Manage Network Profiles (Strata Cloud Manager)
Focus
Focus
Next-Generation Firewall

Manage Network Profiles (Strata Cloud Manager)

Table of Contents

Manage Network Profiles (Strata Cloud Manager)

Add, edit, clone, and delete network profiles from the centralized Network Profiles page in Strata Cloud Manager.
Where Can I Use This?What Do I Need?
  • NGFW (Managed by Strata Cloud Manager)
Network profiles define reusable sets of cryptographic, monitoring, and network behavior settings that you apply to VPN tunnels, interfaces, and zones. The Strata™ Cloud Manager Network Profiles page consolidates all profile types into a single tabbed interface so you can create, edit, and delete profiles without navigating through multiple configuration menus. When you add or edit a profile, a sliding pane opens alongside the existing profile list so you can reference other profiles while making configuration changes.
Clone is available for GlobalProtect IPSec Crypto, IPSec Crypto, IKE Crypto, and LLDP profiles. Role-based access controls determine which users can create, edit, or delete network profiles.
  1. Select ConfigurationNGFW and Prisma Access and choose the Configuration Scope where you want to manage network profiles.
  2. Select Network & DeviceNetwork Profiles.
  3. Select the tab for the profile type you want to manage.
    • IKE Gateways: Define the parameters for IKE phase 1 negotiations between VPN peers, including the peer IP address, authentication method, and associated IKE crypto profile.
    • GlobalProtect IPSec Crypto: Define the encryption and authentication algorithms used to secure GlobalProtect IPSec tunnels.
    • IPSec Crypto: Define the ESP or AH protocol, encryption, authentication, Diffie-Hellman group, lifetime, and lifesize settings for IPSec phase 2 security associations.
    • IKE Crypto: Define the Diffie-Hellman group, encryption, authentication, and lifetime settings for IKE phase 1 key exchanges.
    • Monitor: Define the action, interval, and threshold settings for monitoring IPSec tunnel connectivity.
    • Interface Mgmt: Define the administrative management services and network services permitted on an interface.
    • LLDP: Define the Link Layer Discovery Protocol mode, SNMP syslog notification, and optional TLV settings for interfaces.
  4. On the selected tab, take one of the following actions:
    • To add a profile, click Add and configure the settings in the sliding pane.
    • To edit a profile, click the profile name, update the settings in the sliding pane, and click Save.
    • To clone a profile (GlobalProtect IPSec Crypto, IPSec Crypto, IKE Crypto, and LLDP only), select the profile and click Clone. Enter a new name and click Save.
    • To delete a profile, select the profile and click Delete. Confirm the deletion.