<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: cloud ngfw and resources stuck in &amp;quot;DELETING&amp;quot; stage - post onboarding the tenant account to AWS FMS in Cloud NGFW for AWS Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cloud-ngfw-for-aws-discussions/cloud-ngfw-and-resources-stuck-in-quot-deleting-quot-stage-post/m-p/503342#M318</link>
    <description>&lt;P&gt;I see this list right now. But then, PAN support has already cleaned up the cloud NGFW resources from your side. And i have deleted the IAM account from the portal.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MWhittaker_0-1655182515821.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/41770i95AD1D4FF6B9F74F/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="MWhittaker_0-1655182515821.png" alt="MWhittaker_0-1655182515821.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;May be i will try to recreate the scenario and let you know if the cross-launch IAM roles are properly set&lt;/P&gt;</description>
    <pubDate>Tue, 14 Jun 2022 04:56:00 GMT</pubDate>
    <dc:creator>MWhittaker</dc:creator>
    <dc:date>2022-06-14T04:56:00Z</dc:date>
    <item>
      <title>cloud ngfw and resources stuck in "DELETING" stage - post onboarding the tenant account to AWS FMS</title>
      <link>https://live.paloaltonetworks.com/t5/cloud-ngfw-for-aws-discussions/cloud-ngfw-and-resources-stuck-in-quot-deleting-quot-stage-post/m-p/503128#M315</link>
      <description>&lt;P&gt;My attempt to delete a cloud NGFW instance is stuck. This was a standalone tenant account that i upgraded to an AWS administrator account and introduced AWS FMS to the mix. The issue is this.&lt;/P&gt;
&lt;P&gt;1. When you upgrade a standalone tenant account to an admin account for AWS FMS onboarding, deleting the existing/newly created (?) NGFW resource goes for a whack.&lt;/P&gt;
&lt;P&gt;2. After waiting for an hour, i ended up deleting the stackset and the endpoint from my account thinking i need to clean up my account before the ngfw firewall resource will be cleaned up.&lt;/P&gt;
&lt;P&gt;3. I even revoked the admin access for my AWS account to make sure everything is clean from my side and then upgraded my account to administrator account again to try set things right. But no luck!&lt;/P&gt;
&lt;P&gt;4. The one thing that i noticed is that if i get to the "Firewall Settings" page, i get an error "Account XXXX does not exist as a member".&amp;nbsp;&lt;/P&gt;
&lt;P&gt;5. I cannot add another AWS account now since the account is already onboarded (and i get a prompt popup mentioning the same)&lt;/P&gt;
&lt;P&gt;Somewhere, a disconnect/access permission issue makes it harder for the ngfw resources to get stuck in deleting state.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jun 2022 13:49:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cloud-ngfw-for-aws-discussions/cloud-ngfw-and-resources-stuck-in-quot-deleting-quot-stage-post/m-p/503128#M315</guid>
      <dc:creator>MWhittaker</dc:creator>
      <dc:date>2022-06-13T13:49:14Z</dc:date>
    </item>
    <item>
      <title>Re: cloud ngfw and resources stuck in "DELETING" stage - post onboarding the tenant account to AWS FMS</title>
      <link>https://live.paloaltonetworks.com/t5/cloud-ngfw-for-aws-discussions/cloud-ngfw-and-resources-stuck-in-quot-deleting-quot-stage-post/m-p/503144#M316</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MWhittaker_0-1655128911922.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/41760i2E132623776B32A6/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="MWhittaker_0-1655128911922.png" alt="MWhittaker_0-1655128911922.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could this be the issue? In AWS FMS page, the disassociation is stuck for ever...&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jun 2022 14:02:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cloud-ngfw-for-aws-discussions/cloud-ngfw-and-resources-stuck-in-quot-deleting-quot-stage-post/m-p/503144#M316</guid>
      <dc:creator>MWhittaker</dc:creator>
      <dc:date>2022-06-13T14:02:30Z</dc:date>
    </item>
    <item>
      <title>Re: cloud ngfw and resources stuck in "DELETING" stage - post onboarding the tenant account to AWS FMS</title>
