Enable PAN-OS Shield
Focus
Focus
Next-Generation Firewall

Enable PAN-OS Shield

Table of Contents

Enable PAN-OS Shield

Enable PAN-OS Shield on your firewall to protect control traffic against vulnerability exploits targeting the management plane.
Where Can I Use This?What Do I Need?
  • NGFW
  • PAN-OS 12.2.2 and later
PAN-OS Shield requires PAN-OS 12.2.2 or a later release. When you enable PAN-OS Shield, the firewall creates a dedicated internal virtual system that inspects inbound control traffic using threat prevention signatures delivered through content updates. If you have an Advanced Threat Prevention license, signatures are delivered through regular content packages. If you don't have an Advanced Threat Prevention license (or if it has expired), the signatures are delivered through application-only content packages instead.
You can enable PAN-OS Shield without GlobalProtect gateway or portal configured, but the feature doesn't protect anything until GlobalProtect control traffic is present.
  1. Select DeviceSetupPAN-OS Security.
  2. In the PAN-OS Shield section, enable PAN-OS Shield.
    When enabled, the firewall scans inbound control traffic for vulnerability exploits before it reaches the management plane. A threat log is generated each time a signature triggers.
  3. Commit your changes and reboot the firewall.
    After the commit and reboot complete, the firewall creates the internal PAN-OS Shield vsys and begins inspecting control traffic using the vulnerability protection profile and security policy delivered through content updates.
  4. (Optional) Select MonitorLogsThreat to view threats detected by PAN-OS Shield.
    Threats detected by PAN-OS Shield display panos-shield-policy in the Rule column.
    Click a log entry to open the Detailed Log View, which shows the threat type, threat ID, severity, action taken, and session details. Click View in Threat Vault next to the threat ID to view the associated CVE and additional threat intelligence.