Zero Touch Provisioning (ZTP) for Palo Alto Networks Firewalls

Overview

Zero Touch Provisioning (ZTP) is a provisioning mechanism that allows unconfigured devices to automatically load deployment files upon power-on, including system software, patches, and configuration files. This eliminates the need for onsite, manual configuration and deployment, reducing labor costs and improving deployment efficiency.

Benefits of ZTP

How ZTP Works

  1. Upon power-on, the device obtains an IP address via DHCP.
  2. The device contacts the Palo Alto Networks ZTP service using preconfigured settings.
  3. The ZTP service authenticates the device using its serial number and claim key.
  4. Once authenticated, the device downloads the necessary configuration files and software updates.
  5. The device applies the configurations and connects to the Panorama management server for centralized management.

Implementing ZTP with Panorama

To set up ZTP with Panorama:

  1. Ensure a DHCP server is available on the network to provide IP addresses to new devices.
  2. Register the device's serial number and claim key in the Palo Alto Networks Customer Support Portal.
  3. In Panorama, add the device using its serial number and claim key.
  4. Assign the device to the appropriate device group and template stack.
  5. Power on the device and connect it to the network; it will automatically retrieve its configuration and connect to Panorama.

Note: Devices onboarded using ZTP cannot be configured in a High Availability (HA) setup until ZTP is disabled on the device.

Best Practices

References