Panorama
Focus
Focus
Prisma AIRS

Panorama

Table of Contents


Panorama

Configure DPU traffic steering rules for your NVIDIA BlueField-3 embedded Prisma AIRS firewalls using the VM-Series plugin in Panorama.
  1. Access the VM-Series Plugin to configure DPU steering.
    1. From the Panorama web interface, select PanoramaPlugins.
    2. Locate the VM-Series Plugin and ensure it is installed and enabled.
  2. Define a new traffic steering rule.
    This rule instructs the DPU's OVS-DOCA to direct traffic matching the defined 5-tuple criteria to the Prisma AIRS firewall for inspection.
    1. Select DeviceTemplateVM-Series PluginNvidia.
    2. On the DPU Steering page, select Add Rule.
    3. For Standalone firewall Select VM-Series Plugin > Nvidia.
    4. On the DPU Steering page, select Add Rule.
    5. Enter a descriptive Name, such as Inspect_AI_Traffic.
    6. Set the Priority.
    7. For Action, select Inspect.
    8. Specify the traffic criteria:
      • For Protocol, select tcp.
      • For Source Subnet, enter 10.1.1.0/24.
      • For Destination Subnet, enter 10.2.0.0/24.
      • For Destination Port, enter 443.
    9. Select OK to save the rule.
      You can configure up to 1,000 rules.
  3. Commit the changes to the DPU-embedded firewalls.
    Committing the configuration applies the defined steering rules and failure mode settings from Panorama to your managed DPU-embedded firewalls.
    1. Select Commit at the top right of the Panorama interface.
    2. Review the changes and select Commit again in the confirmation dialog.