Description

This article provides the recommended steps to install and activate a renewed SkyATP (Advanced Threat Prevention) license on a vSRX device.

Solution

To successfully install and activate the renewed SkyATP license, follow these steps:

  1. Protect Traffic During Transition
    Temporarily modify GeoIP-based “permit only” security policies (e.g., GEO_Whitelist) by changing the source address to any. This ensures that production traffic is not impacted during the process.

  2. Disenroll the Device from ATP
    Remove the vSRX device from SkyATP enrollment.

  3. Remove Device from ATP Portal
    Delete the corresponding device entry from the SkyATP cloud portal (devices list).

  4. Remove Old License
    Delete the expired or expiring SkyATP license key from the vSRX device.

  5. Install New License
    Add the renewed SkyATP license key to the device.

  6. Re-enroll the Device
    Re-enroll the vSRX with SkyATP.

    Note: It may take a few minutes for the cloud to synchronize. Temporary errors (e.g., HTTP 400 response) may occur during this period.

  7. Verify GeoIP and Dynamic Feeds
    Ensure that GeoIP feeds and dynamic address objects are fully restored and updated.

  8. Restore Security Policies
    Revert GeoIP-based policies from any back to the intended whitelist configuration.

  9. Validate Traffic Flow
    Monitor and confirm that traffic is flowing normally and that ATP services are functioning as expected.

Modification History

2023-10-20 : Article Created