Palo Alto Networks firewall license renewals: what MSPs need to know

Threat Prevention, Advanced URL Filtering, WildFire, DNS Security and the Core Security bundle, exactly what freezes and what keeps working when a PA-Series subscription expires, why support renewals never get a gap, co-term by quote date, end-of-life dates for the PA-220, PA-800, and PA-3200, and where the expiration date lives.

Last checked against Palo Alto Networks documentation on . Vendor policies change; the sources at the bottom are the record.

Palo Alto publishes the most detailed expiry table of any vendor on this site, and its theme is freezing rather than stopping. When Threat Prevention expires the firewall keeps using the signatures it already has and simply cannot install new ones. When URL Filtering expires, custom categories still enforce and the cached PAN-DB categories stop updating. The firewall does not stop protecting; it stops learning.

The rule that shapes late renewals is on the support side: support renewals always start at the end of the previous contract regardless of any gap, and Palo Alto's end-of-life policy says support cannot be allowed to lapse and be reinstated later on hardware past end of sale. A lapse on a PA-Series is paid for either way.

Palo Alto Networks license tiers

TierWhat it includes
Threat Prevention / Advanced Threat PreventionAntivirus, anti-spyware with command-and-control detection, vulnerability protection, and built-in external dynamic lists. Advanced adds an inline cloud-based detection engine using deep learning models.
Advanced URL FilteringCloud-based, machine-learning web security with real-time inspection of web traffic, on top of the PAN-DB category database.
Advanced WildFireCloud analysis of unknown files including intelligent run-time memory analysis, with five-minute signature updates. Without it, a firewall with active Threat Prevention still receives WildFire signatures within 24 to 48 hours through the antivirus update.
DNS Security / Advanced DNS SecurityCloud-queried DNS sinkholing; requires Threat Prevention. Advanced adds inspection of DNS responses for hijacked and misconfigured domains.
SD-WAN, GlobalProtect, IoT SecuritySD-WAN: dynamic path selection and automatic VPN topology. GlobalProtect Gateway: licensed per gateway; unlocks HIP checks, mobile and Linux apps, IPv6, and Clientless VPN. IoT Security: machine-learning device discovery, policy recommendations, and Device-ID.
Support: Standard / Premium / PlatinumStandard: online support, Severity 1 response under 2 hours, return-and-repair hardware replacement, business hours Pacific. Premium: 24x7 phone, Severity 1 under 1 hour, advance replacement with next-business-day delivery; 4-hour RMA is a paid US-only upgrade. Platinum: Premium plus 15-minute Severity 1, a designated engineer, and on-site troubleshooting.

For the PA-400 and PA-1400, distributors sell a Core Security bundle of Advanced Threat Prevention, Advanced URL Filtering, Advanced WildFire, Advanced DNS Security, and SD-WAN, with SKUs like PAN-PA-410-BND-CORESEC-3YR. Support is always sold separately. The bundle contents are from a distributor bulletin and reseller listings rather than a Palo Alto page.

Available terms

Subscriptions and support are listed in 1-, 3-, and 5-year SKUs, new and renewal, with HA-pair variants. The 5-year term and the SKU pattern are reseller-sourced.

Attached subscriptions start when they are activated or 90 days after delivery of the authorization code, whichever comes first, and they expire at the end of the term even if never activated. Sitting on an authorization code costs term.

What happens when a Palo Alto Networks license expires

A license expires at 12:00 AM GMT at the beginning of the day after the expiration date. For the 30 days before that, a warning appears in the system log daily and cannot be disabled.

Threat Prevention expired: the firewall keeps using its existing and custom signatures but cannot install new signatures, roll back, or use the real-time machine-learning detection engines. DNS Security expired: local DNS signatures keep working with active Threat Prevention, with no new ones. Advanced URL Filtering expired: custom URL categories still enforce; cached PAN-DB categories stop updating and cloud lookups stop. WildFire expired: files can still be forwarded and signatures still arrive in 24 to 48 hours through Threat Prevention, but the five-minute updates stop.

GlobalProtect expired: the Windows and macOS apps, portal, and gateways keep working; Linux, iOS, Android, ChromeOS, and UWP apps, HIP checks, Clientless VPN, IPv6 external gateways, and advanced split tunneling are lost. IoT Security expired: the cloud unsubscribes from the log feed, the firewall clears its cached mappings after 200 minutes, and Device-ID rules stop matching.

Support expired: no software updates and no technical support. Palo Alto's support portal states that software updates cannot be downloaded for a platform with expired support. Panorama with expired support still manages firewalls and collects logs but receives no software or content updates.

Palo Alto publishes no post-expiry grace period for hardware-firewall subscriptions. The only stated grace periods are 30 days for Prisma SD-WAN and 15 days for Prisma Access.

Renewing after a lapse

Support: Palo Alto's policy states that grace periods do not apply to support contract renewals, and support renewals always start at the end of the previous contract regardless of any gap. VM-Series and software firewall renewals behave the same way.

Subscriptions: per a 2026 LIVEcommunity answer, a lapsed order with standard term dates starts on the fulfillment date and runs the quoted term, while a lapsed order quoted with a specific co-term date starts on fulfillment and expires on the quoted co-term date. That is a community post rather than a policy page, so confirm with your reseller on any lapsed subscription.

