Enable Advanced Forwarding to establish high-performance TLS connections directly
from the data plane (DP) to advanced service addresses for inline cloud
analysis.
Advanced Forwarding (PAN-OS 12.2.2 and later) replaces the legacy transport with a
scalable connection pool that distributes cloud analysis submissions across all
available data plane cores. Each connection is established directly from the data
plane over TLS, replacing the intermediate process that previously serialized all
cloud submissions through a limited, platform-dependent number of cores. This
improves throughput and reduces latency for inline cloud analysis services including
Enterprise DLP, Advanced Threat Prevention, Advanced URL Filtering, Advanced
WildFire, Prisma AIRS (AI Runtime Security), ACE (App-ID Cloud Engine) when used
alongside SaaS Security Inline, and AI Access Security.
When you enable Advanced Forwarding, a newly introduced discovery service dynamically
assigns advanced service addresses based on the NGFW's geographic location.
Advanced Forwarding and the legacy transport are
mutually exclusive. To revert to the legacy transport method, you must manually
disable Advanced Forwarding. The NGFW does not automatically switch between
transport modes.
PAN-OS Upgrade Considerations
Advanced Forwarding is available starting in PAN-OS 12.2.2. When upgrading from a
pre-12.2.2 release, Advanced Forwarding is disabled by default and must be explicitly
enabled after the upgrade.
- Advanced Forwarding is disabled by default on NGFWs that are upgraded to
PAN-OS 12.2.2 to avoid breaking existing functionality or causing a change
in behavior. However, new platforms (or future platform releases) that
support a minimum PAN-OS release of 12.2.2 have Advanced Forwarding
automatically enabled.
- When managing a mix of upgraded firewalls and new-platform firewalls under
the same Panorama template, be aware that the local default for Advanced
Forwarding differs between these platforms (including VM-Series base images
with PAN-OS 12.2.2 and later). If the template does not explicitly configure
the Advanced Forwarding setting, upgraded firewalls default to disabled while
new platforms default to enabled. To ensure consistent behavior across your
managed firewalls, explicitly set the Advanced Forwarding state in the
template.
Requirements and Recommendations
(
Required)
Add a security policy rule for Advanced Forwarding
service—When Advanced Forwarding uses the management interface for
cloud connectivity (the default),
create a security policy rule that
allows traffic from the reserved source address range (127.140.0.0/16) to
the cloud service destination.
(Required) Allow Advanced Forwarding App-IDs—In the security
policy rule you created for Advanced Forwarding traffic, specify the
following App-IDs as application match criteria. Advanced Forwarding service
connections are evaluated against the security policy rulebase:
If you have restrictive outbound policies, ensure these App-IDs are
explicitly permitted:
(
Recommended)
Configure a service route for best
performance—For best throughput, configure a service route for Advanced
Forwarding instead of using the management interface. A service route
enables the connections to egress through a data plane interface, leveraging
the data plane's parallel processing capabilities. Ensure a rule permits the
Advanced Forwarding application traffic on the configured interface. When
using a service route,
create a rule that allows traffic
on the service route interface.