Migrate to Device Context Segments
Focus
Focus
Device Security

Migrate to Device Context Segments

Table of Contents

Migrate to Device Context Segments

Move your Device Security-managed network segments to Panorama so that Panorama owns the segment definitions and firewall or virtual system assignments that Advanced Device-ID uses for device context scoping.
Where Can I Use This?What Do I Need?
  • Device Security (Managed by Strata Cloud Manager)
  • (Legacy) IoT Security (Standalone portal)
One of the following subscriptions:
  • Device Security subscription
  • Precision AI bundle subscription
  • Device Security X subscription
To use device context segments, your firewalls must run PAN-OS 12.2 or later. You can create device context segments directly on a firewall. However, if you have firewalls in cluster mode, then you must manage their device context segments through Panorama.
Migrate to PAN-OS device context segments when you want your existing network segments to have both firewall and vsys scoping for device identification and policy enforcement. Migration is per-tenant and moves segment ownership from Device Security to PAN-OS.
If you already use Device Security network segments, you can migrate them to PAN-OS device context segments to gain vsys granularity. Migration is a one-time, per-tenant action that you initiate from Device Security. After you migrate, PAN-OS owns segment definitions for the migrated segments, and Device Security displays them in read-only mode. You must manage device context segments and their firewall and vsys assignments through PAN-OS or Panorama. You can't reverse the migration, so review your device context segment plan before you start.
After migration, define your device context segments and assign firewalls or virtual systems in PAN-OS. For device context segment configuration on the firewall, refer to Configure Device Context Segments in the Device-ID documentation.
  1. In Device Security, select NetworksNetwork Segments.
  2. Review the existing network segments and the firewalls assigned to each one so that you can recreate the equivalent assignments on your firewalls.
  3. Initiate the migration to device context segments and confirm when Device Security prompts you.
    After you confirm, existing segments appear as Panorama-managed on the Network Segments page, and any new device context segments must be added through your firewall. You can still create network segments in Device Security.
  4. Choose whether to preserve or clean up the devices that Device Security already learned from the affected firewalls in the migrated segments.
    If a firewall is removed from a segment during your migration configuration, Device Security prompts you to clean up the segment. If you clean up the data, then Device Security relearns devices when it sees the device traffic under the new segment assignments. If you don't clean up the segment, then Device Security preserves the devices previously learned by the segment and continues to display them in the Assets Inventory. Select View Detail and confirm the Cleanup Network Segment dialog to remove devices previously discovered by the reassigned firewalls.