Multi-vsys Support for Device-ID
Preserve accurate Device-ID policy enforcement when your firewalls or
virtual systems receive traffic from overlapping IP address blocks.
| Where Can I Use This? | What Do I Need? |
To use device context segments, your firewalls must run
PAN-OS 12.2 or later. You can create device context segments
directly on a firewall. However, if you have firewalls in cluster mode, then
you must manage their device context segments through Panorama.
If you use Device-ID for Security policy enforcement, and your deployment
includes firewalls or virtual systems that receive traffic from
overlapping IP address blocks, you must configure device context segments to enable
multi-vsys support. This helps Device Security keep device context accurate across
multi-vsys boundaries. If your firewalls do not use multi-vsys or do not
share IP address blocks, you can continue to use Device-ID without
configuring device context segments.
A segment defines a boundary within which device context is unique. Each
segment identifies the firewalls and vsys that report traffic to
it. The segment identifier travels with every verdict the Edge Service delivers,
so the correct device context reaches the correct firewall or vsys, even when
IP address ranges are reused elsewhere in your network. Device Security uses
the segment context for device-to-site mappings, so that device identification remains
accurate when the same subnet is used in more than one location.
Without device context segments, Device Security cannot distinguish between devices
that share an IP address in different parts of your network, particularly when their
traffic passes through multi-vsys firewalls. Device identities
merge, behavior baselines contaminate each other, and the Edge Service delivers
incorrect Device-ID verdicts to your firewalls, which breaks
Security policy enforcement for every affected network.
Multi-vsys support for Device-ID uses device context segments
as shared objects. You define each segment in under , then assign each firewall or vsys to a segment under . Once you commit and push the configuration, Device Security
receives the segment mapping from PAN-OS and scopes every
verdict the Edge Service delivers to the firewalls and vsys that belong to the
matching segment. Devices with the same IP address in different segments are
tracked, profiled, and evaluated independently, giving Device Security an accurate
picture of each device regardless of address reuse. The device context segments also
help enforce Device-ID policies on the correct devices when your network
uses shared IP address blocks.
For devices in non-overlapping IP address spaces, you can control whether the
device context that Device Security learns in one segment is shared with firewalls
in other segments. This setting is useful when segments represent organizational
boundaries, such as separate business units or geographic sites, and you want to prevent
device context learned in one part of the network from influencing policy enforcement in
another, even when they are not in shared IP address blocks. Devices in
shared IP address blocks always receive segment-scoped verdicts, regardless
of sharing setting, preserving isolation between segments that operate in
overlapping IP address spaces.
Compare Device Security-Managed and PAN-OS-Managed Segments
You can define network segments in Device Security or you can define
device context segments in PAN-OS.
Device Security network segments
give you an application-native workflow with Device Security networks,
device discovery, and third-party integrations. They are only aware of
firewalls in your Device Security network, not including any virtual systems (vsys)
on those firewalls. Device Security network segments aren't sent
to PAN-OS when delivering device context to the Edge Service.
PAN-OS device context segments give you firewall and vsys granularity that
Device Security network segments cannot. Two vsys on the same firewall can belong
to different segments. Device context segments include an identifier that
Device Security receives from EAL, helping Device Security separate device context
along the same boundaries you use for your network on multi-vsys firewalls.
Device Security can send the segment identifier back to PAN-OS when delivering
device context for Security policy enforcement.
Each vsys can belong to only one device context segment. However, a
device context segment can be assigned to multiple vsys on the same firewall,
or to multiple firewalls within the same tenant. If a vsys doesn't have a
device context segment assigned, it belongs to the default segment. You must
remove an existing device context segment assignment on a vsys before
assigning a new segment. A firewall can support up to 1000 segments.
Both segment types can coexist in the same tenant. The
Panorama Managed Segment column in the
Device Security Network Segments table identifies the source. Firewalls and
virtual systems that are not explicitly assigned to a segment belong to the
default segment, which Device Security creates and maintains automatically.
You do not need PAN-OS device context segments to use
Device Security network segments. Choose device context segments when you need
vsys granularity for device identification or for
Device-ID policy enforcement.
Migrate to Panorama-Managed Device Context Segments
If you already use Device Security network segments, you can migrate
them to PAN-OS device context segments to gain vsys granularity.
Migration is a one-time, per-tenant action that you initiate from Device Security.
After you migrate, PAN-OS owns segment definitions for the migrated segments, and
Device Security displays them in read-only mode. You must manage
device context segments and their firewall and vsys assignments through
PAN-OS or Panorama. You can't reverse the migration, so review your
device context segment plan before you start.
During migration, Device Security preserves the devices already learned
within each segment. If a firewall is removed from a network segment during your
device context segment configuration, you can choose to clean up the data learned
from the affected firewalls. If you clean up the data, then Device Security relearns
devices when it sees the device traffic under the new segment assignments. If you
don't clean up the segment, then Device Security preserves the devices previously
learned by the segment and continues to display them in the Assets Inventory.
Restrict Device Context Sharing
Each device context segment includes a
Restrict Device Context Sharing setting that controls
whether device context that Device Security learns outside of shared IP
address blocks is shared with other segments. By default, the setting is off and
Device Security sends non-shared IP address block device contexts to every segment
so that firewalls in one segment can enforce Device-ID policy on devices first seen
in another segment. When you enable Restrict Device Context Sharing on a segment,
that segment doesn't send non-shared IP address block device context from its
firewalls and vsys to other segments.
From Device Security, enable the restriction setting on device context segments
that correspond to distinct administrative or geographic boundaries where you want
to keep device visibility contained. The restriction setting has no effect on
devices in shared IP address blocks — those device contexts are always limited to
the segment where the device was learned.