ACE requires a
SaaS Security Inline subscription. Each
appliance that uses ACE must have a valid device certificate installed.
All
hardware platforms that support PAN-OS 10.1 or later support ACE
and all appliances on which you want to use ACE require PAN-OS 10.1
or later. Panorama cannot push and commit ACE-based polices or objects
to firewalls that don’t have a SaaS Security Inline license installed
or to firewalls that run an earlier version of PAN-OS than 10.1.
ACE is supported in the US, APAC, and EU GCP regions. The region is selected automatically based
on your Strata Logging Service region.
Verify that
the firewall uses the correct Content Cloud FQDN () for
your region and change the FQDN if necessary:
US—hawkeye.services-edge.paloaltonetworks.com
EU—eu.hawkeye.services-edge.paloaltonetworks.com
APAC—apac.hawkeye.services-edge.paloaltonetworks.com
ACE
data, including traffic payloads, is sent to the servers in the
selected region. If you specify a Content Cloud FQDN that is outside
of your region (for example, if you are in the EU region but you
specify the APAC region FQDN), you may break your country’s or your
organization’s privacy and legal regulations.