Enable Advanced Forwarding
Focus
Focus
Enterprise DLP

Enable Advanced Forwarding

Table of Contents

Enable Advanced Forwarding

Enable Advanced Forwarding to establish high-performance TLS connections directly from the data plane (DP) to advanced service addresses for inline cloud analysis.
Where Can I Use This?What Do I Need?
  • NGFW (Managed by PAN-OS or Panorama)
  • PAN-OS 12.2.2 and later
  • One or more inline cloud analysis service licenses:
    • Advanced Threat Prevention
    • Advanced URL Filtering
    • Advanced WildFire
    • Enterprise DLP
    • SaaS Security Inline
    • AI Access Security
Advanced Forwarding (PAN-OS 12.2.2 and later) replaces the legacy transport with a scalable connection pool that distributes cloud analysis submissions across all available data plane cores. Each connection is established directly from the data plane over TLS, replacing the intermediate process that previously serialized all cloud submissions through a limited, platform-dependent number of cores. This improves throughput and reduces latency for inline cloud analysis services including Enterprise DLP, Advanced Threat Prevention, Advanced URL Filtering, Advanced WildFire, Prisma AIRS (AI Runtime Security), ACE (App-ID Cloud Engine) when used alongside SaaS Security Inline, and AI Access Security.
When you enable Advanced Forwarding, a newly introduced discovery service dynamically assigns advanced service addresses based on the NGFW's geographic location.
Advanced Forwarding and the legacy transport are mutually exclusive. To revert to the legacy transport method, you must manually disable Advanced Forwarding. The NGFW does not automatically switch between transport modes.
PAN-OS Upgrade Considerations
Advanced Forwarding is available starting in PAN-OS 12.2.2. When upgrading from a pre-12.2.2 release, Advanced Forwarding is disabled by default and must be explicitly enabled after the upgrade.
  • Advanced Forwarding is disabled by default on NGFWs that are upgraded to PAN-OS 12.2.2 to avoid breaking existing functionality or causing a change in behavior. However, new platforms (or future platform releases) that support a minimum PAN-OS release of 12.2.2 have Advanced Forwarding automatically enabled.
  • When managing a mix of upgraded firewalls and new-platform firewalls under the same Panorama template, be aware that the local default for Advanced Forwarding differs between these platforms (including VM-Series base images with PAN-OS 12.2.2 and later). If the template does not explicitly configure the Advanced Forwarding setting, upgraded firewalls default to disabled while new platforms default to enabled. To ensure consistent behavior across your managed firewalls, explicitly set the Advanced Forwarding state in the template.
Requirements and Recommendations
  • (Required) Install a device certificate—The NGFW requires a valid device certificate to authenticate with the Advanced Forwarding cloud services. You can install the device certificate directly on the firewall or use Panorama to install it on managed firewalls.
  • (Required) Add a security policy rule for Advanced Forwarding service—When Advanced Forwarding uses the management interface for cloud connectivity (the default), create a security policy rule with the following match criteria:
    • Source Zone: any
    • Destination Zone: any
    • Source Address: 127.140.0.0/16
    • Destination Address: any
    • Service: application-default
    Both zones must be set to "any" because the reserved source address range does not belong to a configured zone.
  • (Required) Allow Advanced Forwarding App-IDs—In the security policy rule you created for Advanced Forwarding traffic, specify the following App-IDs as application match criteria. Advanced Forwarding service connections are evaluated against the security policy rulebase:
    • When using the management interface for cloud connectivity (default), create a security policy rule that allows traffic from the reserved source address range (127.140.0.0/16) to the cloud service destination.
    If you have restrictive outbound policies, ensure these App-IDs are explicitly permitted:
    • paloalto-pae-discovery-service
    • paloalto-pae-service
    • paloalto-chs-service
  • (Recommended) Configure a service route for best performance—For best throughput, configure a service route for Advanced Forwarding instead of using the management interface. A service route enables the connections to egress through a data plane interface, leveraging the data plane's parallel processing capabilities. Ensure a rule permits the Advanced Forwarding application traffic on the configured interface. When using a service route, create a rule that allows traffic on the service route interface.
    Advanced Forwarding components map to the following service route destinations:
    • paloalto-networks-services—Discovery service, Configuration Hub Service (reserved for future use)
