Manage Cloud NGFW with Panorama.
| Where Can I Use This? | What Do I Need? |
|
|
- Cloud NGFW subscription
- Palo Alto Networks Customer Support Account (CSP)
- AWS Marketplace account
- User role (either tenant or administrator)
|
After linking your Cloud NGFW tenant to the Panorama virtual appliance you can start
using the integration for policy management tasks, such as adding device groups and
applying policies to the device group for the Cloud NGFW tenant using the Panorama
console.
When you use the Panorama console to configure the Cloud NGFW, the browser caches
local information, like the cloud device group, template stack and region, so that
as you switch between Panorama tasks, cached Cloud NGFW information is displayed in
the Panorama console.
When you select a tenant from the Cloud Device Groups node and navigate to
another configuration option in Panorama, returning to the Resources node
retains the tenant view you previously selected. For example, selecting a single
tenant in a region displays the cloud device groups configured for that tenant.
When you navigate to another area in the Panorama console, then return to Cloud
NGFW > Cloud Device Groups, the console displays the single tenant you
previously selected. For example, after displaying the cloud device groups for a
tenant, select AWS > Setup.
When you return to the Cloud NGFW > Resources screen, the Panorama console
remembers the previously selected tenant rather than displaying all the tenants
associated with the Cloud NGFW resource.
Refresh the browser to dynamically update the
display.
Panorama integration displays only those configuration options available to the Cloud
NGFW resource. For example, to display policy options available to the Cloud NGFW
resource, select Policies. The Panorama console only displays policies
available to the Cloud NGFW cloud device group.
The device group name is prefixed with
cngfw-aws.
To display device group objects supported by the Cloud NGFW resource, select
Objects. Only those objects supported by Cloud NGFW appear in the
Panorama console.
To display templates supported by the Cloud NGFW resource, select Network.
Only those cloud templates supported by the Cloud NGFW appear.
Rulestack considerations
When you provision a Cloud NGFW resource with a local rulestack, you cannot associate
it with a cloud device group in Panorama; the firewall appears greyed out in the
Panorama console. To resolve this issue, you can disassociate the local rulestack
using the Cloud NGFW console, or, you can provision a new firewall resource without
a local rulestack and associate it with a cloud device group in Panorama.
Alternately, use a global rulestack.
For firewalls created using the
AWS Firewall Manager Service (FMS), the
rulestack cannot be deselected in the Panorama console. Select a Panorama pushed
global rulestack from the FMS console. This process removes the associated rulestack
and updates the firewall with a Panorama pushed global rulestack. For more
information see the AWS FMS
documentation.
Add Cloud Device Group
With Panorama, you group firewalls in your network into logical units called
device groups. A device group enables grouping based on
network segmentation, geographic location, organizational function, or any other
common aspect of firewalls requiring similar policy configurations.
Using device groups, you can configure policy rules and the objects they reference.
Organize device groups hierarchically, with shared rules and objects at the top, and
device group-specific rules and objects at subsequent levels. This enables you to
create a hierarchy of rules that enforce how firewalls handle traffic.
To add a cloud device group using the Panorama console: