Licensing Flashcards

1
Q

What does the licensing process for the VM-Series firewall use to generate a unique serial number for each VM-Series firewall?

A

UUID and the CPU ID

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is UUID (Universally Unique Identifier)?

A
  • a 128-bit number used to uniquely identify information in computer systems
  • UUIDs are used in many applications and protocols, including as part of the licensing process for Palo Alto VM-Series firewalls
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Which licensing models does Palo Alto support?

A
  1. Bring Your Own License (BYOL)
  2. PAYG (Pay-As-You-Go, PayGo) - only in public cloud
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is the name of the licensing model that provides VM-50, VM-100, VM-200, VM-300, VM-500, etc.?

A

capacity licenses

no longer available for purchase

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are the two licensing systems based on VCPUs that Palo Alto uses, where one is being deprecated?

A
  1. FLEXIBLE VCPUS
  2. FIXED VCPUS - being deprecated
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

The flexible license cost is based on what?

A
  1. number of vCPUs
  2. security services enabled
  3. whether Panorama is used to manage the firewall or act as a log collector
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Since when is the Flexible vCPUs model available?

A

PAN-OS 10.0.4 and later

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is the capacity license cost is based on?

A
  1. device memory
  2. storage costs
  3. support entitlement

Security services and a Panorama deployment to manage your firewalls are additional costs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What exactly are the PayGo licenses? Where are they obtained from?

A

purchased from a public cloud marketplace (such as AWS, Azure, or GCP), or a Cloud Security Service Provider (CSSP)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are the capacity license types?

A
  • VM-Series Enterprise License Agreement (Multi-Model ELA)
  • Multi-Model ELA
  • Perpetual VM-Series model capacity license
  • Term firewall capacity license
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Describe VM-Series Enterprise License Agreement (Multi-Model ELA). Which licenses does it include?

A
  • one- or three-year comprehensive licensing agreement that enables you to purchase VM-Series firewalls, along with the GlobalProtect, PAN-DB URL Filtering, Threat Prevention, WildFire, and DNS Security subscriptions
  • also includes a support entitlement and a device management license for Panorama
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Describe Multi-Model ELA

A

features a token pool from which you allocate tokens to license VM-Series firewalls. (It is unique to the ELA, and is not the same as the Software NGFW Credits pool.)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Describe Perpetual VM-Series license

A

capacity license with a support entitlement and/or security services bundle 1 or bundle 2

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Describe Term license

A

firewall capacity license with a support entitlement and your choice of security services

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What does Bundle 1 include?

A

Threat Prevention and premium support entitlement.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What does Bundle 2 include?

A

Threat Prevention, DNS Security, GlobalProtect, WildFire, URL Filtering, SD-WAN, DLP, and premium support entitlement

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

What is the Capacity License?

A

the VM-Series firewall requires a base license, also called a capacity license, to enable the model number (VM-50, VM-100, VM-200, VM300, VM-500, VM-700, or VM-1000-HV) and the associated capacities on the firewall

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

Capacity licenses are included in a bundle and can be licensed as…?

A
  1. Perpetual License
  2. Term-Based License
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

What is the Perpetual License?

A
  • license with no expiration date
  • allows to use the VM-Series firewall at the licensed capacity, indefinitely
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

What are Perpetual Licenses available for?

A

the VM-Series capacity license only

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

What is the Term-Based License?

A
  • license that allows to use VM-Series firewall for a specified period of time
  • it has an expiration date and you will be prompted to renew the license before it expires
22
Q

What are Term-based licenses available for?

A

capacity licenses, support entitlements, and subscriptions

23
Q

How does the multi-model VM-Series ELA work?

A
  1. forecast the number of firewalls that needed over the term of subscription
  2. based on the forecast and an additional allotment that accommodates for future growth, your account on the CSP is credited with a license token pool that allows to deploy any model of the VM-Series firewall
  3. depending on the firewall model and the number of firewalls deployed, a specified number of tokens are deducted from available license token pool
  4. tokens drawn from the account are calculated based on the value of each firewall model
24
Q

How many tokes are deducted for VM-50?

A

10 tokens

25
Q

How many tokes are deducted for VM-100?

A

25 tokens

26
Q

How many tokes are deducted for VM-300?

