Multi-vsys Support for Device-ID
Focus
Focus
Network Security

Multi-vsys Support for Device-ID

Table of Contents

Multi-vsys Support for Device-ID

Preserve accurate Device-ID policy enforcement when your firewalls or virtual systems receive traffic from overlapping IP address blocks.
Where Can I Use This?What Do I Need?
  • NGFW (Managed by PAN-OS or Panorama)
  • (Legacy) IoT Security (Standalone portal)
  • Device Security subscription for an advanced Device Security product (Enterprise Plus, Industrial OT, or Medical)
To use device context segments, your firewalls must run PAN-OS 12.2 or later. You can create device context segments directly on a firewall. However, if you have firewalls in cluster mode, then you must manage their device context segments through Panorama.
If you use Device-ID for Security policy enforcement, and your deployment includes firewalls or virtual systems that receive traffic from overlapping IP address blocks, you must configure device context segments to enable multi-vsys support. This helps Device Security keep device context accurate across multi-vsys boundaries. If your firewalls do not use multi-vsys or do not share IP address blocks, you can continue to use Device-ID without configuring device context segments.
A segment defines a boundary within which device context is unique. Each segment identifies the firewalls and vsys that report traffic to it. The segment identifier travels with every verdict the Edge Service delivers, so the correct device context reaches the correct firewall or vsys, even when IP address ranges are reused elsewhere in your network. Device Security uses the segment context for device-to-site mappings, so that device identification remains accurate when the same subnet is used in more than one location.
Without device context segments, Device Security cannot distinguish between devices that share an IP address in different parts of your network, particularly when their traffic passes through multi-vsys firewalls. Device identities merge, behavior baselines contaminate each other, and the Edge Service delivers incorrect Device-ID verdicts to your firewalls, which breaks Security policy enforcement for every affected network.
Multi-vsys support for Device-ID uses device context segments as shared objects. You define each segment in under ObjectsDevice Context Segment, then assign each firewall or vsys to a segment under DeviceIoT SecurityDevice Context Segment Assignment. Once you commit and push the configuration, Device Security receives the segment mapping from PAN-OS and scopes every verdict the Edge Service delivers to the firewalls and vsys that belong to the matching segment. Devices with the same IP address in different segments are tracked, profiled, and evaluated independently, giving Device Security an accurate picture of each device regardless of address reuse. The device context segments also help enforce Device-ID policies on the correct devices when your network uses shared IP address blocks.
For devices in non-overlapping IP address spaces, you can control whether the device context that Device Security learns in one segment is shared with firewalls in other segments. This setting is useful when segments represent organizational boundaries, such as separate business units or geographic sites, and you want to prevent device context learned in one part of the network from influencing policy enforcement in another, even when they are not in shared IP address blocks. Devices in shared IP address blocks always receive segment-scoped verdicts, regardless of sharing setting, preserving isolation between segments that operate in overlapping IP address spaces.

Compare Device Security-Managed and PAN-OS-Managed Segments

You can define network segments in Device Security or you can define device context segments in PAN-OS.
Device Security network segments give you an application-native workflow with Device Security networks, device discovery, and third-party integrations. They are only aware of firewalls in your Device Security network, not including any virtual systems (vsys) on those firewalls. Device Security network segments aren't sent to PAN-OS when delivering device context to the Edge Service.
PAN-OS device context segments give you firewall and vsys granularity that Device Security network segments cannot. Two vsys on the same firewall can belong to different segments. Device context segments include an identifier that Device Security receives from EAL, helping Device Security separate device context along the same boundaries you use for your network on multi-vsys firewalls. Device Security can send the segment identifier back to PAN-OS when delivering device context for Security policy enforcement.
Each vsys can belong to only one device context segment. However, a device context segment can be assigned to multiple vsys on the same firewall, or to multiple firewalls within the same tenant. If a vsys doesn't have a device context segment assigned, it belongs to the default segment. You must remove an existing device context segment assignment on a vsys before assigning a new segment. A firewall can support up to 1000 segments.
Both segment types can coexist in the same tenant. The Panorama Managed Segment column in the Device Security Network Segments table identifies the source. Firewalls and virtual systems that are not explicitly assigned to a segment belong to the default segment, which Device Security creates and maintains automatically.
You do not need PAN-OS device context segments to use Device Security network segments. Choose device context segments when you need vsys granularity for device identification or for Device-ID policy enforcement.

Migrate to Panorama-Managed Device Context Segments

If you already use Device Security network segments, you can migrate them to PAN-OS device context segments to gain vsys granularity. Migration is a one-time, per-tenant action that you initiate from Device Security. After you migrate, PAN-OS owns segment definitions for the migrated segments, and Device Security displays them in read-only mode. You must manage device context segments and their firewall and vsys assignments through PAN-OS or Panorama. You can't reverse the migration, so review your device context segment plan before you start.
During migration, Device Security preserves the devices already learned within each segment. If a firewall is removed from a network segment during your device context segment configuration, you can choose to clean up the data learned from the affected firewalls. If you clean up the data, then Device Security relearns devices when it sees the device traffic under the new segment assignments. If you don't clean up the segment, then Device Security preserves the devices previously learned by the segment and continues to display them in the Assets Inventory.

Restrict Device Context Sharing

Each device context segment includes a Restrict Device Context Sharing setting that controls whether device context that Device Security learns outside of shared IP address blocks is shared with other segments. By default, the setting is off and Device Security sends non-shared IP address block device contexts to every segment so that firewalls in one segment can enforce Device-ID policy on devices first seen in another segment. When you enable Restrict Device Context Sharing on a segment, that segment doesn't send non-shared IP address block device context from its firewalls and vsys to other segments.
From Device Security, enable the restriction setting on device context segments that correspond to distinct administrative or geographic boundaries where you want to keep device visibility contained. The restriction setting has no effect on devices in shared IP address blocks — those device contexts are always limited to the segment where the device was learned.