      <link>https://live.paloaltonetworks.com/t5/cloud-ngfw-for-aws-discussions/cloud-ngfw-and-resources-stuck-in-quot-deleting-quot-stage-post/m-p/503189#M317</link>
      <description>&lt;P&gt;There is a iam role called&amp;nbsp;CustomerPANWCloudNGFWRole created under your account for PAN to assume, this role allow PAN to validate the VPC information for the firewall, can you verify that role still exist?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jun 2022 16:47:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cloud-ngfw-for-aws-discussions/cloud-ngfw-and-resources-stuck-in-quot-deleting-quot-stage-post/m-p/503189#M317</guid>
      <dc:creator>XSun</dc:creator>
      <dc:date>2022-06-13T16:47:27Z</dc:date>
    </item>
    <item>
      <title>Re: cloud ngfw and resources stuck in "DELETING" stage - post onboarding the tenant account to AWS FMS</title>
      <link>https://live.paloaltonetworks.com/t5/cloud-ngfw-for-aws-discussions/cloud-ngfw-and-resources-stuck-in-quot-deleting-quot-stage-post/m-p/503342#M318</link>
      <description>&lt;P&gt;I see this list right now. But then, PAN support has already cleaned up the cloud NGFW resources from your side. And i have deleted the IAM account from the portal.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MWhittaker_0-1655182515821.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/41770i95AD1D4FF6B9F74F/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="MWhittaker_0-1655182515821.png" alt="MWhittaker_0-1655182515821.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;May be i will try to recreate the scenario and let you know if the cross-launch IAM roles are properly set&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jun 2022 04:56:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cloud-ngfw-for-aws-discussions/cloud-ngfw-and-resources-stuck-in-quot-deleting-quot-stage-post/m-p/503342#M318</guid>
      <dc:creator>MWhittaker</dc:creator>
      <dc:date>2022-06-14T04:56:00Z</dc:date>
    </item>
    <item>
      <title>Re: cloud ngfw and resources stuck in "DELETING" stage - post onboarding the tenant account to AWS FMS</title>
      <link>https://live.paloaltonetworks.com/t5/cloud-ngfw-for-aws-discussions/cloud-ngfw-and-resources-stuck-in-quot-deleting-quot-stage-post/m-p/503345#M319</link>
      <description>&lt;P&gt;Sounds good. That AwsServiceLinkRole was controlled by AWS FMS, so you may not want to manually deleting it. Regarding your PaloAlto FW service, your account was reset back to init state, since you already cleaned up the role stack, you need do following to start able to deploy firewall again.&lt;BR /&gt;1. Go to Account Page, download the CFT and run it.&lt;BR /&gt;2. From PaloAlto SAAS UI User page, add LocalFirewall Admin and LocalRuleStack Admin role back to the Tenant Admin user.&lt;BR /&gt;&lt;BR /&gt;Then you should be ok.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jun 2022 05:14:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cloud-ngfw-for-aws-discussions/cloud-ngfw-and-resources-stuck-in-quot-deleting-quot-stage-post/m-p/503345#M319</guid>
      <dc:creator>XSun</dc:creator>
      <dc:date>2022-06-14T05:14:23Z</dc:date>
    </item>
    <item>
      <title>Re: cloud ngfw and resources stuck in "DELETING" stage - post onboarding the tenant account to AWS FMS</title>
      <link>https://live.paloaltonetworks.com/t5/cloud-ngfw-for-aws-discussions/cloud-ngfw-and-resources-stuck-in-quot-deleting-quot-stage-post/m-p/503348#M320</link>
      <description>&lt;P&gt;Thanks. i will note it down to make sure i keep the link-role intact for PAN to operate into my account.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am running a test to delete my tenant account from the portal and also unsubscribe the cloud ngfw (a clean exit to start again).&lt;/P&gt;
