Enterprise DLP
Enterprise DLP Plugin
Table of Contents
Enterprise DLP Plugin
Enterprise DLP
PluginInstall or uninstall the
Enterprise Data Loss Prevention (E-DLP)
plugin on your Panorama™ management server
.Where Can I Use This? | What Do I Need? |
---|---|
|
|
To install the
Enterprise Data Loss Prevention (E-DLP)
plugin on your Panorama™ management server
, you
must install the Panorama device certificate and device certificated for all
Next-Gen firewalls using Enterprise DLP
. Then, you must download the plugin
from the Palo Alto Networks Update Server and then install it. The Enterprise DLP
plugin needs to be installed only on Panorama
, and is installed by
default on all Next-Gen firewalls. Review the PAN-OS Upgrade Guide if you need to
upgrade the Enterprise DLP
plugin
version.To perform configuration changes on
Panorama
, the Enterprise DLP
plugin
creates a temporary __dlp
Panorama
admin regardless of the admin making the configuration changes.
The temporary __dlp
admin is only used by the Enterprise DLP
plugin for configuration changes and has no log in credentials.
The __dlp
admin cannot be used to log in to Panorama
and is not listed as a Panorama
administrator account. The
__dlp
admin has no access privileges beyond the Enterprise DLP
plugin. Your existing data patterns () and data filtering profiles () are automatically hidden after you successfully install the
Objects
Custom Objects
Data Patterns
Objects
Security Profiles
Data Filtering
Enterprise DLP
plugin on Panorama
. To display your existing data
patterns and filtering profiles when you need to reference them, you can
temporarily Enable Existing Data Patterns and Filtering Profiles.To uninstall the
Enterprise Data Loss Prevention (E-DLP)
plugin, you must remove all Enterprise DLP
data filtering profile references from all your Security policy
rules before you can uninstall the plugin from Panorama
.Install the Plugin
Install the
Enterprise Data Loss Prevention (E-DLP)
plugin on your Panorama™ management server
.- Review the Compatibility Matrix to verify theEnterprise DLPplugin version is supported on the PAN-OS version running onPanorama.
- (Best Practices) Before you install the plugin and activate yourEnterprise DLPlicense, selectto locateAssetsDevicesPanoramaand your managed firewalls to verify that they all belong to the same CSP account.Panoramaand any managed firewalls on which you want to useEnterprise DLPmust belong to the same CSP account, which enables you to share data profiles and maintain consistent Security policy rule enforcement.
- The device certificate is required for all managed firewalls usingEnterprise DLP.
- Install the plugin onPanorama.
- Log in to thePanoramaweb interface.
- Selectand search for the latest version of thePanoramaPluginsEnterprise DLPplugin.
- DownloadandInstalltheEnterprise DLPplugin onPanorama.
- Commit and push the new configuration to your managed firewalls to complete theEnterprise DLPplugin installation.This step is required forEnterprise DLPdata filtering profile names to appear in Data Filtering logs.TheCommit and Pushcommand isn’t recommended forEnterprise DLPconfiguration changes. Using theCommit and Pushcommand requires the additional and unnecessary overheard of manually selecting the impacted templates and managed firewalls in the Push Scope Selection.
- Full configuration push from Panorama
- SelectandCommitCommit toPanoramaCommit.
- SelectandCommitPush to DevicesEdit Selections.
- SelectDevice GroupsandInclude Device and Network Templates.
- ClickOK.
- Pushyour configuration changes to your managed firewalls that are usingEnterprise DLP.
- Partial configuration push from PanoramaYou must always include the temporary__dlpadministrator when performing a partial configuration push. This is required to keepPanoramaand the DLP cloud service in sync.For example, you have anadminPanoramaadmin user who is allowed to commit and push configuration changes. Theadminuser made changes to theEnterprise DLPconfiguration and only wants to commit and push these changes to managed firewalls. In this case, theadminuser is required to also select the__dlpuser in the partial commit and push operations.
- Select.CommitCommit toPanorama
- SelectCommit Changes Made Byand then click the current Panorama admin user to select additional admins to include in the partial commit.In this example, theadminuser is currently logged in and performing the commit operation. Theadminuser must clickadminand then select the__dlpuser. If there are additional configuration changes made by other Panorama admins they can be selected here as well.ClickOKto continue.
- Commit.
- Select.CommitPush to Devices
- SelectPush Changes Made Byand then click the current Panorama admin user to select additional admins to include in the partial push.In this example, theadminuser is currently logged in and performing the push operation. Theadminuser must clickadminand then select the__dlpuser. If there are additional configuration changes made by other Panorama admins they can be selected here as well.ClickOKto continue.
- SelectDevice GroupsandInclude Device and Network Templates.
- ClickOK.
- Pushyour configuration changes to your managed firewalls that are usingEnterprise DLP.
- Activate yourEnterprise DLPlicense for your managed firewalls.Repeat this step for all managed firewalls usingEnterprise DLP.
- Log in to the Palo Alto Networks Customer Support Portal.
- Selectand locate the managed firewall for which you want to activateAssetsLicenses & SubscriptionsEnterprise DLP
- In theActionscolumn, clickLicenses & Subscriptions.