On hardware past end of sale the stakes are higher: Palo Alto's end-of-life policy grants the five years of post-end-of-sale support only if a valid support contract is maintained continuously, and support cannot be allowed to lapse and be reinstated later.

Palo Alto publishes no reinstatement fee. Renewals go through the reseller or account manager, and emergency license extensions are handled by the regional quotes and renewals mailboxes.

Co-terming

Co-terming on Palo Alto is done on the quote. A co-term date on the renewal quote sets the expiration regardless of when the order is fulfilled, and Palo Alto's renewals team produces coterminous quotes as a normal part of the job. Palo Alto has no separately published co-term policy page.

The practical target is the hardware end-of-life date, since support cannot extend past it and the five-year post-end-of-sale window requires continuous coverage.

End of sale and end of life

Palo Alto defines end of sale as the last day a product can be ordered and end of life as the last day it is supported. Hardware receives technical assistance and replacement parts for five years after end of sale, provided a valid support contract is maintained continuously through that period.

Each end-of-sale model also has a last supported PAN-OS release, which caps what the device can run for its remaining life. The PA-440 and PA-410 had no end-of-sale announced as of the check date.

ModelEnd of saleEnd of life / supportNote
PA-2202023-01-312028-01-31Last PAN-OS 10.2. Replacement: PA-400 series.
PA-820 / PA-8502024-08-312029-08-31Last PAN-OS 11.1. Replacement: PA-1400 series.
PA-32202023-08-312028-08-31Last PAN-OS 11.1.
PA-410 / PA-440No end of sale announced as of the check date.

Where to find the expiration date

  • Firewall: Device > Licenses lists each subscription with its expiration and is where keys are retrieved from the license server or activated with an authorization code.
  • Panorama: Device Deployment > Licenses shows whether each license is active or inactive and its expiration date across managed firewalls. Panorama checks in daily between 1 and 2 a.m. and pushes renewed licenses.
  • Customer Support Portal: Assets > Devices, or Assets > Network Security > Licenses Expiring. The portal cannot send expiration notifications on its own.
  • Alerts: the daily system-log warning for the 30 days before expiry can drive a syslog or email alert profile and cannot be turned off.

How the renewal moves

Renewals go through the reseller or the Palo Alto account manager, and the license attaches to the device serial number registered in the customer's Customer Support Portal account. The serial belongs on every pricing request.

Renewal SKUs follow a readable pattern: PAN-PA-440-TP-3YR-R for a 3-year Threat Prevention renewal on a PA-440, PAN-PA-440-ADVURL-5YR-R for Advanced URL Filtering, and PAN-SVC-PREM-440-3YR-R for Premium support. HA pairs use an -HA2 variant. Partner-delivered Premium support carries a PAN-SVC-BKLN prefix.

Once the order is fulfilled, the firewall retrieves the new keys from the license server on Device > Licenses, or Panorama pushes them on its daily check-in.

How MSP Renewals tracks Palo Alto Networks

MSP Renewals stores each PA-Series firewall with its serial number, the support tier you sell it on (Premium or Standard), the term you normally quote, and the expiration date you enter or sync. It alerts at 90, 30, and 5 days, drafts the renewal quote at 90 days, and can send the pricing request to your distributor automatically with the serial, tier, term, and your reference number.

Because support renewals always start at the previous contract's end and subscriptions co-term by quote date, the pricing request asks the distributor to state the effective start and end dates on the quote. When the client approves, the device's expiration rolls forward by the term you sold and the countdown restarts.

Palo Alto Networks renewal questions

Does a Palo Alto firewall stop passing traffic when a subscription expires?
No. Palo Alto's expiry table shows every subscription freezing rather than stopping: Threat Prevention keeps its existing signatures, custom URL categories still enforce, and GlobalProtect's Windows and macOS apps keep connecting. What stops is updates, cloud lookups, and the advanced features.
Is there a grace period on Palo Alto subscriptions?
Not for hardware firewall subscriptions. Licenses expire at midnight GMT the day after the expiration date. The only published grace periods are 30 days for Prisma SD-WAN and 15 days for Prisma Access.
If Palo Alto support lapsed, does the renewal start today or on the old date?
On the old date. Palo Alto's policy says grace periods do not apply to support renewals and they always start at the end of the previous contract regardless of any gap. On hardware past end of sale, a lapse can also forfeit the five years of post-end-of-sale support, which requires continuous coverage.
What still works if URL Filtering expires?
Custom URL categories continue to enforce. The cached PAN-DB categories stop updating and cloud lookups for uncategorized sites stop, so new sites go unrated.
Can I still download PAN-OS updates with expired support?
No. Palo Alto states that software updates cannot be downloaded for a platform whose support has expired. Content updates need active subscriptions as well.
How long can I renew support on a PA-220 or PA-850?
Until end of life: January 31, 2028 for the PA-220 and August 31, 2029 for the PA-820 and PA-850, and only if support has been maintained continuously since end of sale. The PA-220 is capped at PAN-OS 10.2 and the PA-800 series at 11.1.

Sources