Strata Cloud Manager Policy Management
Focus
Focus
Cloud NGFW for AWS

Strata Cloud Manager Policy Management

Table of Contents

Strata Cloud Manager Policy Management

Link your Cloud NGFW resource with Strata Cloud Manager (SCM) for policy management.
Where Can I Use This?What Do I Need?
  • Cloud NGFW for AWS
  • Cloud NGFW subscription
  • Palo Alto Networks Customer Support Account (CSP)
  • AWS Marketplace account
  • User role (either tenant or administrator)
You can integrate your Cloud NGFW resource with Strata Cloud Manager (SCM) for policy management. With this integration, you can now use a single Strata Cloud Manager to centrally manage a shared set of security rules on Cloud NGFW resources alongside your physical and virtual firewall appliances. You can also manage all aspects of shared policy configurations, gain comprehensive visibility with actionable insights, and generate reports on traffic patterns or security incidents of your Cloud NGFW resources, all from a single console.
When you get started from AWS Marketplace, you use the Cloud NGFW console to link your Cloud NGFW tenant with the Strata Cloud Manager and then create Cloud NGFW resources. See Cloud NGFW Policy management when started from the Cloud NGFW Console.
When you get started from Strata Cloud Manager, you use the Strata Cloud Manager as the single console to create Cloud NGFW resources and manage policies. For more information, see Coud NGFW Policy management when started from the Strata Cloud Manager.
Important Considerations:
When using SCM for Cloud NGFW policy management, consider the following:
  • X-forwarded functionality isn't supported in an SCM policy management for your Cloud NGFW resource.
  • Cloud certificate isn't supported.
  • DLP isn't supported.
  • DAGs isn't supported.
  • When configuring security rules for your SCM-managed Cloud NGFW resource, you must specify ANY for the security rule. However, from/to zone appears as the data Zone in the Strata Logging Service.