Configure Multi-vsys Support for Device-ID
Focus
Focus
Network Security

Configure Multi-vsys Support for Device-ID

Table of Contents

Configure Multi-vsys Support for Device-ID

Configure multi-vsys support for Device-ID when your firewalls or virtual systems receive traffic from overlapping IP address blocks.
Where Can I Use This?What Do I Need?
  • NGFW (Managed by PAN-OS or Panorama)
  • (Legacy) IoT Security (Standalone portal)
  • Device Security subscription for an advanced Device Security product (Enterprise Plus, Industrial OT, or Medical)
To use device context segments, your firewalls must run PAN-OS 12.2 or later. You can create device context segments directly on a firewall. However, if you have firewalls in cluster mode, then you must manage their device context segments through Panorama.
If you use Device-ID and your deployment includes firewalls or virtual systems that receive traffic from overlapping IP address blocks, configure multi-vsys support. Multi-vsys support uses PAN-OS device context segments to scope device context to the firewalls and vsys assigned to each segment, so that the Edge Service delivers the correct Device-ID verdict to each vsys.
If you already use Device Security network segments, you can migrate them to PAN-OS device context segments to gain vsys granularity. Migration is a one-time, per-tenant action that you initiate from Device Security. After you migrate, PAN-OS owns segment definitions for the migrated segments, and Device Security displays them in read-only mode. You must manage device context segments and their firewall and vsys assignments through PAN-OS or Panorama. You can't reverse the migration, so review your device context segment plan before you start.

Migrate to Device Context Segments

(Optional) Complete this task only if you already use Device Security network segments. If you have never configured network segments, skip this task and start with Configure Device Context Segments.
  1. In Device Security, select NetworksNetwork Segments.
  2. Review the existing network segments and the firewalls assigned to each one so that you can recreate the equivalent assignments on your firewalls.
  3. Initiate the migration to device context segments and confirm when Device Security prompts you.
    After you confirm, existing segments appear as Panorama-managed on the Network Segments page, and any new device context segments must be added through your firewall. You can still create network segments in Device Security.
  4. Choose whether to preserve or clean up the devices that Device Security already learned from the affected firewalls in the migrated segments.
    If a firewall is removed from a segment during your migration configuration, Device Security prompts you to clean up the segment. If you clean up the data, then Device Security relearns devices when it sees the device traffic under the new segment assignments. If you don't clean up the segment, then Device Security preserves the devices previously learned by the segment and continues to display them in the Assets Inventory. Select View Detail and confirm the Cleanup Network Segment dialog to remove devices previously discovered by the reassigned firewalls.

Configure Device Context Segments

Enable device context segments on your firewalls, define each device context segment as a shared object, assign the firewalls and virtual systems that belong to the segment, and push the configuration.
  1. Enable device context segments on your firewalls.
    1. Select DeviceSetupManagement.
    2. Edit PAN-OS Edge Service Settings.
    3. Enable Device Context Segments.
    4. Click OK.
  2. Define each device context segment as a shared object.
    1. Select ObjectsDevice Context Segment.
    2. + Add a new device context segment.
      To add multiple device context segments at once, use Bulk Segment Upload.
    3. Enter a unique Name for the segment.
    4. (Optional) Enter a Description and a UUID.
      If you don't specify a UUID, PAN-OS generates the segment UUID automatically.
    5. Click OK.
  3. Assign each firewall or vsys a device context segment.
    Each vsys can belong to only one device context segment. However, a device context segment can be assigned to multiple vsys on the same firewall, or to multiple firewalls within the same tenant. If a vsys doesn't have a device context segment assigned, it belongs to the default segment. You must remove an existing device context segment assignment on a vsys before assigning a new segment. A firewall can support up to 1000 segments.
    1. Select DeviceIoT SecurityDevice Context Segment Assignment.
    2. Choose the vsys Location you want to assign the device context segment to.
    3. Add a device context segment and choose the segment Name from the dropdown.
    4. Click OK.
    5. Repeat for each vsys.
  4. Commit the configuration and push it.
  5. Verify the assignment in Device Security.
    Select NetworksNetwork Segments and confirm that each segment lists the firewalls and virtual systems you assigned under Assigned Firewalls: By Panorama.
  6. (Optional) In Device Security, on the NetworksNetwork Segments page, select a device context segment and enable Restrict Device Context Sharing if you do not want that segment to send its non-shared IP address block device context to other segments.
    Each device context segment includes a Restrict Device Context Sharing setting that controls whether device context that Device Security learns outside of shared IP address blocks is shared with other segments. By default, the setting is off and Device Security sends non-shared IP address block device contexts to every segment so that firewalls in one segment can enforce Device-ID policy on devices first seen in another segment. When you enable Restrict Device Context Sharing on a segment, that segment doesn't send non-shared IP address block device context from its firewalls and vsys to other segments.