Tags allow you to identify the purpose or function of a security rule and help you
better organize your policy rulebase. PAN-OS 11.1 introduces the ability to
visually group and manage your policy rulebase using the assigned tags. When
viewing your policy rulebase using tags, you can perform operation procedures
such as adding, deleting, or moving the rules with the applied tag more easily.
Viewing your policy rulebase using tags maintains the rule evaluation order.
For firewalls managed by a Panorama management server, you can create and assign
tags to security rules from Panorama. Both Panorama, managed firewalls, and
standalone firewalls running PAN-OS 10.2.5 or later 10.2 release, PAN-OS 11.0.3
or later 11.0 release, or any PAN-OS 11.1 release support policy rulebase base
management using tags. Policy rulebase management using tags is supported for
all policy types.