Conref - Device Context Segments
Reusable content chunks for Device Context Segments documentation, shared between the
Advanced Device-ID book and the Device Security administration book.
Restrict Device Context Sharing
Each device context segment includes a
Restrict Device Context Sharing setting that controls
whether device context that Device Security learns outside of shared IP
address blocks is shared with other segments. By default, the setting is off and
Device Security sends non-shared IP address block device contexts to every segment
so that firewalls in one segment can enforce Device-ID policy on devices first seen
in another segment. When you enable Restrict Device Context Sharing on a segment,
that segment doesn't send non-shared IP address block device context from its
firewalls and vsys to other segments.
From Device Security, enable the restriction setting on device context segments
that correspond to distinct administrative or geographic boundaries where you want
to keep device visibility contained. The restriction setting has no effect on
devices in shared IP address blocks — those device contexts are always limited to
the segment where the device was learned.
Migrate to Panorama-Managed Device Context Segments
If you already use Device Security network segments, you can migrate
them to PAN-OS device context segments to gain vsys granularity.
Migration is a one-time, per-tenant action that you initiate from Device Security.
After you migrate, PAN-OS owns segment definitions for the migrated segments, and
Device Security displays them in read-only mode. You must manage
device context segments and their firewall and vsys assignments through
PAN-OS or Panorama. You can't reverse the migration, so review your
device context segment plan before you start.
During migration, Device Security preserves the devices already learned
within each segment. If a firewall is removed from a network segment during your
device context segment configuration, you can choose to clean up the data learned
from the affected firewalls. If you clean up the data, then Device Security relearns
devices when it sees the device traffic under the new segment assignments. If you
don't clean up the segment, then Device Security preserves the devices previously
learned by the segment and continues to display them in the Assets Inventory.
Pointer Paragraphs
When your firewalls receive traffic from overlapping IP address blocks,
use multi-vsys support for Device-ID so that each vsys applies policy
against the correct device. Multi-vsys support assigns device context segments
to firewalls and vsys, and their traffic gets scoped to the corresponding segment.
The segment identifier helps scope device context to the correct firewall or vsys,
preventing merged baselines when the same address appears in more than one part of
your network.
If you use multiple virtual systems (multi-vsys) with your firewalls, you can define
PAN-OS device context segments instead of Device Security network segments.
Device context segments can be scoped to an individual vsys within a firewall,
making them particularly useful both for device identification when you use
shared IP blocks across multi-vsys and when you want to ensure accurate
Security policy enforcement with Device-ID.
Compare Device Security-Managed and PAN-OS-Managed Segments
You can define network segments in Device Security or you can define
device context segments in PAN-OS.
Device Security network segments
give you an application-native workflow with Device Security networks,
device discovery, and third-party integrations. They are only aware of
firewalls in your Device Security network, not including any virtual systems (vsys)
on those firewalls. Device Security network segments aren't sent
to PAN-OS when delivering device context to the Edge Service.
PAN-OS device context segments give you firewall and vsys granularity that
Device Security network segments cannot. Two vsys on the same firewall can belong
to different segments. Device context segments include an identifier that
Device Security receives from EAL, helping Device Security separate device context
along the same boundaries you use for your network on multi-vsys firewalls.
Device Security can send the segment identifier back to PAN-OS when delivering
device context for Security policy enforcement.
Each vsys can belong to only one device context segment. However, a
device context segment can be assigned to multiple vsys on the same firewall,
or to multiple firewalls within the same tenant. If a vsys doesn't have a
device context segment assigned, it belongs to the default segment. You must
remove an existing device context segment assignment on a vsys before
assigning a new segment. A firewall can support up to 1000 segments.
Both segment types can coexist in the same tenant. The
Panorama Managed Segment column in the
Device Security Network Segments table identifies the source. Firewalls and
virtual systems that are not explicitly assigned to a segment belong to the
default segment, which Device Security creates and maintains automatically.
You do not need PAN-OS device context segments to use
Device Security network segments. Choose device context segments when you need
vsys granularity for device identification or for
Device-ID policy enforcement.