- ClickActivate Licenseat the bottom of the page.
- SelectActivate Licensefrom the list of Activation Types.
- In theActivate Auth-Codefield, enter the auth code provided byPalo Alto Networks.
- Agree and Submit.
- Activate theEnterprise DLPtenant for your Customer Support (CSP) tenant.This is required to connect Panorama and managed firewalls to the DLP cloud service to forward traffic for verdict rendering and to allow synchronization between Panorama and the DLP cloud service.
- Select.Activate ProductsReady for Activation
- LocateEnterprise DLPfrom the list of applications ready for activation.
- Activate Now.
- (Optional) Create a Palo Alto Networks Support ticket to enable yourEnterprise DLPlicense to transfer between firewalls.Requesting that theEnterprise DLPlicense is transferable enables you to transfer your DLP license to other managed firewalls.In the support ticket, include the following information:
- The request for a firewall transfer for theEnterprise DLPlicense.
- Your CSP account ID and the email associated with your CSP account.
- The managed firewall serial number. If you activated theEnterprise DLPlicense on multiple managed firewalls, include the serial numbers for all the managed firewalls in a single support ticket.
- The auth codes used to activate theEnterprise DLPlicense on your managed firewalls.
- Also provide the CSP account ID with which additional managed firewalls are associated if you have managed firewalls that belong to a different CSP account.
- Activate theEnterprise DLPplugin on your managed firewalls.
- SelectandPanoramaDevice DeploymentLicenseActivatetheEnterprise DLPplugin.
- Enter theAuth Codefor the target managed firewalls.The auth code is automatically provided to you by Palo Alto Networks in an email after you complete your purchase of theEnterprise DLPplugin license.
- ActivatetheEnterprise DLPplugin license on your managed firewalls.
- Selectand verify that the predefined data filtering profiles are displayed.ObjectsDLPData Filtering ProfilesPanoramais automatically populated with predefined data filtering profiles whenPanoramasuccessfully connects to the DLP cloud service.
- Verify that theEnterprise DLPlicense is successfully activated on your managed firewalls.
- Selectand verify that the license is successfully activated.DeviceLicenses
- After you successfully install theEnterprise DLPplugin onPanorama, you must create Security policy rules to enable your managed firewalls to leverageEnterprise DLP.
Uninstall the Plugin
Uninstall the
Enterprise Data Loss Prevention (E-DLP)
plugin from your Panorama™ management server
.- Log in to thePanoramaweb interface.
- Selectand remove allPoliciesSecurityEnterprise DLPdata filtering profiles from your Security policy rules.This step is required to successfully uninstall theEnterprise DLPplugin.
- Commit and push your configuration changes to your managed firewalls usingEnterprise DLP.TheCommit and Pushcommand isn’t recommended forEnterprise DLPconfiguration changes. Using theCommit and Pushcommand requires the additional and unnecessary overheard of manually selecting the impacted templates and managed firewalls in the Push Scope Selection.
- SelectandCommitCommit to PanoramaCommit.
- SelectandCommitPush to DevicesEdit Selections.
- SelectDevice GroupsandInclude Device and Network Templates.
- ClickOK.
- Pushyour configuration changes to your managed firewalls that are usingEnterprise DLP.
- Commit and push the new configuration to your managed firewalls to uninstall theEnterprise DLPplugin.TheCommit and Pushcommand isn’t recommended forEnterprise DLPconfiguration changes. Using theCommit and Pushcommand requires the additional and unnecessary overheard of manually selecting the impacted templates and managed firewalls in the Push Scope Selection.
- Full configuration push from Panorama
- SelectandCommitCommit toPanoramaCommit.
- SelectandCommitPush to DevicesEdit Selections.
- SelectDevice GroupsandInclude Device and Network Templates.
- ClickOK.
- Pushyour configuration changes to your managed firewalls that are usingEnterprise DLP.
- Partial configuration push from PanoramaYou must always include the temporary__dlpadministrator when performing a partial configuration push. This is required to keepPanoramaand the DLP cloud service in sync.For example, you have anadminPanoramaadmin user who is allowed to commit and push configuration changes. Theadminuser made changes to theEnterprise DLPconfiguration and only wants to commit and push these changes to managed firewalls. In this case, theadminuser is required to also select the__dlpuser in the partial commit and push operations.
- Select.CommitCommit toPanorama
- SelectCommit Changes Made Byand then click the current Panorama admin user to select additional admins to include in the partial commit.In this example, theadminuser is currently logged in and performing the commit operation. Theadminuser must clickadminand then select the__dlpuser. If there are additional configuration changes made by other Panorama admins they can be selected here as well.ClickOKto continue.
- Commit.
- Select.CommitPush to Devices
- SelectPush Changes Made Byand then click the current Panorama admin user to select additional admins to include in the partial push.In this example, theadminuser is currently logged in and performing the push operation. Theadminuser must clickadminand then select the__dlpuser. If there are additional configuration changes made by other Panorama admins they can be selected here as well.ClickOKto continue.
- SelectDevice GroupsandInclude Device and Network Templates.
- ClickOK.
- Pushyour configuration changes to your managed firewalls that are usingEnterprise DLP.