- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
10-15-2023 08:42 PM
Can we get anyone explained the potential issues or risks when deactivating the PA-VM in AWS and reactivating them with different auth code?
Here is the use case:
We had a few PA-VM firewalls deployed in the different segments of our AWS environment. In the past, the licensing process and onboarding with Panorama are all manual processes and there was no issue. However, recently, the cloud platform teams strongly push the idea of the infrastructure-as-code approach and want to implement the automated processes for the firewall device licensing and onboarding processes, for the DR automation purposes.
To achieve the goals, we have to break the existing big license pool and replace it with multiple smaller license pools and deactivate the licenses on the existing devices and reactivate them with new license codes.
My questions are
- What might go wrong when we deactivate the devices and replace the licenses?
- How can we check before the actions and avoid the potential worst scenarios?
- What're the best options in the worst scenarios, without completely rebuild the firewall images?
Many thanks.
10-17-2023 08:58 PM
Hi @Rockey ,
Deactivating and reactivating PA-VMs with new licenses will result in downtime during the transition. I believe reactivating the firewall with a new license will result in a loss of the firewall's previous state. I would ensure that you have a backup of ALL configurations to restore them after reactivation.
I would test this out on some non-prod/test accounts before working on prod firewalls to understand all that is needed for this migration.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!