Cloud NGFW for AWS Enterprise Data Loss Prevention (E-DLP) Integration
Focus
Focus
Cloud NGFW for AWS

Cloud NGFW for AWS Enterprise Data Loss Prevention (E-DLP) Integration

Table of Contents

Cloud NGFW for AWS Enterprise Data Loss Prevention (E-DLP) Integration

Learn how to use Enterprise Data Loss Prevention (E-DLP) with Cloud NGFW for AWS.
Where Can I Use This?What Do I Need?
  • Cloud NGFW for AWS
  • Cloud NGFW subscription
  • Panorama or Strata Cloud Manager instance associated with a Tenant Service Group (TSG)
  • TSG with at least one active application instance (such as Strata Cloud Manager Essentials, Strata Logging Service, or AIOps)
  • Valid Enterprise DLP entitlements
Enterprise Data Loss Prevention (E-DLP) is a cloud-delivered service that protects sensitive information against unauthorized access, misuse, extraction, or sharing. For more information, see About Enterprise DLP.
Cloud NGFW for AWS automatically provisions an Enterprise DLP tenant when you link your policy management instance—Panorama or Strata Cloud Manager—to your Cloud NGFW account. The Enterprise DLP tenant is associated with your Tenant Service Group (TSG), and no additional setup is required to enable the service.
You can integrate E-DLP with Cloud NGFW for AWS and use the Panorama console to add data filtering profiles to your Security Policy rules.
Cloud NGFW for AWS exclusively supports E-DLP. All data-filtering profiles configured in Panorama are treated as E-DLP usage and billed at the E-DLP add-on price. To prevent unexpected charges, verify that no data-filtering profiles remain active in security rules you don't intend to monitor.
Minimum Requirements
The following are the combination of Panorama and Panorama plugin version requirements to integrate E-DLP with your Cloud NGFW service:
Panorama Version (PAN-OS)DLP PluginAWS Plugin
10.0.2 and above
1.0.9
5.5.1
10.2.4 and above
3.0.7
5.5.1
11.0.2 and above
4.0.3
5.5.1
11.1.0 and above
5.0.1
5.5.1

Prerequisites

Before Enterprise DLP can be provisioned for your Cloud NGFW account, ensure the following requirements are met:
  1. Your Panorama or Strata Cloud Manager (SCM) instance must be associated with a Tenant Service Group (TSG).
  2. The target TSG must contain at least one existing application instance (such as SCM Essentials, Cortex Data Lake/SLS, or AIOps).
  3. Ensure your support account possesses valid Enterprise DLP entitlements.

Enterprise DLP Provisioning for New Users

Panorama / SCM Linking: When you link a new Panorama or SCM tenant to Cloud NGFW AWS, the system automatically checks your TSG for an existing DLP tenant.
  • If a DLP tenant already exists in the TSG, Cloud NGFW attaches to the existing DLP tenant ID.
  • If no DLP tenant exists, Cloud NGFW automatically provisions a new DLP tenant in the TSG out of the box.
As Cloud NGFW firewall instances are created, their serial numbers are automatically registered and associated with the TSG's Enterprise DLP tenant.
For existing Cloud NGFW AWS deployments, Enterprise DLP enablement depends on your policy management integration:
  • Panorama Link:Enterprise DLP is not automatically provisioned for existing (brownfield) Panorama integrations. To enable the Enterprise DLP tenant, you must open a support ticket with Palo Alto Networks. Ensure your Panorama link is associated with a TSG containing at least one active service prior to ticket submission.
  • Strata Cloud Manager (SCM) Link:
    • Standard Brownfield Deployments: Enterprise DLP is not automatically provisioned. You must open a support ticket with Palo Alto Networks to request tenant provisioning and linking.
    • Simplified Onboarding Tenant Workflow: For existing SCM deployments utilizing the Simplified Onboarding Workflow, Enterprise DLP is automatically provisioned in the backend during migration with no additional manual setup required.
  • SCM with Simplified Onboarding Tenant Workflow: Tenants onboarded through the simplified SCM workflow automatically inherit Enterprise DLP entitlements upon association with a valid TSG, requiring no additional manual setup or migration steps.

Verify Enterprise DLP Status on Cloud NGFW for AWS

Use the following steps to verify the E-DLP status on your Cloud NGFW Console.
  1. Log in to the Cloud NGFW Console.
  2. Select SettingsManagement / Integrations.
  3. Select your linked Panorama or Strata Cloud Manager tenant.
  4. Under Security Services, confirm that Data Loss Prevention displays Enabled.

Configure and Push Security Policies

Once the DLP tenant is provisioned, manage DLP rules directly from Panorama or Strata Cloud Manager:
  1. In the Panorama or Strata Cloud Manager console, configure your Data Filtering Profiles and Data Filtering Patterns. For more information see, Creating data filtering profiles on Panorama/Strata Cloud Manager.
  2. Attach the Data Filtering Profile to your Security Policy Rules under profile settings. For more information see, attaching data filtering profiles on Panorama and Strata Cloud Manager.
  3. Commit and push the configuration changes to your Cloud NGFW device groups/rulestacks.
  4. Cloud NGFW firewalls will enforce Enterprise DLP data filtering inspection on matching traffic flows.

Monitoring DLP Log Details

To view your DLP logs in Panorama, click the Monitor tab, and then go to Logs > Data Filtering. For more information, see View Enterprise DLP Log Details on Panorama.
To view your Strata Logging Service logs for DLP, go to the Explore tab, and select the Firewall or File option. For more information, see View Log Details on Strata Logging Service.
To view your DLP tenant incidents logs on SCM, see View Enterprise DLP Log Details on Strata Cloud Manager.
For more information on AWS destinations on DLP logs, see Amazon CloudWatch Logs.