| Where Can I Use This? | What Do I Need? |
To use device context segments, your firewalls must run
PAN-OS 12.2 or later. You can create device context segments
directly on a firewall. However, if you have firewalls in cluster mode, then
you must manage their device context segments through Panorama.
If you use Device-ID and your deployment includes firewalls or
virtual systems that receive traffic from overlapping IP address blocks, configure
multi-vsys support. Multi-vsys support uses PAN-OS
device context segments to scope device context to the firewalls and vsys
assigned to each segment, so that the Edge Service delivers the correct
Device-ID verdict to each vsys.
If you already use Device Security network segments, you can migrate
them to PAN-OS device context segments to gain vsys granularity.
Migration is a one-time, per-tenant action that you initiate from Device Security.
After you migrate, PAN-OS owns segment definitions for the migrated segments, and
Device Security displays them in read-only mode. You must manage
device context segments and their firewall and vsys assignments through
PAN-OS or Panorama. You can't reverse the migration, so review your
device context segment plan before you start.