    • data-services—Advanced Service health checks, Advanced Service TLS connections
    Configure service routes for both destinations under DeviceSetupServicesService Route Configuration. See Configure Service Routes.
  1. Navigate to the Content-ID settings.
    • NGFW—Select DeviceSetupContent-ID and edit the Content Cloud Settings.
    • Panorama—Select DeviceSetupContent-ID and select the Template associated with the managed firewalls that you want to enable Advanced Forwarding on.
  2. Enable Advanced Forwarding.
    Switching from the legacy transport mode to Advanced Forwarding causes a momentary disruption to the cloud connection. It is recommended to commit this change during a maintenance window.
  3. Configure the Advanced Forwarding settings.
    • Discovery Service Address—The address for the discovery service that dynamically assigns advanced service addresses to the NGFW based on its serial number, PAN-OS version, and geographic location (default: pae-discovery.hawkeye.services-edge.paloaltonetworks.com). By default, the discovery service address resolves to the closest regional IP address.
      Ensure the discovery service address is reachable from your network. If your network restricts outbound access, allow traffic to this address so the NGFW can query for its assigned advanced service addresses.
      • Discovery Service Address per Region
        • United States (Central)usc1.pae-discovery.hawkeye.services-edge.paloaltonetworks.com
        • United States (East)use4.pae-discovery.hawkeye.services-edge.paloaltonetworks.com
        • United States (West)usw1.pae-discovery.hawkeye.services-edge.paloaltonetworks.com
        • Canadaca.pae-discovery.hawkeye.services-edge.paloaltonetworks.com
        • Brazilbr.pae-discovery.hawkeye.services-edge.paloaltonetworks.com
        • Germanyde.pae-discovery.hawkeye.services-edge.paloaltonetworks.com
        • United Kingdomuk.pae-discovery.hawkeye.services-edge.paloaltonetworks.com
        • Netherlandsnl.pae-discovery.hawkeye.services-edge.paloaltonetworks.com
        • Switzerlandch.pae-discovery.hawkeye.services-edge.paloaltonetworks.com
        • Francefr.pae-discovery.hawkeye.services-edge.paloaltonetworks.com
        • Polandpl.pae-discovery.hawkeye.services-edge.paloaltonetworks.com
        • Spaines.pae-discovery.hawkeye.services-edge.paloaltonetworks.com
        • Italyit.pae-discovery.hawkeye.services-edge.paloaltonetworks.com
        • Israelil.pae-discovery.hawkeye.services-edge.paloaltonetworks.com
        • Qatarqa.pae-discovery.hawkeye.services-edge.paloaltonetworks.com
        • Saudi Arabiasa.pae-discovery.hawkeye.services-edge.paloaltonetworks.com
        • Singaporesg.pae-discovery.hawkeye.services-edge.paloaltonetworks.com
        • Japanjp.pae-discovery.hawkeye.services-edge.paloaltonetworks.com
        • Koreakr.pae-discovery.hawkeye.services-edge.paloaltonetworks.com
        • Taiwantw.pae-discovery.hawkeye.services-edge.paloaltonetworks.com
        • Indonesiaid.pae-discovery.hawkeye.services-edge.paloaltonetworks.com
        • Indiain.pae-discovery.hawkeye.services-edge.paloaltonetworks.com
        • Australiaau.pae-discovery.hawkeye.services-edge.paloaltonetworks.com
        • South Africaza.pae-discovery.hawkeye.services-edge.paloaltonetworks.com
    • Discovery Service Interval (seconds)—The interval, in seconds, between discovery service queries. The NGFW periodically queries the discovery service to refresh its assigned advanced service addresses (default is 14400 seconds).
    • Max Discovery Retry Count—The maximum number of times the NGFW retries a failed discovery service query.
      The NGFW retries failed discovery queries every 60 seconds up to the configured maximum retry count. Once exhausted, retries continue at 5 minute intervals until discovery is successful.
    • Enable Multi-FQDN Support—Enable the NGFW to use multiple advanced service address FQDNs simultaneously. When enabled, the discovery service can assign different FQDNs for different cloud analysis services, allowing the NGFW to distribute connections across multiple endpoints. Reserved for future use.
    • Override Discovered CHS Address—Enable this option to manually override the Config Hub Service (CHS) address assigned by the discovery service. When enabled, the NGFW uses the address specified in Config Hub Service (CHS) Address instead of the discovery-assigned endpoint. Reserved for future use.
    • Config Hub Service (CHS) Address—The address for the Config Hub Service (CHS) that the NGFW uses to store and retrieve configuration. Only configurable when Override Discovered CHS Address is enabled. Reserved for
      • CHS Address per Region
        The Configuration Hub Service is reserved for future use. These addresses are provided as a reference for proxy allowlist configuration.
