Failover and Resiliency
Focus
Focus
Enterprise DLP

Failover and Resiliency

Table of Contents

Failover and Resiliency

Learn about automatic regional failover for Enterprise Data Loss Prevention (E-DLP).
Where Can I Use This?What Do I Need?
  • NGFW (Managed by Panorama or Strata Cloud Manager)
  • Prisma Access (Managed by Panorama or Strata Cloud Manager)
  • Prisma Browser
  • Enterprise Data Loss Prevention (E-DLP) license
    Review the Supported Platforms for details on the required license for each enforcement point.
Or any of the following licenses that include the Enterprise DLP license
  • Prisma Access CASB license
  • Next-Generation CASB for Prisma Access and NGFW (CASB-X) license
  • Data Security license
Enterprise Data Loss Prevention (E-DLP) provides automatic failover between cloud regions so that traffic inspection and enforcement continue without interruption when a regional cloud infrastructure failure occurs.
Enterprise DLP continuously monitors the health and performance of its dependent services. When it detects a local failure, Palo Alto Networks automatically reroutes your traffic to a healthy secondary region within 180 seconds. Palo Alto Networks handles the failover entirely, requiring no action from your IT team. If no healthy secondary region is available, the enforcement point takes the Action When Scanning Error Occurred configured in your Enterprise DLP data filtering setting. Palo Alto Networks restores your Enterprise DLP tenant back to its primary region after service is restored.
Enterprise DLP supports regional failover in the following geographic areas. Palo Alto Networks maps all secondary regions to stay within the country's geographic boundaries to comply with country-specific data residency requirements if they exist.
  • United States
If your Enterprise DLP service experiences a disruption, the Strata Cloud Manager Incidents dashboard displays information about the incident and the action taken.