Use a device onboarding rule to automate parts of the Palo Alto Networks Next
Generation Firewall (NGFW) onboarding to Strata Cloud Manager whether you're
manually onboarding Palo Alto Networks NGFW or onboarding using Zero Touch
Provisioning (ZTP). This allows you to associate the firewall with a folder and
push a configuration when the firewall first connects to Strata Cloud Manager.
Device onboarding rules are designed to simplify and greatly reduce the time
spent onboarding new Palo Alto Networks NGFW at scale and ensure the correct
configuration is applied to newly onboarded Palo Alto Networks NGFW. You can
create multiple device onboarding rules to define different match criteria that
apply to different Palo Alto Networks NGFW.
The Match Criteria, Action,
VPN Onboarding, and User Context
Onboarding configurations are optional and can be configured as
needed. If no Match Criteria is specified then the device
onboarding rule applies to Any Palo Alto Networks NGFW
model and serial number. The Palo Alto Networks NGFW must match all
Match Criteria defined in the rule for Strata Cloud Manager to take the configured Action or
push the VPN Onboarding and User Context
Onboarding configurations.
For example, you don't configure the Match Criteria and
configure only the Target Folder in the rule
Action. Additionally, you don't configure
VPN Onboarding and User Context
Onboarding. In this example Strata Cloud Manager applies the
rule to all Palo Alto Networks NGFW onboarded to Strata Cloud Manager and only
adds them to the Target Folder. Another example is that
you specify Palo Alto Networks NGFW models and serial numbers in the
Match Criteria but you don't configure the rule
Action at all. Additionally, you configure
VPN Onboarding and User Context
Onboarding. In this example Strata Cloud Manager pushes the
VPN Onboarding and User Context
Onboarding configurations to only the Palo Alto Networks NGFW
models and serial numbers that match the Match
Criteria.