        • United States (Central)usc1.chs.hawkeye.services-edge.paloaltonetworks.com
        • United States (East)use4.chs.hawkeye.services-edge.paloaltonetworks.com
        • United States (West)usw1.chs.hawkeye.services-edge.paloaltonetworks.com
        • Canadaca.chs.hawkeye.services-edge.paloaltonetworks.com
        • Brazilbr.chs.hawkeye.services-edge.paloaltonetworks.com
        • Germanyde.chs.hawkeye.services-edge.paloaltonetworks.com
        • United Kingdomuk.chs.hawkeye.services-edge.paloaltonetworks.com
        • Netherlandsnl.chs.hawkeye.services-edge.paloaltonetworks.com
        • Switzerlandch.chs.hawkeye.services-edge.paloaltonetworks.com
        • Francefr.chs.hawkeye.services-edge.paloaltonetworks.com
        • Polandpl.chs.hawkeye.services-edge.paloaltonetworks.com
        • Spaines.chs.hawkeye.services-edge.paloaltonetworks.com
        • Italyit.chs.hawkeye.services-edge.paloaltonetworks.com
        • Israelil.chs.hawkeye.services-edge.paloaltonetworks.com
        • Qatarqa.chs.hawkeye.services-edge.paloaltonetworks.com
        • Saudi Arabiasa.chs.hawkeye.services-edge.paloaltonetworks.com
        • Singaporesg.chs.hawkeye.services-edge.paloaltonetworks.com
        • Japanjp.chs.hawkeye.services-edge.paloaltonetworks.com
        • Koreakr.chs.hawkeye.services-edge.paloaltonetworks.com
        • Taiwantw.chs.hawkeye.services-edge.paloaltonetworks.com
        • Indonesiaid.chs.hawkeye.services-edge.paloaltonetworks.com
        • Indiain.chs.hawkeye.services-edge.paloaltonetworks.com
        • Australiaau.chs.hawkeye.services-edge.paloaltonetworks.com
        • South Africaza.chs.hawkeye.services-edge.paloaltonetworks.com
      future use.
    • Override Discovered Advanced Address—Enable this option to manually override the Advanced Forwarding service address assigned by the discovery service. When enabled, the NGFW uses the address specified in Advanced Service Address instead of the discovery-assigned endpoint.
    • Advanced Service Address—The address for the Advanced Forwarding service used for inline cloud analysis payload exchange. Only configurable when Override Discovered Advanced Address is enabled.
      Ensure the advanced service address assigned by the discovery service is reachable from your network. If your network restricts outbound access, allow traffic to this address.
      • Advanced Service Address per Region
        • United States (Central)usc1.pae.hawkeye.services-edge.paloaltonetworks.com
        • United States (East)use4.pae.hawkeye.services-edge.paloaltonetworks.com
        • United States (West)usw1.pae.hawkeye.services-edge.paloaltonetworks.com
        • Canadaca.pae.hawkeye.services-edge.paloaltonetworks.com
        • Brazilbr.pae.hawkeye.services-edge.paloaltonetworks.com
        • Germanyde.pae.hawkeye.services-edge.paloaltonetworks.com
        • United Kingdomuk.pae.hawkeye.services-edge.paloaltonetworks.com
        • Netherlandsnl.pae.hawkeye.services-edge.paloaltonetworks.com
        • Switzerlandch.pae.hawkeye.services-edge.paloaltonetworks.com
        • Francefr.pae.hawkeye.services-edge.paloaltonetworks.com
        • Polandpl.pae.hawkeye.services-edge.paloaltonetworks.com
        • Spaines.pae.hawkeye.services-edge.paloaltonetworks.com
        • Italyit.pae.hawkeye.services-edge.paloaltonetworks.com
        • Israelil.pae.hawkeye.services-edge.paloaltonetworks.com
        • Qatarqa.pae.hawkeye.services-edge.paloaltonetworks.com
        • Saudi Arabiasa.pae.hawkeye.services-edge.paloaltonetworks.com
        • Singaporesg.pae.hawkeye.services-edge.paloaltonetworks.com
        • Japanjp.pae.hawkeye.services-edge.paloaltonetworks.com
        • Koreakr.pae.hawkeye.services-edge.paloaltonetworks.com
        • Taiwantw.pae.hawkeye.services-edge.paloaltonetworks.com
        • Indonesiaid.pae.hawkeye.services-edge.paloaltonetworks.com
        • Indiain.pae.hawkeye.services-edge.paloaltonetworks.com
        • Australiaau.pae.hawkeye.services-edge.paloaltonetworks.com
        • South Africaza.pae.hawkeye.services-edge.paloaltonetworks.com
  4. Click OK.
  5. (Required for external proxy deployments only) If the firewall reaches the internet through an external proxy, configure the proxy server to forward Advanced Forwarding traffic.
    Select DeviceSetupServices and edit the Services details. Specify the Proxy Server settings and enable Enable proxy for Inline Cloud Services.
    Alternatively, enable the inline cloud proxy via CLI:
    set deviceconfig system inline-cloud-proxy yes
    All Advanced Forwarding components (discovery service, Advanced Service health checks, Configuration Hub Service (reserved for future use), and Advanced Service TLS connections) use this proxy setting.
  6. Commit the configuration.
  7. (Optional) Validate the Advanced Forwarding configuration through the CLI.
    Verify that the discovery service query completed successfully:
    admin@firewall> show paed discovery-status
    
