Next-Generation Firewall
Configure Interfaces and Zones (SCM)
Table of Contents
Expand All
|
Collapse All
Next-Generation Firewall Docs
-
-
-
-
-
-
-
- PAN-OS 12.1
- PAN-OS 11.2
- PAN-OS 11.1
- PAN-OS 11.0 (EoL)
- PAN-OS 10.2
- PAN-OS 10.1
- PAN-OS 10.0 (EoL)
- PAN-OS 9.1 (EoL)
- PAN-OS 9.0 (EoL)
- PAN-OS 8.1 (EoL)
-
- PAN-OS 12.1
- PAN-OS 11.2
- PAN-OS 11.1
- PAN-OS 10.2
- PAN-OS 10.1
Configure Interfaces and Zones (SCM)
Configure interfaces and zones on your NGFW to segment your network in Strata Cloud
Manager.
Create an Interface
Interfaces serve as the fundamental building blocks of your firewall's network
connectivity, defining how traffic enters, exits, and flows through your
security infrastructure. In Strata Cloud Manager, you can create and configure
various types of interfaces to match your specific network architecture and
deployment requirements, whether you're implementing network segmentation,
connecting to different network zones, or establishing connectivity between
network segments. Each interface type serves distinct purposes and operates at
different layers of the network stack, from simple traffic monitoring and
forwarding to complex routing and switching functions.
The interface configuration determines how the firewall processes traffic,
applies security policies, and integrates with your existing network
infrastructure. Choose the appropriate interface type based on your network
topology, traffic flow requirements, and the level of packet inspection and
processing needed for your deployment:
- Routing and Interfaces
- Configure a Layer 2 Interface
- Configure a Layer 2 Interface
Create a Zone
Assign one or more firewall interfaces to a zone to segment your network to
control protection for each zone individually.
- Log in to Strata Cloud Manager.Configure your NGFW interfaces.Select ManageConfigurationNGFW and Prisma AccessDevice SettingsInterfaces and select the Configuration Scope where you want to create the zone.You can select a folder or firewall from your Folders or select Snippets to configure the zone in a snippet.Add Zone.Configure the zone.
- Select the Interface Type.Select Layer2 if you want to add Layer 2 interfaces to the zone or Layer 3 to add Layer 3 interfaces.Add one or more interfaces to the zone.(Optional) Select a Zone Protection Profile to specify how the firewall responds to attack from this zone.Select Create New to create a new Zone Protection Profile inline.(Optional) Confirm you want to Enable Packet Buffer Protection.This setting is enabled by default. The firewall applies Packet Buffer Protection to the ingress zone only to protect the zone from DoS attacks and aggressive sessions and sources.(Optional) Enable User ID ACL.This setting is disabled by default. When disabled, the firewall applies user mapping information it discovers to all traffic of this zone for use in logs, reports, and policy rules. When enabled, the firewall(Optional) Enable Device ID ACL.This setting is disabled by default.Save.