&lt;P&gt;And i see this in the portal and thats good.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MWhittaker_0-1655183933619.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/41771iD4B7D96DC4E14033/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="MWhittaker_0-1655183933619.png" alt="MWhittaker_0-1655183933619.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But i still see that the subscription is active.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MWhittaker_1-1655183968174.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/41772i537D1304CFDCBB5A/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="MWhittaker_1-1655183968174.png" alt="MWhittaker_1-1655183968174.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How do i unsubscribe from the cloud ngfw service and delete the current tenant account in the portal? I dont see a way to do this myself.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jun 2022 05:20:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cloud-ngfw-for-aws-discussions/cloud-ngfw-and-resources-stuck-in-quot-deleting-quot-stage-post/m-p/503348#M320</guid>
      <dc:creator>MWhittaker</dc:creator>
      <dc:date>2022-06-14T05:20:39Z</dc:date>
    </item>
    <item>
      <title>Re: cloud ngfw and resources stuck in "DELETING" stage - post onboarding the tenant account to AW...</title>
      <link>https://live.paloaltonetworks.com/t5/cloud-ngfw-for-aws-discussions/cloud-ngfw-and-resources-stuck-in-quot-deleting-quot-stage-post/m-p/503892#M322</link>
      <description>&lt;P&gt;&lt;SPAN style="background-color:rgb(219,234,255);color:rgb(45,51,56);font-size:10pt;"&gt;Hi @&lt;/SPAN&gt;&lt;SPAN style="background-color:rgb(255,255,255);color:rgb(46,46,46);font-size:13px;"&gt;&lt;STRONG&gt;MWhittaker&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Greetings from Palo Alto Networks!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To unsubscribe please navigate to AWS Marketplace &amp;gt; Manage Subscriptions &amp;gt; Palo Alto Networks Cloud NGFW.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;IMG style="width:72.37%;" src="https://ip1.i.lithium.com/edf5febc51bbb8630e4be39abc454c9710f0ba96/68747470733a2f2f6c69746869756d2d726573706f6e73652d70726f642e73332e75732d776573742d322e616d617a6f6e6177732e636f6d2f70616c6f616c746f2d6e6574776f726b732e726573706f6e73652e6c69746869756d2e636f6d2f524553504f4e5345494d4147452f38393133383239342d323764372d343965362d613163382d3737666337356665626466322e64656661756c742e706e67" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="background-color:white;color:rgb(29,28,29);"&gt;Edison K Benny&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="background-color:rgb(248,248,248);color:rgb(29,28,29);font-size:10pt;"&gt;Product specialist&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="background-color:rgb(248,248,248);color:rgb(29,28,29);font-size:10pt;"&gt;Palo Alto Networks&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/cloud-ngfw-help-center/ct-p/Cloud_NGFW" target="_blank"&gt;&lt;SPAN style="background-color:white;color:rgb(51,51,51);font-size:10pt;"&gt;https://live.paloaltonetworks.com/t5/cloud-ngfw-help-center/ct-p/Cloud_NGFW&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="background-color:white;color:rgb(62,62,62);font-size:10pt;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="background-color:white;color:#3E3E3E;font-size:10.0pt;"&gt;&lt;STRONG&gt;*Don’t forget to accept the solution provided!*&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jun 2022 18:29:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cloud-ngfw-for-aws-discussions/cloud-ngfw-and-resources-stuck-in-quot-deleting-quot-stage-post/m-p/503892#M322</guid>
      <dc:creator>ebenny</dc:creator>
      <dc:date>2022-06-15T18:29:35Z</dc:date>
    </item>
    <item>
      <title>Re: cloud ngfw and resources stuck in "DELETING" stage - post onboarding the tenant account to AWS FMS</title>
      <link>https://live.paloaltonetworks.com/t5/cloud-ngfw-for-aws-discussions/cloud-ngfw-and-resources-stuck-in-quot-deleting-quot-stage-post/m-p/504988#M325</link>
      <description>&lt;P&gt;this did not help - as I still cannot see Manage NGFWs or create Firewall in Cloud Tenant. Old Firewall is still in Deleting status for almost 6 hours now&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jun 2022 21:15:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cloud-ngfw-for-aws-discussions/cloud-ngfw-and-resources-stuck-in-quot-deleting-quot-stage-post/m-p/504988#M325</guid>
      <dc:creator>SGopal11</dc:creator>
      <dc:date>2022-06-20T21:15:20Z</dc:date>
    </item>
  </channel>
</rss>

