Link the Cloud NGFW to Palo Alto Networks Management
Link Cloud NGFW to Panorama
You have two options for linking:
- Link the Cloud NGFW to Palo Alto Networks with Panorama for policy management only.
- Link the Cloud NGFW tenant with Panorama for policy management and Cortex Data Lake for log management.
You must be subscribed to the Cloud NGFW service using AWS Marketplace to integrate Cloud NGFW with Panorama. After linking your Cloud NGFW tenant to Panorama, you can view the tenants and resources, along with their status, in the Panorama console under the AWS plugin.
Once you link your Cloud NGFW resource to Panorama, you cannot unlink it. Palo Alto Networks recommends that you create a support case. For more information, see Create a Support Case later in this article.
To link your Cloud NGFW tenant to Panorama using the Cloud NGFW:
- In thePolicy Managementsection, clickEdit.TheEdit Policy Managementscreen displays Panorama serial numbers to integrate with your Cloud NGFW resource. This screen displays two different icons describing the state of the Panorama license; a Panorama linked to CDL, and a Panorama that is not linked to CDL. The image below illustrates these icons:
- In theEdit Policy Managementscreen, select thePrimary Panorama Serial Numberfrom the drop-down menu. For HA environments, select theSecondary Panorama Serial Numberfrom the drop-down menu.If you select a Panorama serial number that is not linked to CDL, you must specify an option to either cancel the linking process, in which case you agree to procure a CDL license and associate it with your Panorama appliance, or, you agree to continue using Panorama for policy management only:If you select a Panorama license that is already connected to a CDL, you are asked toConfirmthe association before continuing with the integration process:After selecting the Panorama license, clickContinue.The Cloud NGFW tenant automatically pulls the CDL information from Panorama. If you do not plan to use CDL for logging, you can send logs to AWS. For more information, see Configure Logging for Cloud NGFW on AWS.The Integrations page displays the serial numbers and CDL ID:
Create a support case
If you linked a Cloud NGFW resource to Panorama and you wish to unlink it, contact Palo Alto Support for additional information. When creating the support case, you may be asked to provide additional information, like the AWS account ID, and the tenant ID for the resource.
To create a support case using the Cloud NGFW console:
- Locate yourAWS Account ID. SelectAWS Accounts.
- If required, use the Panorama console to determine additional information for the support case, like the tenant ID, or the Panorama serial number.Locate the Panorama serial number using theDashboard:Locate theTenant IDfor the Cloud NGFW resource:
- On the Overview page in the Cloud NGFW console, clickCreate a Case.
Recommended For You
Recommended videos not found.