Install the Enterprise DLP Plugin on Panorama for FedRAMP
Focus
Focus
Enterprise DLP

Install the Enterprise DLP Plugin on Panorama for FedRAMP

Table of Contents


Install the Enterprise DLP Plugin on Panorama for FedRAMP

Install the Enterprise Data Loss Prevention (E-DLP) plugin on your Panorama® management server in a FedRAMP environment.
FedRAMP is supported on the following Enterprise DLP plugin versions:
  • 3.0.11 and later 3.0 releases
  • 5.0.9 and later 5.0 releases
  • 6.0.3 and later releases
  1. Activate the Enterprise DLP License.
    You must activate the Enterprise DLP license and associate it with your Panorama and managed devices before you install the Enterprise DLP plugin. This ensures the plugin correctly maps to your TSG and prevents synchronization issues.
  2. Review the Compatibility Matrix to verify the Enterprise DLP plugin version is supported on the PAN-OS version running on Panorama.
  3. Verify that Panorama and your managed devices belong to the same tenant service group (TSG) using Device Associations in Strata Cloud Manager.
    Panorama and any managed devices must belong to the same TSG to synchronize Enterprise DLP data profiles with Strata Cloud Manager and maintain consistent Security policy rule enforcement. If Panorama isn't already associated with the TSG, use Device Associations to add it before you install the plugin.
  4. Add your managed devices to a device group and template stack.
    Device groups and template stacks are required to manage device configurations and push Enterprise DLP configuration changes.
    Skip this step if you already added your managed devices to a device group and template stack.
  5. Install device certificates on Panorama and your managed devices.
    1. Install the Panorama Device Certificate.
      (High Availability) If Panorama is in an active/passive high availability (HA) configuration, install the Panorama device certificate on both HA peers.
    2. Install the Device Certificate for Managed Devices.
      The device certificate is required for all managed devices using Enterprise DLP.
  6. Install the plugin on Panorama.
    1. Log in to the Panorama web interface.
    2. Select PanoramaPlugins and search for the latest version of the Enterprise DLP plugin.
    3. Download the Enterprise DLP plugin.
    4. (HA only) Check (enable) Sync to HA peer to install the Enterprise DLP on the Panorama peer.
      Both HA peers must have the plugin installed. Installing it on only one peer can cause configuration push errors and suspend the active peer.
    5. Install the Enterprise DLP plugin on Panorama.
      Repeat this step on both Panorama HA peers.
  7. Log in to the Panorama CLI and set up the Enterprise DLP plugin.
    1. Set the Enterprise DLP plugin cloud mode.
      Setting the cloud mode automatically configures the correct Public Cloud Server FQDN for your FedRAMP environment.
      request plugins dlp set-cloud-mode mode <mode>
      Replace <mode> with the value that matches your FedRAMP environment:
      • gov-mod — FedRAMP Moderate
      • gov-high — FedRAMP High
    2. Reset the Enterprise DLP plugin using either of these commands.
      The plugin uses the default Commercial mode on installation. Reset it to ensure the plugin successfully connects successfully connect to and synchronize with Enterprise DLP.
      • request plugins reset-plugin only plugin plugin-name dlp
      • request plugins reset-plugin plugin-name dlp
  8. Commit and push the new configuration to your managed devices to complete the Enterprise DLP plugin installation.
    The Commit and Push command isn't recommended for Enterprise DLP configuration changes. Using the Commit and Push command requires the additional and unnecessary overhead of manually selecting the impacted templates and managed devices in the Push Scope Selection.
    • Full configuration push from Panorama
      1. Select CommitCommit to Panorama and Commit.
      2. Select CommitPush to Devices and Edit Selections.
      3. Select Device Groups and Include Device and Network Templates.
      4. Click OK.
      5. Push your configuration changes to your managed devices that are using Enterprise DLP.
    • Partial configuration push from Panorama
      You must always include the temporary __dlp administrator when performing a partial configuration push. This is required to keep Panorama and Strata Cloud Manager in sync.
      For example, if admin is logged in and making changes, they must select both admin and __dlp in the partial commit and push.
      1. Select CommitCommit to Panorama.
      2. Select Commit Changes Made By and then click the current Panorama admin user to select additional admins to include in the partial commit.
        Select your logged-in admin user, the __dlp user, and any other admins whose changes to include. Click OK to continue.
      3. Commit.
      4. Select CommitPush to Devices.
      5. Select Push Changes Made By and then click the current Panorama admin user to select additional admins to include in the partial push.
        Select your logged-in admin user, the __dlp user, and any other admins whose changes to include. Click OK to continue.
      6. Select Device Groups and Include Device and Network Templates.
      7. Click OK.
      8. Push your configuration changes to your managed devices that are using Enterprise DLP.
  9. Activate your Enterprise DLP license for your managed devices.
    Repeat this step for all managed devices using Enterprise DLP.
    1. Log in to the Palo Alto Networks Customer Support Portal.
    2. Select AssetsLicenses & Subscriptions and locate the managed device for which you want to activate Enterprise DLP.
    3. In the Actions column, click Licenses & Subscriptions.
    4. Click Activate License at the bottom of the page.
    5. Select Activate License from the list of Activation Types.
    6. In the Activate Auth-Code field, enter the auth code provided by Palo Alto Networks.
    7. Agree and Submit.
  10. (Optional) Create a Palo Alto Networks Support ticket to enable your Enterprise DLP license to transfer between NGFW.
    In the support ticket, include the following information:
    • The request for a firewall transfer for the Enterprise DLP license.
    • Your CSP account ID and the email associated with your CSP account.
    • The managed device serial number. If you activated the Enterprise DLP license on multiple managed devices, include the serial numbers for all the managed devices in a single support ticket.
    • The auth codes used to activate the Enterprise DLP license on your managed devices.
    • The CSP account ID associated with any managed devices that belong to a different CSP account.
  11. Verify that you successfully activated Enterprise DLP.
    1. On Panorama, select ObjectsDLP to confirm that the Data Filtering Patterns and Data Filtering Profiles automatically populate with the predefined data patterns and profiles.
    2. On the firewall web interface, select DeviceLicenses and verify that Enterprise DLP successfully activated.
  12. Review the Setup Prerequisites and allow the required ports and FQDNs for your FedRAMP environment on your network.
  13. Review the supported features for your FedRAMP environment.
  14. After you successfully install the Enterprise DLP plugin on Panorama, you must create Security policy rules to enable managed devices to use Enterprise DLP.