| Where Can I Use This? | What Do I Need? |
NGFW (Managed by PAN-OS or Panorama) Device Security (Managed by Strata Cloud Manager) (Legacy) IoT Security (Standalone portal)
|
One of the following subscriptions:
Device Security subscription for an advanced
Device Security product (Enterprise,
OT, or Medical)
Device Security X subscription
|
When you configure your next-generation firewall to obtain and log network traffic
metadata, you can use a data interface to access
Strata Logging Service
and
Device Security. To use a data interface, you need to configure
service routes
and
Security policy rules, and commit your
configuration changes once you are done.
By default, the firewall uses its management interface to send data logs to the
logging service, get recommended policy rule sets and IP address-to-device mappings
from Device Security, and download device dictionary files from the update
server. When a firewall uses its management interface for all this, a service route
and a Security policy rule are not needed.
However, when a firewall accesses the logging service, Device Security, and
update server through a data interface, then you must add a service route
identifying the source data interface, source interface IP address, and service
type. In addition, you must add an interzone Security policy rule permitting
Data Services from 127.168.0.0/16 to the destination zone where the logging service,
Device Security, and update server are.
When a firewall generates traffic that it sends through a data interface, it
uses an IP address in the 127.168.0.0/16 subnet as its internal source and then
translates it to the IP address of the source interface. Because
Security policy rules are applied to the original source IP address before NAT,
the source IP address must be 127.168.0.0/16 instead of the IP address of the
source interface.