Panorama enables you to deploy content updates to firewalls easily
and rapidly. If you’re using Panorama to manage firewalls, follow these steps to
deploy content updates instead of the ones below.
To unlock the full Applications and Threats content
package, get a Threat Prevention license and activate the license on
Manually upload the license key or retrieve it from
the Palo Alto Networks license server.
Verify that the Threat Prevention license is active.
Set the schedule for the firewall to retrieve and install
the firewall checks with the Palo Alto Networks update server for
new Applications and Threat content releases, and on what
for the firewall
to take when it finds and retrieves a new content release.
Set an installation
content releases. Content releases must be available on the Palo
Alto Networks update server at least this amount of time before
the firewall can retrieve the release and perform the Action you
configured in the last step.
If yours is a mission-critical network, where you
have zero tolerance for application downtime (application availability
is tantamount even to the latest threat prevention), you can set
New App-ID Threshold
. The firewall only
retrieves content updates that contain new App-IDs after they have
been available for this amount of time.
to save the Applications
and Threats content update schedule, and
Set up log forwarding to send Palo Alto
Networks critical content alerts to external services that you use
for monitoring network and firewall activity. This allows you to
ensure that the appropriate personnel is notified about critical content
issues, so that they can take action as needed. Critical content
alerts are logged as system log entries with the following Type
and Event: (subtype eq content) and (eventid eq palo-alto-networks-message).
While scheduling content updates is a one-time or infrequent
task, after you’ve set the schedule, you’ll need to continue to Manage New and Modified App-IDs that
are included in content releases, as these App-IDs can change how
security policy is enforced.