Device Onboarding Rules
Onboarding rules allow you to add a firewall to a folder and apply predefined
configurations when a Palo Alto Networks Next-Generation Firewall (NGFW) first connects to
Strata Cloud Manager.
Use a
device onboarding rule to automate parts of the Palo
Alto Networks NGFW onboarding to Strata Cloud Manager whether you are manually
onboarding Palo Alto Networks NGFW or onboarding using Zero Touch Provisioning
(ZTP). This allows you to associate the firewall with a folder and apply predefined
configuration when the firewall first connects to Strata Cloud Manager. You can
create multiple device onboarding rules to define different match criteria that
apply to different Palo Alto Networks NGFW. Device onboarding rules are designed to
simplify and greatly reduce the time spent onboarding new Palo Alto Networks NGFW at
scale and ensure the correct configuration is applied to newly onboarded Palo Alto
Networks NGFW.
Device onboarding rules use Match Criteria to define which
Palo Alto Networks NGFW the rule applies to. This includes information such as the
firewall Model and any Labels applied
to the firewall during the onboarding process. You can define the rule
Action to specify a Target Folder
one or more Palo Alto Networks NGFW are added to and the Snippet
Association define any firewall-specific snippet configurations that
need to be applied. Additionally, if you use SD-WAN or Cloud Identity Engine (CIE)
you can also define and apply those necessary configurations in the device
onboarding rule to ensure all required connectivity and user-based visibility and
policy enforcement immediately after onboarding.