Enable Advanced Forwarding
Focus
Focus
SaaS Security

Enable Advanced Forwarding

Table of Contents

Enable Advanced Forwarding

Enable Advanced Forwarding to establish high-performance TLS connections directly from the data plane (DP) to advanced service addresses for inline cloud analysis.
Advanced Forwarding (PAN-OS 12.2.2 and later) replaces the legacy transport with a scalable connection pool that distributes cloud analysis submissions across all available data plane cores. Each connection is established directly from the data plane over TLS, replacing the intermediate process that previously serialized all cloud submissions through a limited, platform-dependent number of cores. This improves throughput and reduces latency for inline cloud analysis services including Enterprise DLP, Advanced Threat Prevention, Advanced URL Filtering, Advanced WildFire, Prisma AIRS (AI Runtime Security), ACE (App-ID Cloud Engine) when used alongside SaaS Security Inline, and AI Access Security.
When you enable Advanced Forwarding, a newly introduced discovery service dynamically assigns advanced service addresses based on the NGFW's geographic location.
Advanced Forwarding and the legacy transport are mutually exclusive. To revert to the legacy transport method, you must manually disable Advanced Forwarding. The NGFW does not automatically switch between transport modes.
PAN-OS Upgrade Considerations
Advanced Forwarding is available starting in PAN-OS 12.2.2. When upgrading from a pre-12.2.2 release, Advanced Forwarding is disabled by default and must be explicitly enabled after the upgrade.
  • Advanced Forwarding is disabled by default on NGFWs that are upgraded to PAN-OS 12.2.2 to avoid breaking existing functionality or causing a change in behavior. However, new platforms (or future platform releases) that support a minimum PAN-OS release of 12.2.2 have Advanced Forwarding automatically enabled.
  • When managing a mix of upgraded firewalls and new-platform firewalls under the same Panorama template, be aware that the local default for Advanced Forwarding differs between these platforms (including VM-Series base images with PAN-OS 12.2.2 and later). If the template does not explicitly configure the Advanced Forwarding setting, upgraded firewalls default to disabled while new platforms default to enabled. To ensure consistent behavior across your managed firewalls, explicitly set the Advanced Forwarding state in the template.
Requirements and Recommendations
  • (Required) Add a security policy rule for Advanced Forwarding service—When Advanced Forwarding uses the management interface for cloud connectivity (the default), create a security policy rule that allows traffic from the reserved source address range (127.140.0.0/16) to the cloud service destination.
  • (Required) Allow Advanced Forwarding App-IDs—In the security policy rule you created for Advanced Forwarding traffic, specify the following App-IDs as application match criteria. Advanced Forwarding service connections are evaluated against the security policy rulebase:
    • When using the management interface for cloud connectivity (default), create a security policy rule that allows traffic from the reserved source address range (127.140.0.0/16) to the cloud service destination.
    If you have restrictive outbound policies, ensure these App-IDs are explicitly permitted:
    • paloalto-pae-discovery-service
    • paloalto-pae-service
    • paloalto-chs-service
  • (Recommended) Configure a service route for best performance—For best throughput, configure a service route for Advanced Forwarding instead of using the management interface. A service route enables the connections to egress through a data plane interface, leveraging the data plane's parallel processing capabilities. Ensure a rule permits the Advanced Forwarding application traffic on the configured interface. When using a service route, create a rule that allows traffic on the service route interface.
    To configure a service route, add a service route for data-services under DeviceSetupServicesService Route Configuration. See Configure Service Routes.
  1. Navigate to the Content-ID settings.
    • NGFW—Select DeviceSetupContent-ID and edit the Content Cloud Settings.
    • Panorama—Select DeviceSetupContent-ID and select the Template associated with the managed firewalls that you want to enable Advanced Forwarding on.
  2. Enable Advanced Forwarding.
    Switching from the legacy transport mode to Advanced Forwarding causes a momentary disruption to the cloud connection. It is recommended to commit this change during a maintenance window.
  3. Configure the Advanced Forwarding settings.
    • Discovery Service Address—The address for the discovery service that dynamically assigns advanced service addresses to the NGFW based on its serial number, PAN-OS version, and geographic location (default: pae-discovery.hawkeye.services-edge.paloaltonetworks.com). By default, the discovery service address resolves to the closest regional IP address.
      Ensure the discovery service address is reachable from your network. If your network restricts outbound access, allow traffic to this address so the NGFW can query for its assigned advanced service addresses.
      • Discovery Service Address per Region
        • United States (Central)usc1.pae-discovery.hawkeye.services-edge.paloaltonetworks.com
        • United States (East)use4.pae-discovery.hawkeye.services-edge.paloaltonetworks.com
