Risks of the AWS PA-VM license deactivation and reactivation

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Risks of the AWS PA-VM license deactivation and reactivation

L0 Member

Can we get anyone explained the potential issues or risks when deactivating the PA-VM in AWS and reactivating them with different auth code?

 

Here is the use case:

We had a few PA-VM firewalls deployed in the different segments of our AWS environment. In the past, the licensing process and onboarding with Panorama are all manual processes and there was no issue.  However, recently, the cloud platform teams strongly push the idea of the infrastructure-as-code approach and want to implement the automated processes for the firewall device licensing and onboarding processes, for the DR automation purposes.

To achieve the goals, we have to break the existing big license pool and replace it with multiple smaller license pools and deactivate the licenses on the existing devices and reactivate them with new license codes.

 

My questions are

- What might go wrong when we deactivate the devices and replace the licenses?

- How can we check before the actions and avoid the potential worst scenarios?

- What're the best options in the worst scenarios, without completely rebuild the firewall images?

 

Many thanks.

1 REPLY 1

Community Team Member

Hi @Rockey ,

 

Deactivating and reactivating PA-VMs with new licenses will result in downtime during the transition. I believe reactivating the firewall with a new license will result in a loss of the firewall's previous state. I would ensure that you have a backup of ALL configurations to restore them after reactivation.


I would test this out on some non-prod/test accounts before working on prod firewalls to understand all that is needed for this migration. 

LIVEcommunity team member
Stay Secure,
Jay
Don't forget to Like items if a post is helpful to you!

Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.
  • 1376 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!