A

50 tokens

27
Q

How many tokes are deducted for VM-500?

A

140 tokens

28
Q

How many tokes are deducted for VM-700?

A

300 tokens

29
Q

How does PAYG license work?

A
  1. the firewall is prelicensed and ready for use as it is deployed; no auth code is received
  2. when firewall is stopped or terminated from Cloud console, PAYG licenses are suspended or terminated
  3. VM-Series capacity license is applied based on the hardware allocated to the instance
30
Q

Which billing options does PAYG firewall from AWS Marketplace support?

A

hourly and annual

31
Q

Which billing options does PAYG firewall from Azure Marketplace support?

A

hourly

32
Q

Which billing options does PAYG firewall from GCP Marketplace support?

A

per-minute

33
Q

What is the time period within which a warning message displays in the system log daily until you renew the subscription or it expires?

A

30 days

34
Q

What is the precise moment of license expiry?

A
  • 12:00 AM Greenwich Mean Time (GMT)
  • all license-related functions operate on GMT, regardless of the configured time zone on the firewall
35
Q

Can Panorama still manage the firewall of which the support license expires? What is the catch?

A

yes, but content updates are not available for the firewall, which will later cause commit errors, as the packages need to be the same on firewall and Panorama

36
Q

What are the limitations if the support license expires?

A
  • can no longer:
    • receive software updates
    • download VM images
    • benefit from technical support
37
Q

What are the limitations if the VM-Series expires?

A
  • can continue to configure and use the firewall you deployed prior to the license expiring with no change in session capacity and the firewall won’t reboot automatically and cause a disruption in traffic
  • if the firewall reboots for any reason, the firewall enters an unlicensed state and while unlicensed, a firewall supports a maximum of 1,200 sessions
38
Q

What are the limitations if the DNS Security license expires?

A

cannot get new DNS signatures

39
Q

What are the limitations if the Threat Prevention
license
expires?

A
  • can use signatures installed at the time the license expired, unless you install a new Applications-only content update either manually or as part of an automatic schedule - f you do, the update will delete your existing threat signatures and you will no longer receive protection against them
  • cannot install new signatures or roll signatures back to previous versions
40
Q

What are the Advanced URL Filtering / URL Filtering
license
expires?

A
  • get updates to cached PAN-DB categories
  • connect to the PAN-DB URL filtering database
  • get PAN-DB categories of uncached URLs
  • analyze URL requests in real-time using Advanced URL Filtering
41
Q

In case of license deactivation, where does the process start?

A

on the firewall or Panorama (not on the Palo Alto Networks Customer Support web site)

42
Q

What needs to be done to successfully deactivate a license?

A

install a license deactivation API key and enable verification of the update server identity (enabled by default)

43
Q

When is the deactivation API key not required?

A

for manual license deactivation, where there is not connectivity between the firewall and license server

44
Q

What is the process of manual license key deactivation?

A
  1. from the firewall or Panorama, you generate and export a license token file that includes information on the deactivated keys
  2. while logged in to the CSP, upload the token file to dissociate the license keys from the firewall
45
Q

What are the steps for auto mode license deactivation?

A
  1. log in to CLI
  2. view the name of the license key for the feature you want to deactivate with request license deactivate key features
  3. deactivate the license or subscription with request license deactivate key features <name> mode auto
46
Q

What should be done before deleting a VM firewall?

A

licenses should be deactivated

47
Q

What are the options if firewall is deleted before deactivating the licenses?

A
  • if firewall is managed from Panorama, it is possible to deactivate them from there
  • if the firewall is not managed from Panorama, open a TAC case
48
Q

Which billing options does PAYG firewall from OCI Marketplace support?

A

hourly

PAN-OS 10.0.3 or later

49
Q

Can firewall rely on Panorama for connectivity to license server in the absence of direct connectivity to the internet from the firewall?

A

yes; the Licensing plugin also supports timeout-based de-licensing

50
Q

What is the possible validity period that can be used for software NGFW credits?

A

can be defined for any amount of time between one and five years

51
Q

Do also unallocated credits expire or are they transferred to a new term?

A

both allocated and unallocated credits expire at the end of the agreed-upon term

52
Q

Can you purchase additional credits for a credit pool?

A

yes, but the expiration date must be the same as the target pool