This article provides the recommended steps to install and activate a renewed SkyATP (Advanced Threat Prevention) license on a vSRX device.
To successfully install and activate the renewed SkyATP license, follow these steps:
Protect Traffic During TransitionTemporarily modify GeoIP-based “permit only” security policies (e.g., GEO_Whitelist) by changing the source address to any. This ensures that production traffic is not impacted during the process.
GEO_Whitelist
any
Disenroll the Device from ATPRemove the vSRX device from SkyATP enrollment.
Remove Device from ATP PortalDelete the corresponding device entry from the SkyATP cloud portal (devices list).
Remove Old LicenseDelete the expired or expiring SkyATP license key from the vSRX device.
Install New LicenseAdd the renewed SkyATP license key to the device.
Re-enroll the DeviceRe-enroll the vSRX with SkyATP.
Note: It may take a few minutes for the cloud to synchronize. Temporary errors (e.g., HTTP 400 response) may occur during this period.
Verify GeoIP and Dynamic FeedsEnsure that GeoIP feeds and dynamic address objects are fully restored and updated.
Restore Security PoliciesRevert GeoIP-based policies from any back to the intended whitelist configuration.
Validate Traffic FlowMonitor and confirm that traffic is flowing normally and that ATP services are functioning as expected.