: Link the Cloud NGFW to Palo Alto Networks Management
Focus
Focus

Link the Cloud NGFW to Palo Alto Networks Management

Table of Contents

Link the Cloud NGFW to Palo Alto Networks Management

Link Cloud NGFW to Panorama
You have two options for linking:
  1. Link the Cloud NGFW to Palo Alto Networks with Panorama for policy management only.
  2. Link the Cloud NGFW tenant with Panorama for policy management and Cortex Data Lake for log management.
You must be subscribed to the Cloud NGFW service using AWS Marketplace to integrate Cloud NGFW with Panorama. After linking your Cloud NGFW tenant to Panorama, you can view the tenants and resources, along with their status, in the Panorama console under the AWS plugin.
See Unlink the Cloud NGFW from Palo Alto Networks Management to remove an existing Panorama virtual appliance from the Cloud NGFW resource. If you're using AWS Firewall Manager, you can't unlink Panorama from your Cloud NGFW resource. See Create a support case to unlink Cloud NGFW from Panorama when using AWS Firewall Manager for additional information.
To link your Cloud NGFW tenant to Panorama using the Cloud NGFW:
  1. Select
    Integrations
    .
  2. In the
    Integrations
    page, click
    Add Panorama
    .
    If you're using a tenant linked to Panorama that was created using the AWS Firewall Manager you can't unlink the Cloud NGFW resource.
  3. In the
    Add Panorama
    screen, enter a
    Link Name
    . Select the
    Primary Panorama Serial Number
    from the drop-down. For HA environments, select the
    Secondary Panorama Serial Number
    from the drop-down.
    This screen displays two different icons describing the state of the Panorama license; a Panorama linked to CDL, and a Panorama that isn't linked to CDL. The image below illustrates these icons:
    If you select a Panorama serial number that isn't linked to CDL, you must specify an option to either cancel the linking process, in which case you agree to procure a CDL license and associate it with your Panorama appliance, or you agree to continue using Panorama for policy management only:
    If you select a Panorama license that is already connected to a CDL, you're asked to
    Confirm
    the association before continuing with the integration process:
    After selecting the Panorama license, click
    Continue
    . The
    Integrations
    page displays the
    Link ID
    and the linked
    Panorama Serial Number
    :
    The Cloud NGFW tenant automatically pulls the CDL information from Panorama. If you don't plan to use CDL for logging, you can send logs to AWS. For more information, see Configure Logging for Cloud NGFW on AWS.
    The
    Integrations
    page displays the
    Link ID
    and the linked
    Panorama Serial Number
    . For additional information, including the Cortex Data Lake ID, select the
    For additional information, including the Cortex Data Lake ID associated with the linked Panorama, click the
    Link ID
    in the
    Integrations
    page. The
    Link Panorama
    window appears:

Unsubscribe a Cloud NGFW Tenant from AWS Marketplace

To unsubscribe a Cloud NGFW tenant from AWS Marketplace:
  1. Sign in to the AWS Management Console.
  2. Go to the
    My Subscriptions
    page.
  3. Select the subscription for the product that you want to cancel.
  4. Choose
    Cancel subscription
    . After canceling your subscription, you can't launch your application.
    For more information, see Cancel your subscription.

Create a Support Case to Unlink Panorama from Cloud NGFW When Using AWS Firewall Manager

If you're using AWS Firewall Manager and linked a Cloud NGFW resource to Panorama, you must contact Palo Alto Networks Support to unlink the Cloud NGFW resource from Panorama. When creating the support case, you may be asked to provide additional information, like the AWS account ID, and the tenant ID for the resource.
To create a support case using the Cloud NGFW console:
  1. Locate your
    AWS Account ID
    . Select
    AWS Accounts
    .
  2. If required, use the Panorama console to determine additional information for the support case, like the tenant ID, or the Panorama serial number.
    Locate the
    Panorama serial number
    using the
    Dashboard
    :
    Locate the
    Tenant ID
    for the Cloud NGFW resource:
  3. On the
    Overview
    page in the Cloud NGFW console, click
    Create a case
    .

Recommended For You