|
Enable PAN-OS Shield to scan control traffic destined for the
firewall for vulnerability exploits before it reaches the
management plane.
When enabled, the firewall inspects inbound control traffic using
threat prevention signatures delivered through content updates. If a
threat is detected, the configured action is taken and a threat log
is generated.
The vulnerability protection profile and security policy are
delivered through content updates and are read-only. You can add
threat exceptions to handle false positives by changing the action
for a specific threat ID.
This feature is disabled by default. A commit and reboot is required
after enabling or disabling PAN-OS Shield.
|