Security Profile Groups
Focus
Focus
Network Security

Security Profile Groups

Table of Contents

Security Profile Groups

A Security profile group is a set of security profiles that can be treated as a unit and then easily added to Security policies.
Where Can I Use This?What Do I Need?
  • NGFW (Managed by Strata Cloud Manager)
  • NGFW (Managed by PAN-OS or Panorama)
  • Prisma Access (Managed by Panorama or Strata Cloud Manager)
  • Prisma AIRS
Check for any license or role requirements for the products you're using.
A Security profile group is a set of security profiles that can be treated as a unit and then easily added to Security policies. Profiles that are often assigned together can be added to profile groups to simplify the creation of Security policies. For example, you can create a Security profile group for threats that includes profiles for Antivirus, Anti-Spyware, and Vulnerability Protection and then create a Security rule that includes the threats profile. Similarly, Antivirus, Anti-Spyware, Vulnerability Protection, URL filtering, and file blocking profiles that are often assigned together can be combined into profile groups to simplify the creation of Security policies. You can also setup a default security profile group—new security policies will use the settings defined in the default profile group to check and control traffic that matches the Security policy. Name a security profile group default to allow the profiles in that group to be added to new Security policies by default. This allows you to consistently include your organization’s preferred profile settings in new policies automatically, without having to manually add security profiles each time you create new rules.
Here are the Security Profile settings:
Security Profile Group Settings
Description
Name
The profile group name (up to 31 characters). This name appears in the profiles list when defining Security policies. The name is case-sensitive and must be unique. Use only letters, numbers, spaces, hyphens, and underscores.
Shared (Panorama only)
When a profile group is Shared, the profile group to be available to:
  • Every virtual system (vsys) on a multi-vsys. If you clear this selection, the profile group will be available only to the Virtual System selected in the Objects tab.
  • Every device group on Panorama. If you clear this selection, the profile group will be available only to the Device Group selected in the Objects tab.
Disable override (Panorama only)
Prevents administrators from overriding the settings of this Security Profile group object in device groups that inherit the object. By default, the administrators can override the settings for any device group that inherits the object.
Profiles
Profiles to be included in this group, for example, Antivirus, Anti-Spyware, Vulnerability Protection, URL filtering, and/or file blocking. Data filtering profiles can also be specified in Security Profile groups.

Create a Security Profile Group

While Security rules enable you to allow or block traffic on your network, Security profiles help you define an allow but scan rule, which scans allowed applications for threats, such as viruses, malware, spyware, and DDOS attacks. When traffic matches the allow rule defined in the Security policy, the Security profile(s) that are attached to the rule are applied for further content inspection rules such as antivirus checks and data filtering.
Security profiles are the only profiles that attach to security rules. Profiles and the security rules that they attach to must be of the same type.
  • Security profiles are not used in the match criteria of a traffic flow. The Security profile is applied to scan traffic after the application or category is allowed by the Security policy.
  • You must create a security profile group to add security profiles to policy rule in Strata Cloud Manager, but PAN-OS and Panorama do not have this requirement.
You can use out of the box default Security profiles to begin protecting your network from threats. See Set Up a Basic Security Policy for information on using the default profiles in your Security policy.
For recommendations on the best-practice settings for Security profiles, see Create Best Practice Security Profiles for the Internet Gateway.
Security Profile Groups streamline the management and application of security settings, allowing you to apply a set of predefined profiles to traffic based on their security requirements.