Discovery of Cloud NGFW for Azure on Strata Cloud Manager
Focus
Focus
Prisma AIRS

Discovery of Cloud NGFW for Azure on Strata Cloud Manager

Table of Contents

Discovery of Cloud NGFW for Azure on Strata Cloud Manager

Automatically detect and visualize Cloud NGFW for Azure resources in Strata Cloud Manager for a unified topological view of your cloud infrastructure and network dependencies.
Where Can I Use This?What Do I Need?
  • Cloud NGFW for Azure (Managed by Strata Cloud Manager)
  • Azure cloud accounts onboarded onto Strata Cloud Manager with discovery enabled
  • Required cross-account permissions granted for Azure visibility
Strata Cloud Manager provides a unified, topological view of your cloud infrastructure and maps network dependencies for Cloud NGFW for Azure. The discovery service enables automated detection and visualization of both existing and newly deployed Azure firewall resources.
Network changes in Azure can take approximately 10 minutes to reflect in the Strata Cloud Manager discovery view.

Prerequisites

Before you can discover Cloud NGFW for Azure deployments in Strata Cloud Manager, ensure the following requirements are met:

Discovery and Visualization

The discovery service identifies Cloud NGFW resources in Azure using their unique Resource IDs, enabling accurate mapping across both standard VNet and virtual WAN (vWAN) architectures:
  • Network topology map: Strata Cloud Manager represents Cloud NGFW as an inline hop on a topological map, showing its exact position within the network traffic flow.
  • Asset inventory: Strata Cloud Manager automatically detects and displays all Palo Alto Networks-managed firewalls, including those managed by Panorama, Strata Cloud Manager, or local rulestacks.
  • Operational health: Strata Cloud Manager displays real-time health metrics showing whether instances are healthy or unhealthy. In Azure, a cluster is considered healthy if it has at least one instance in a chosen zone, as it supports cross-zone load balancing.
  • Application-centric view: You can see the complete traffic path from an application's source to its destination, whether that destination is another cloud application or the public internet.
Panorama-managed and local rulestack-managed Cloud NGFW for Azure resources are discovered in Strata Cloud Manager, but their serial number and type display as N/A. Only Strata Cloud Manager-managed firewalls show serial number and resource name details.

Supported Deployment Topologies

The discovery service validates two Cloud NGFW for Azure deployment models.
Centralized VNet peering
The discovery service examines User Defined Routes (UDRs). For application-to-application traffic to be categorized as protected, the UDR's next hop must target the private IP address of the hub VNet where the Cloud NGFW resource is hosted.
Azure Virtual WAN (vWAN)
The discovery service evaluates routing intent inside the Azure Virtual WAN. For application-to-application traffic paths, the routing intent's next hop for private traffic must point explicitly to the Cloud NGFW Network Virtual Appliance (NVA) link.

Strata Cloud Manager Dashboard Visibility

After you onboard your Cloud NGFW for Azure account and enable discovery in Strata Cloud Manager, discovered resources and their details appear across two primary sections.
Application-centric view
In the Strata Cloud Manager console, go to the Applications dashboard. The application-centric view provides a tabular list of discovered application assets, including each deployment's protection status (Protected or Unprotected), application type, and cloud provider.
Connectivity view
Select InsightsDiscover & Assets. The connectivity view provides:
  • Asset mapping: A visual topology showing application VNets connected through their respective connectivity elements—such as vWAN hubs or VNet peerings—to the firewall cluster.
  • Resource metadata: Selecting a discovered Cloud NGFW asset shows its Azure Resource ID, subscription path, the total number of applications it protects, and its active deployment mode.
  • Granular traffic status: Protection profiles broken down by traffic vector—App-to-Internet, Users-to-App, and App-to-Models.
  • Logs and metrics: When fully managed by Strata Cloud Manager through a global rulestack, the dashboard shows traffic volume metrics (in bytes) and active threat data.