Learn about how to use the Panorama Software Firewall
License plugin to license VM-Series firewalls.
| Where Can I Use This? | What Do I Need? |
|
|
- VM-Series 10.x or above
- Panorama running PAN-OS 10.1.x or above versions
- Customer Support Portal (CSP) account with one of the
following user roles:
- Superuser, Standard User, Limited User, Threat
Researcher, AutoFocus Trial Role, Group superuser,
Group Standard User, Group Limited User, Group
Threat Researcher, Authorized Support Center (ASC)
User, and ASC Full Service User
- Superuser access to the VM-Series
firewall
|
The Panorama Software Firewall License plugin allows you to automatically license a VM-Series
firewall when it connects to Panorama. If your VM-Series firewalls are located in
the perimeter of your deployment and don't have connectivity to the Palo Alto
Networks licensing server, the Software Firewall License plugin simplifies the
license activation process by using Panorama to license the VM-Series firewall.
Additionally, the Software
Firewall License plugin simplifies the license activation and deactivation
of VM-Series firewalls in environments that use auto-scaling and
automation to deploy and delete firewalls to address changes in
the cloud.
Pay-as-you-go (PAYG) licenses are not supported
for use with this plugin.
Don't use the Software Firewall License plugin to license the VM-Series firewall for VMware
NSX. The Panorama plugin for VMware NSX automatically licenses VM-Series
firewalls deployed in NSX and NSX-T.
.
Also, don't use this plugin to
license firewalls deployed in device groups that include instances of the
VM-Series firewall deployed in NSX-T.
To
install the Panorama Software Firewall License plugin, you must
be using Panorama 10.0.0 or later and VM-Series plugin 2.0.4 or
later. Your VM-Series firewalls must be running PAN-OS 9.1.0 or
later.
The VM-Series firewall for Azure requires VM-Series
plugin 2.0.8 or later.
If you have a standalone Panorama or two Panorama appliances installed in an HA pair with
multiple plugins installed, plugins might not receive updated IP-tag information if
one or more of the plugins isn't configured. This occurs because Panorama won't
forward IP-tag information to unconfigured plugins. Additionally, this issue can
occur if one or more of the Panorama plugins isn't in the Registered or Success
state (positive state differs on each plugin). Ensure that your plugins are in the
positive state before continuing or executing the commands described below.
If
you encounter this issue, there are two workarounds:
Uninstall the unconfigured plugin or plugins. It is recommended that you don't install a plugin
that you do not plan to configure right away
You can use the following commands to work around this issue. Execute the following command
for each unconfigured plugin on each Panorama instance to prevent Panorama
from waiting to send updates. If you don't, your firewalls may lose some
IP-tag information.
request plugins dau plugin-name
<plugin-name> unblock-device-push yesYou can cancel this
command by executing:
request plugins dau plugin-name
<plugin-name> unblock-device-push no
The
commands described are not persistent across reboots and must be
used again for any subsequent reboots. For Panorama in HA pair, the
commands must be executed on each Panorama.