| Where Can I Use This? | What Do I Need? |
|
|
One of the following subscriptions:
Device Security subscription
Precision AI bundle subscription
Device Security X subscription
|
To use device context segments, your firewalls must run
PAN-OS 12.2 or later. You can create device context segments
directly on a firewall. However, if you have firewalls in cluster mode, then
you must manage their device context segments through Panorama.
Migrate to PAN-OS device context segments when you want your
existing network segments to have both firewall and vsys scoping for
device identification and policy enforcement. Migration is
per-tenant and moves segment ownership from Device Security to
PAN-OS.
If you already use Device Security network segments, you can migrate
them to PAN-OS device context segments to gain vsys granularity.
Migration is a one-time, per-tenant action that you initiate from Device Security.
After you migrate, PAN-OS owns segment definitions for the migrated segments, and
Device Security displays them in read-only mode. You must manage
device context segments and their firewall and vsys assignments through
PAN-OS or Panorama. You can't reverse the migration, so review your
device context segment plan before you start.
After migration, define your device context segments and assign firewalls or
virtual systems in PAN-OS. For device context segment configuration
on the firewall, refer to Configure Device Context Segments in the
Device-ID documentation.