    PAE Job Status:
    
     Recent Jobs:
      Service: pae
       Operation: Discovery
       Request ID: 9590
       Timestamp: Wed Jul 29 14:10:43 2026
       Status: Completed
       FQDN Used: pae-discovery.hawkeye.services-edge.paloaltonetworks.com
       IP Used: 192.0.2.10
       Request Length: 329 bytes
       Response Length: 584 bytes
       CURL Code: 0
       HTTP Code: 200
       SVC Status Code: Valid
    Verify the discovered Advanced Service and CHS FQDNs assigned to the NGFW:
    admin@firewall> show paed fqdns
    
    Current FQDNs:
    
     Service: pae
    
      FQDN s1dp0:
       Request ID: 9590
       Slot ID: 1
       DP ID: 0
       Service: pae
       Service Version: 1
       Subservice: pae-fqdns
       Update Time: Wed Jul 29 14:10:43 2026
       FQDN: usc1.pae.hawkeye.services-edge.paloaltonetworks.com
       Port: 443
       Inline Proxy: disabled
       IP Address: 198.51.100.25
       Protocol: v4
       FQDN Type: Dynamic
       Valid Start: Fri Jun 19 11:53:42 2026
       Valid End: Wed Jun 25 17:00:00 2036
       Region: us-central1
       Health Check:
        Pod Name: paesvc-api-744d65c7dc-hgh68
        Version: 1.0.0.0-2_aabac9591b
        Built on: 2026-07-23T10:32:32PDT
        Config mgmt: yes
        Backend: yes
        Status: yes
    
      CHS FQDN:
       Request ID: 9590
       Service: pae
       Service Version: 1
       Subservice: chs-fqdns
       Update Time: Wed Jul 29 14:10:43 2026
       FQDN: usc1.chs.hawkeye.services-edge.paloaltonetworks.com
       FQDN Type: Dynamic
       Valid Start: Mon Jun 29 22:48:45 2026
       Valid End: Sun Jul 6 17:00:00 2036
       Region: us-central1
    Verify that the data plane has established active connections to the advanced services:
    admin@firewall> debug dataplane pae show connections list active
    
    Active Connections:
     Total connections in list Active: 4
     ID: 12  State: ACTIVE
     ID: 14  State: ACTIVE
     ID: 13  State: ACTIVE
     ID: 3   State: ACTIVE
    The number of active connections depends on your hardware platform:
    • PA-3420—Minimum 1, up to 2 concurrent TLS connections
    • Other PA-34xx series—Minimum 2, up to 4 concurrent TLS connections
    • All other platforms—Minimum 4, up to 8 concurrent TLS connections
    If the output displays Advanced Forwarding is not enabled, verify that you enabled Advanced Forwarding and committed the configuration.