How to Transfer PA-Series Licenses to a Spare Device

How to Transfer PA-Series Licenses to a Spare Device

751366
Created On 09/25/18 18:07 PM - Last Modified 09/11/26 18:42 PM


Objective


IMPORTANT
This article applies only to the transfer of standard hardware subscriptions such as Threat Prevention, WildFire, URL Filtering, GlobalProtect, and Support from an RMA defective PA-Series firewall to a replacement device.

If the defective device has activated Cloud/Tenant-Based License(s) (DLP, SaaS Inline, Device Security, or AIOps for NGFW), DO NOT follow these steps. Please use this guide instead: 
How to Transfer PA-Series Licenses Along with Cloud/Tenant-Based License(s) (DLP, SaaS Inline, Device Security, and AIOps for NGFW) to a Spare Device?



Environment


Applicable Models:
• Physical PA-Series hardware firewalls only.

Not Applicable To:
• VM-Series (Virtual Firewalls)
• CN-Series (Container Firewalls)
• Cloud NGFW 



Procedure


Before Transferring PA-Series NGFW to Spare

Before licenses from a PA-Series NGFW can be transferred to a spare, purchase and register the spare device in your Customer Support Portal (CSP) account.

  • To register a spare: Go to Products > Assets, click Account Actions > Register NGFW, and select Register device Using Serial Number

  • To locate spares: Go to Products > Assets (use Add New Filter > Asset Type > PA-Series (Spare)) or go directly to Products > Spares.

Note: We recommend managing hardware via Products > Assets, as the dedicated Spares and Devices tabs are scheduled for future deprecation.

 

Note on Panorama M-Series Appliances
For information on transferring licenses and replace a Panorama M-Series appliances, see:


End of Sale (EOS) hardware platforms enables better replacement for next closest model


How to Transfer Support License after RMA for Prisma SD-WAN


Transfer Licenses to Spare
Ensure you have a compatible spare to replace a defective PA-Series NGFW.  For example, to replace a defective PA-220, you will need a PA-220 spare.   Be sure to register your purchased spare devices in CSP.

  • If you have not yet returned the defective device back to Palo Alto Networks


You can replace a PA-Series NGFW using either of two methods:

  1. Find defective PA-Series NGFW in Assets page.  CSP will then help you find compatible PA-Series spares to replace the defective PA-Series NGFW.
  2. Find a PA-Series Spare in Assets page that is compatible with the defective PA-Series NGFW you want to replace.  CSP will then help you find compatible PA-Series NGFWs.


First find defective PA-Series NGFW. 

  1. If you have not yet registered a spare that is compatible with a PA-Series NGFW you want to replace, click Account Actions> Register Product > Register device using Serial Number >Next > populate the serial number and address (required fields) > click  Agree and Submit button to complete registration of the  new spare.
  2. If you already have a spare that is compatible with the PA-Series NGFW that you want to replace, use CSP Assets page filters or search to find the defective PA-Series NGFW you want to replace.  If you have a compatible spare, CSP will help you find the spare.
  3. Hover mouse over the blank Actions column to make the menu icons appear, then click Licenses/Subscriptions icon for the PA-Series NGFW. 
image.png
  1. Click Transfer License button. 
Screenshot 2024-02-07 at 2.51.08 PM.png
  1. CSP displays a dropdown list of compatible spares. Select a spare.  Then, click Transfer button.
Screenshot 2024-02-07 at 2.52.58 PM.png
  1. CSP displays a warning that this transfer operation cannot be reverted.  Click Agree and Submit button.
Screenshot 2024-02-07 at 2.56.35 PM.png
The licenses for the PA-Series NGFW transfer to the Spare (replacement) device.

Note: If a license expires prior to the transfer, it will be expired on the replacement. The defective device will be given licenses valid for 30 days from the date of transfer regardless of the status of the license before the transfer. A previously expired license will be valid for 30 days from transfer on the defective unit.


First find compatible PA-Series spare. 

  1. To first find a compatible PA-Series spare, remember the model of the defective PA-Series NGFW.  Then, search for a compatible PA-Series spare using the Asset Type filter - filter for PA-Series (Spare).  Then, find a compatible spare.

Screenshot 2024-02-14 at 8.56.10 AM.png

 

Then, go to Licenses and Subscriptions drawer, and click on Transfer License button.  Follow the steps described in the previous section.
 
  • If you already returned the defective device back to Palo Alto Networks
When a defective firewall is returned back to our warehouse, the Inventory team scrubs the Serial Number from the Licensing Database, which means that you are no longer able to find it under the Products-> Assets section of the Support Portal. In this case, you need to follow the steps below to complete the RMA license transfer:
 
  1. Go to Products > Spares and locate the Replacement Serial Number from the RMA.
 
  1. Click on the Serial Number and, in the Device Information pop-up window, select Transfer Licenses.
 
 kcs2.png

 
  1. In the Transfer License window, under Available Source Devices, you will need to click on Can't find defective device?, as the Serial Number will not show in the list. This will open a new Search field and you can enter the defective Serial Number there.
 
kcs3.png


 
  1. Once the defective SN is displayed in the list, Select it, click on Confirm Transfer and then Yes to confirm the transfer.
 
kcs4.png
 
5.  Once the licenses have been transferred the Defective/Source SN will have temporary licenses for 30 days.

 

See Also

For a full list of other Support Portal User Documents, please click here:

Customer Support Portal User Documents

 

 
 


Additional Information


If the defective firewall has been added and managed through Strata Cloud Manager  - to  minimize the effort required to restore the configuration on a cloud managed NGFW involving a Return Merchandise Authorization (RMA), you can now trigger an RMA workflow through Device Management.
The new RMA workflow will automatically restore the configuration of the original NGFW to your replacement NGFW. By importing the state of your original NGFW, you can quickly resume using Strata Cloud Manager to manage your network.
Before you trigger the RMA process, complete the following prerequisites:
  • -The RMA request has been placed in the Customer Support Portal.
  • -Replacement device should be of the same hardware model.
  • Replacement device is registered to CSP account and associated with the correct tenant.
  • Note: at this step ensure to complete the licenses transfer from the defective to spare device using the steps outlined in this article. 
  • -Replacement device is found in Available Devices(System Settings>Device Management>Available Devices).

RMA Workflow in SCM:

  1.  

    Step 1.  Log in to Strata Cloud Manager.
    Step 2.   Select System Settings -> Device Management ->  Cloud Managed Devices.

    Step 3. Locate the faulty device in the table.
    Step 4. Start the RMA process:



Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClNMCA0&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail%3Fid%3DkA10g000000ClNMCA0

Choose Language