Edit the Cloud Content Settings
Focus
Focus
Advanced Threat Prevention Powered by Precision AI®

Edit the Cloud Content Settings

Table of Contents

Edit the Cloud Content Settings

Edit the Cloud Content Settings to specify the server used by the firewall to handle inline cloud analysis service requests for Advanced Threat Prevention.
To take advantage of inline cloud analysis, you must have a persistent, active cloud connection used by the firewall to handle inline cloud analysis service requests. When the Advanced Threat Prevention license is enabled, the firewall performs PAN-DB URL categorization lookups as part of its internal processing, independent of any URL Filtering license or explicit cloud inline configuration. This is facilitated by the Cloud Content FQDN.
The default FQDN connects to hawkeye.services-edge.paloaltonetworks.com and then resolves to the closest cloud services server. You can override the automatic server selection by specifying a regional cloud content server that best meets your data residency and performance requirements.
The Cloud Content FQDN is a globally used resource and affects how other services that rely on this connection send traffic payloads.
  1. Navigate to the Content-ID settings.
    • NGFW—Select DeviceSetupContent-ID and edit the Content Cloud Settings.
    • Panorama—Select DeviceSetupContent-ID and select the Template associated with the managed firewalls using Advanced Threat Prevention.
  2. Modify the Public Cloud Server based on your data residency requirements.
    Verify that the firewall uses the correct Cloud Content FQDN for your region and change the FQDN if necessary.
    If your firewall is configured inline to facilitate a SaaS Security deployment, the FQDNs located in France and Japan do not currently support SaaS Security functionality.
    Review the list of
    • Public Cloud Server by Region
      • Defaulthawkeye.services-edge.paloaltonetworks.com
        The default Public Cloud Server automatically resolves to the closest Public Cloud Server to where the inspected traffic originated.
      • United States (Central)us.hawkeye.services-edge.paloaltonetworks.com
      • Europe (Germany)eu.hawkeye.services-edge.paloaltonetworks.com
      • APAC (Singapore)apac.hawkeye.services-edge.paloaltonetworks.com
      • Indiain.hawkeye.services-edge.paloaltonetworks.com
      • United Kingdomuk.hawkeye.services-edge.paloaltonetworks.com
      • Francefr.hawkeye.services-edge.paloaltonetworks.com
      • Japanjp.hawkeye.services-edge.paloaltonetworks.com
      • Australiaau.hawkeye.services-edge.paloaltonetworks.com
      • Canadaca.hawkeye.services-edge.paloaltonetworks.com
      • Switzerlandch.hawkeye.services-edge.paloaltonetworks.com
      • Israelil.hawkeye.services-edge.paloaltonetworks.com
      • FedRAMP ModerateRefer to the product entry PanOS Cloud Component
      • FedRAMP HighRefer to the product entry PanOS CC (Cloud Component)
        FedRAMP (Moderate and High) currently does not support the following Advanced Threat Prevention features:
        • Exfiltration Shield
        • UTCP and UUDP Models
        • PCAP retrieval for malicious detections
  3. Click OK.
  4. Commit and push the configuration to your managed firewalls.