Configure NGFW Connector Integration Strata Cloud Manager
Focus
Prisma Access

Configure NGFW Connector Integration Strata Cloud Manager

Table of Contents


Configure NGFW Connector Integration Strata Cloud Manager

Configure your NGFWs as ZTNA Connectors in Strata Cloud Manager by registering them to your tenant, configuring network settings, and creating the NGFW Connector.
Before you begin, ensure the following are in place:
  • PAN-OS® version 12.1.5 and later
  • Prisma Access version 6.2 and later
  • Strata Cloud Manager license and AIOps for NGFW license activated on the tenant
  • LAN interface configured on the NGFW for local network connectivity
When your NGFWs are managed by Strata Cloud Manager, NGFWs in the same tenant are automatically discovered as available NGFW Connectors — no Cloud Services Plugin (CSP) installation, TSG ID, or service account configuration is required. Complete the network prerequisites in Strata Cloud Manager before creating the NGFW Connector.
A tenant can manage NGFW Connectors using either Strata Cloud Manager or Panorama — not both simultaneously. If your tenant already has Panorama-managed NGFW Connectors, Strata Cloud Manager-managed NGFW Connector onboarding will fail, and vice versa.
  1. Verify that an NGFW license is activated on your Strata Cloud Manager tenant.
    Your tenant requires one of the following licenses: AIOps for NGFW, Strata Cloud Manager Pro, or an equivalent NGFW SKU. To confirm the license is active, navigate to the NGFW section in Strata Cloud Manager, if All Firewalls is visible, the license is activated.
  2. Register your NGFW with the Strata Cloud Manager tenant and move it to cloud management.
    1. Ensure your NGFW has a valid Device Certificate from the Palo Alto Networks support portal.
    2. In the Palo Alto Networks Hub, go to Device Associations, select Add Device, and associate your NGFW by serial number with your tenant.
      Once associated, the device appears under Available Devices in Strata Cloud Manager.
    3. In Strata Cloud Manager, select SettingsDevice ManagementAvailable Devices, select your NGFW, and choose Move to Cloud Management.
  3. On the NGFW, set the management mode to Cloud Service and commit the changes. Verify that the cloud management status on the NGFW shows Connected before proceeding.
  4. Verify that the NGFW is using default routing mode.
    Advanced routing isn't supported for NGFW Connector. In Strata Cloud Manager, select the NGFW's Virtual Router, if the router shows Legacy, default routing is active. If it shows Advanced, disable advanced routing on the NGFW and reboot it before proceeding.
  5. In Strata Cloud Manager, create a folder for your NGFW devices and add your device to it.
    1. Go to System SettingsFolder ManagementAdd Folder.
    2. Add a Name, Description, Labels, and select which firewalls you want to associate with. Select Create to create a folder, and move your NGFW device into it.
    Strata Cloud Manager uses snippets to group NGFW Connector-related configuration separately from your existing folder configuration. Snippets are automatically created and attached to the folder when you onboard an NGFW Connector, you don't configure them directly.
  6. Configure the WAN and local interface variables for your NGFW.
    1. At the folder level, assign the WAN interface variable to the appropriate physical interface (for example, ethernet1/1).
      Strata Cloud Manager uses object variables for interface assignment, you cannot assign a physical interface directly. Default variables for WAN and local interfaces are available, or you can create custom variables.
    2. At the device level, set the specific values for each variable, including the WAN IP address and local interface IP address.
  7. Configure a Virtual Router with a default route for internet connectivity.
    1. In Strata Cloud Manager, go to NetworkVirtual Routers and create a new Virtual Router or select an existing one.
    2. Add the WAN and local interfaces to the Virtual Router.
    3. Under Static Routes, add a default route through the WAN interface for internet connectivity.
  8. Assign the WAN and local interfaces to security zones.
    In Strata Cloud Manager, go to NetworkZones. Default zones are available — assign the WAN interface to the internet or untrust zone and the local interface to the trust or local zone. You can also create new zones.
  9. Commit and Push the network configuration to the NGFW.
    This commits the folder, interface, virtual router, and zone configuration from the preceding steps. Review the changes before committing to avoid unintended modifications to your environment. After you create the NGFW Connector in the next phase, Strata Cloud Manager automatically pushes the connector configuration to your NGFW.