Discovery of Cloud NGFW for Azure on Strata Cloud Manager
Automatically detect and visualize Cloud NGFW for Azure resources in Strata Cloud
Manager for a unified topological view of your cloud infrastructure and network
dependencies.
| Where Can I Use This? | What Do I Need? |
- Cloud NGFW for Azure (Managed by Strata Cloud Manager)
|
- Azure cloud accounts onboarded onto Strata Cloud Manager with
discovery enabled
- Required cross-account permissions granted for Azure
visibility
|
Strata Cloud Manager provides a unified, topological view of your cloud infrastructure
and maps network dependencies for Cloud NGFW for Azure. The discovery service enables
automated detection and visualization of both existing and newly deployed Azure firewall
resources.
Network changes in Azure can take approximately
10 minutes to reflect in the Strata Cloud Manager discovery view.
Prerequisites
Before you can discover Cloud NGFW for Azure deployments in Strata Cloud Manager,
ensure the following requirements are met:
Discovery and Visualization
The discovery service identifies Cloud NGFW resources in Azure using their unique
Resource IDs, enabling accurate mapping across both standard VNet and virtual WAN
(vWAN) architectures:
- Network topology map: Strata Cloud Manager represents Cloud NGFW as an
inline hop on a topological map, showing its exact position within the network
traffic flow.
- Asset inventory: Strata Cloud Manager automatically detects and displays
all Palo Alto Networks-managed firewalls, including those managed by Panorama,
Strata Cloud Manager, or local rulestacks.
- Operational health: Strata Cloud Manager displays real-time health
metrics showing whether instances are healthy or unhealthy. In Azure, a cluster
is considered healthy if it has at least one instance in a chosen zone, as it
supports cross-zone load balancing.
- Application-centric view: You can see the complete traffic path from an
application's source to its destination, whether that destination is another
cloud application or the public internet.
Panorama-managed and local
rulestack-managed Cloud NGFW for Azure resources are discovered in Strata Cloud
Manager, but their serial number and type display as N/A. Only Strata Cloud
Manager-managed firewalls show serial number and resource name details.
Supported Deployment Topologies
The discovery service validates two Cloud NGFW for Azure deployment models.
Centralized VNet peering
The discovery service examines User Defined Routes (UDRs). For
application-to-application traffic to be categorized as protected, the UDR's next
hop must target the private IP address of the hub VNet where the Cloud NGFW
resource is hosted.
Azure Virtual WAN (vWAN)
The discovery service evaluates routing intent inside the Azure Virtual WAN. For
application-to-application traffic paths, the routing intent's next hop for private
traffic must point explicitly to the Cloud NGFW Network Virtual Appliance (NVA)
link.
Strata Cloud Manager Dashboard Visibility
After you onboard your Cloud NGFW for Azure account and enable discovery in Strata
Cloud Manager, discovered resources and their details appear across two primary
sections.
Application-centric view
In the Strata Cloud Manager console, go to the Applications
dashboard. The application-centric view provides a tabular list of discovered
application assets, including each deployment's protection status (Protected or
Unprotected), application type, and cloud provider.
Connectivity view
Select . The connectivity view provides:
- Asset mapping: A visual topology showing application VNets connected
through their respective connectivity elements—such as vWAN hubs or VNet
peerings—to the firewall cluster.
- Resource metadata: Selecting a discovered Cloud NGFW asset shows its
Azure Resource ID, subscription path, the total number of applications it
protects, and its active deployment mode.
- Granular traffic status: Protection profiles broken down by traffic
vector—App-to-Internet, Users-to-App, and App-to-Models.
- Logs and metrics: When fully managed by Strata Cloud Manager through a
global rulestack, the dashboard shows traffic volume metrics (in bytes) and
active threat data.