To take advanced of inline cloud analysis, you must have a persistent, active
cloud connection used by Prisma Access to handle inline cloud analysis service
requests. When the
Advanced Threat Prevention license is enabled, Prisma Access
performs PAN-DB URL categorization lookups as part of its internal processing,
independent of any URL Filtering license or explicit cloud inline configuration.
This is facilitated by the Cloud Content FQDN. The default FQDN connects to
hawkeye.services-edge.paloaltonetworks.com and then resolves to the closest
cloud services server. You can override the automatic server selection by
specifying a regional cloud content server that best meets your data residency
and performance requirements.
The Cloud Content FQDN is a globally used resource and affects how other
services that rely on this connection sends traffic payloads.
Verify that the firewall uses the correct Content Cloud FQDN () for your region and change the FQDN as necessary:
US Central (Iowa,
US)—us.hawkeye.services-edge.paloaltonetworks.com
Europe (Frankfurt,
Germany)—eu.hawkeye.services-edge.paloaltonetworks.com
APAC
(Singapore)—apac.hawkeye.services-edge.paloaltonetworks.com
India
(Mumbai)—in.hawkeye.services-edge.paloaltonetworks.com
UK (London,
England)—uk.hawkeye.services-edge.paloaltonetworks.com
France (Paris,
France)—fr.hawkeye.services-edge.paloaltonetworks.com
Japan (Tokyo,
Japan)—jp.hawkeye.services-edge.paloaltonetworks.com
Australia (Sydney,
Australia)—au.hawkeye.services-edge.paloaltonetworks.com
Canada (Montréal,
Canada)—ca.hawkeye.services-edge.paloaltonetworks.com
Switzerland (Zürich,
Switzerland)—ch.hawkeye.services-edge.paloaltonetworks.com
Israel (Tel Aviv,
Israel)—il.hawkeye.services-edge.paloaltonetworks.com
FedRAMP High—Refer to the
product entry
PanOS CC (Cloud Component)
FedRAMP (Moderate and High) currently does not support the
following
Advanced Threat Prevention features:
Update or create a new Anti-Spyware security profile to enable inline cloud
analysis (to analyze traffic for advanced C2 [command-and-control] and spyware
threats in real-time).
Select .
Select your Anti-Spyware security profile and navigate to the
Inline Cloud Analysis panel and
Enable Inline Cloud Analysis.
Select enable for each available analysis
engine with a Local Deep Learning (LDL)
option. There are currently two analysis engines available with an
optional LDL mode: HTTP Command and Control
detector and HTTP2 Command and Control
detector.
Specify an Action to take when a threat is
detected using a corresponding analysis engine.
The default action for each analysis engine is
alert, however, Palo Alto Networks
recommends setting all actions to
Reset-Both for the best security
posture.
Click Save to exit the Anti-Spyware security
profile configuration dialog and Commit your
changes.
(Optional) Add URL and/or IP address exceptions to your Anti-Spyware
profile if Inline Cloud Analysis produces false-positives. You can add
exceptions by specifying an EDL URL containing a series of URLs or a custom URL
category or an IP address list defined in an EDL or within an Address
object.
Add an External Dynamic Lists or [IP]
Addresses object exception.
Select .
Select an Anti-Spyware profile for which you want to exclude specific
URLs or IP addresses and then go to the Inline Cloud
Analysis pane.
Add EDL/URL or
Add IP
Address, depending on the type of exception you want
to add, and then select a preexisting URL or IP address external
dynamic list. If none is available, create a new
external dynamic list policy
object. For IP address exceptions, you can, optionally,
select an
Addresses object list.
Click Save to save the Anti-Spyware profile
and Commit your changes.
Update or create a new Vulnerability Protection Security profile to enable
inline cloud analysis (to analyze traffic for command injection and SQL
injection vulnerabilities in real-time).
Select an existing Vulnerability Protection security profile or
Add Profile to create a new one ().
Select your Vulnerability Protection profile and then go to
Inline Cloud Analysis and
Enable cloud inline analysis.
Specify an Action to take when a vulnerability
exploit is detected using a corresponding analysis engine. There are
currently two analysis engines available: SQL
Injection and Command
Injection.
Click Save to exit the Vulnerability
Protection Profile configuration dialog and
Commit your changes.
Add URL and/or IP address exceptions to your Vulnerability Protection profile
if Inline Cloud Analysis produces false-positives. You can add exceptions by
specifying an EDL URL containing a series of URLs or a custom URL category or an
IP address list defined in an EDL or within an Address object.
Add an External Dynamic Lists or [IP]
Addresses object exception.
Select to return to your Vulnerability Protection
profile.
Select a Vulnerability profile for which you want to exclude specific
URLs and/or IP addresses and then select Inline Cloud
Analysis.
Add an EDL/URL or
IP Address, depending on the type of
exception you want to add, and then select a pre-existing URL or IP
address external dynamic list. If none are available, create a new
external dynamic list. For IP address exceptions, you can
optionally, select an Addresses object
list.
Vulnerability profiles that are configured as
Shared on Panorama-managed firewalls
cannot have IP address objects added to the Inline Cloud
Analysis exceptions list.
Click Save to save the Vulnerability
Protection profile and Commit your
changes.
Configure the timeout latency and action to take when the request exceeds the
max latency.
Select and Customize.
Specify the timeout value and the associated action to take when
latency limits are reached for inline cloud analysis requests. Use
the Log Traffic Not Scanned function to
fine-tune your Max Latency settings. By
testing various threshold values, you can identify the optimal
balance for your network environment. If the latency setting is too
low, Prisma Access bypasses (does not scan) using inline cloud
analysis and, instead, generates a threat log entry to notify you
that the scan was skipped.
Max Latency (ms)—Specify the maximum acceptable processing
time, in milliseconds, for Inline Cloud Analysis to return a
result. The default value is 200ms.
Allow on Max Latency—Enables the Prisma Access to take the
action of allow, when the maximum latency is reached.
De-selecting this option sets the action to block.
Log Traffic Not Scanned— Enables the Prisma Access to log
traffic requests that exhibit anomalous traits indicating
the presence of advanced evasive command-and-control (C2)
threats and zero-day exploits, but have not been processed
by Advanced Threat Prevention Inline Cloud analyzers.
The threat logs generated by Log Traffic Not
Scanned are defined by the following
characteristics:
Threat
Category—inline-cloud-c2
Application—Either
unknown-udp or
unknown-tcp
Does not generate a cloud report.
Click Save to confirm your changes.