a Time for Reminder that specifies the number of Days and Hours before the master key expires when the NGFW generates an expiration alarm. The NGFW automatically opens the System Alarms dialog to display the alarm.
    Set the reminder so that it gives you plenty of time to configure a new master key before it expires in a scheduled maintenance window. When the Time for Reminder expires and the NGFW or Panorama sends a notification log, change the master key, don’t wait for the Lifetime to expire. For grouped devices, track every device (for example, NGFWs that Panorama manages and NGFW HA pairs) and when the reminder value expires for any device in the group, change the master key.
    To ensure the expiration alarm displays, select DeviceLog Settings, edit the Alarm Settings, and Enable Alarms.
  7. Enable Auto Renew Master Key to configure the NGFW to automatically renew the master key. To configure Auto Renew With Same Master Key, specify the number of Days or Hours to renew the same master key. The key extension enables the NGFW to remain operational and continue securing your network; it is not a replacement for configuring a new key if the existing master key lifetime expires soon.
    Automatically renewing the master key has benefits and risks. The benefit is that extending the master key Lifetime protects against failure to change the master key before its lifetime expires. The risk is that encryptions will repeat and cause a security risk if the number of encryptions the device performs with the master key exceeds the number of unique encryptions the master key can generate (232 unique encryptions).
    If the master key expires (you don't automatically renew or replace it in a timely manner), the device reboots into maintenance mode, causing a network traffic outage. The only recovery method is to factory reset the device.
    If you enable Auto Renew Master Key, set it so that the total time (lifetime plus the auto renew time) does not cause the device to run out of unique encryptions. For example, if you believe the device will consume the master key’s number of unique encryptions in two and a half years, you could set the Lifetime for two years, set the Time for Reminder to 60 days, and set the Auto Renew Master Key for 60-90 days to provide the extra time to configure a new master key before the Lifetime expires. However, the best practice is still to change the master key before the lifetime expires to ensure that no device repeats encryptions.
    Consider the number of days until your next available maintenance window when configuring the master key to automatically renew after the lifetime of the key expires.
  8. (12.2.2 and later releases) Configure the Default Master Key Grace Period in the Master Key dialog.
    1. In the Master Key dialog, locate the Default Master Key Grace Period field at the bottom of the dialog.
      • This field is only active and editable while the device is still using the default master key. Once a custom master key is configured on the device, this field is hidden — it is not applicable and the option to configure it is removed from the dialog.
      • Enter a value between 60 and 120 days. If you do not configure a value, the grace period defaults to 60 days.
      • 120-day limit is cumulative from the original trigger event (upgrade, factory reset, or first power-on) — it is not an additional extension. For example, if 60 days have already elapsed since upgrade, you cannot gain a further 120 days. The maximum total time available is 120 days from the original start of the timer.
      • The dialog displays a warning indicator showing the number of days remaining to configure a new master key — for example, 96 Days Remaining to Configure New Master Key.
      During the grace period, each configuration commit generates an on-screen warning prompting you to configure a custom master key. In addition, a critical severity system log is generated on every commit. Monitor these warnings and act before the grace period expires — once it does, commits fail and HA sync is suspended until a custom master key is configured.
      If this firewall is managed by Panorama, the grace period can also be configured centrally. See Manage the Master Key from Panorama.
    2. Click OK.
  9. (Optional) For added security, select whether to use an HSM to encrypt the master key. For details, see Encrypt and Refresh Master Keys Using an HSM.
  10. Click OK and select CommitCommit to PanoramaCommit All Changes.
  11. (HA only) Re-enable configuration synchronization.
    1. Select DeviceHigh AvailabilityGeneral and edit the Setup.
    2. Enable Config Sync, and then click OK.
    3. Select CommitCommit to PanoramaCommit All Changes.