        • United States (West)usw1.pae-discovery.hawkeye.services-edge.paloaltonetworks.com
        • Canadaca.pae-discovery.hawkeye.services-edge.paloaltonetworks.com
        • Brazilbr.pae-discovery.hawkeye.services-edge.paloaltonetworks.com
        • Germanyde.pae-discovery.hawkeye.services-edge.paloaltonetworks.com
        • United Kingdomuk.pae-discovery.hawkeye.services-edge.paloaltonetworks.com
        • Netherlandsnl.pae-discovery.hawkeye.services-edge.paloaltonetworks.com
        • Switzerlandch.pae-discovery.hawkeye.services-edge.paloaltonetworks.com
        • Francefr.pae-discovery.hawkeye.services-edge.paloaltonetworks.com
        • Polandpl.pae-discovery.hawkeye.services-edge.paloaltonetworks.com
        • Spaines.pae-discovery.hawkeye.services-edge.paloaltonetworks.com
        • Italyit.pae-discovery.hawkeye.services-edge.paloaltonetworks.com
        • Israelil.pae-discovery.hawkeye.services-edge.paloaltonetworks.com
        • Qatarqa.pae-discovery.hawkeye.services-edge.paloaltonetworks.com
        • Saudi Arabiasa.pae-discovery.hawkeye.services-edge.paloaltonetworks.com
        • Singaporesg.pae-discovery.hawkeye.services-edge.paloaltonetworks.com
        • Japanjp.pae-discovery.hawkeye.services-edge.paloaltonetworks.com
        • Koreakr.pae-discovery.hawkeye.services-edge.paloaltonetworks.com
        • Taiwantw.pae-discovery.hawkeye.services-edge.paloaltonetworks.com
        • Indonesiaid.pae-discovery.hawkeye.services-edge.paloaltonetworks.com
        • Indiain.pae-discovery.hawkeye.services-edge.paloaltonetworks.com
        • Australiaau.pae-discovery.hawkeye.services-edge.paloaltonetworks.com
        • South Africaza.pae-discovery.hawkeye.services-edge.paloaltonetworks.com
    • Discovery Service Interval (seconds)—The interval, in seconds, between discovery service queries. The NGFW periodically queries the discovery service to refresh its assigned advanced service addresses (default is 14400 seconds).
    • Max Discovery Retry Count—The maximum number of times the NGFW retries a failed discovery service query.
      The NGFW retries failed discovery queries every 60 seconds up to the configured maximum retry count. Once exhausted, retries continue at 5 minute intervals until discovery is successful.
    • Enable Multi-FQDN Support—Enable the NGFW to use multiple advanced service address FQDNs simultaneously. When enabled, the discovery service can assign different FQDNs for different cloud analysis services, allowing the NGFW to distribute connections across multiple endpoints. Reserved for future use.
    • Override Discovered CHS Address—Enable this option to manually override the Config Hub Service (CHS) address assigned by the discovery service. When enabled, the NGFW uses the address specified in Config Hub Service (CHS) Address instead of the discovery-assigned endpoint. Reserved for future use.
    • Config Hub Service (CHS) Address—The address for the Config Hub Service (CHS) that the NGFW uses to store and retrieve configuration. Only configurable when Override Discovered CHS Address is enabled. Reserved for future use.
    • Override Discovered Advanced Address—Enable this option to manually override the Advanced Forwarding service address assigned by the discovery service. When enabled, the NGFW uses the address specified in Advanced Service Address instead of the discovery-assigned endpoint.
    • Advanced Service Address—The address for the Advanced Forwarding service used for inline cloud analysis payload exchange. Only configurable when Override Discovered Advanced Address is enabled.
      Ensure the advanced service address assigned by the discovery service is reachable from your network. If your network restricts outbound access, allow traffic to this address.
      • Advanced Service Address per Region
        • United States (Central)usc1.pae.hawkeye.services-edge.paloaltonetworks.com
        • United States (East)use4.pae.hawkeye.services-edge.paloaltonetworks.com
        • United States (West)usw1.pae.hawkeye.services-edge.paloaltonetworks.com
        • Canadaca.pae.hawkeye.services-edge.paloaltonetworks.com
        • Brazilbr.pae.hawkeye.services-edge.paloaltonetworks.com
        • Germanyde.pae.hawkeye.services-edge.paloaltonetworks.com
        • United Kingdomuk.pae.hawkeye.services-edge.paloaltonetworks.com
        • Netherlandsnl.pae.hawkeye.services-edge.paloaltonetworks.com
        • Switzerlandch.pae.hawkeye.services-edge.paloaltonetworks.com
        • Francefr.pae.hawkeye.services-edge.paloaltonetworks.com
        • Polandpl.pae.hawkeye.services-edge.paloaltonetworks.com
        • Spaines.pae.hawkeye.services-edge.paloaltonetworks.com
        • Italyit.pae.hawkeye.services-edge.paloaltonetworks.com
        • Israelil.pae.hawkeye.services-edge.paloaltonetworks.com
        • Qatarqa.pae.hawkeye.services-edge.paloaltonetworks.com
        • Saudi Arabiasa.pae.hawkeye.services-edge.paloaltonetworks.com
        • Singaporesg.pae.hawkeye.services-edge.paloaltonetworks.com
        • Japanjp.pae.hawkeye.services-edge.paloaltonetworks.com
        • Koreakr.pae.hawkeye.services-edge.paloaltonetworks.com
        • Taiwantw.pae.hawkeye.services-edge.paloaltonetworks.com
        • Indonesiaid.pae.hawkeye.services-edge.paloaltonetworks.com
        • Indiain.pae.hawkeye.services-edge.paloaltonetworks.com
        • Australiaau.pae.hawkeye.services-edge.paloaltonetworks.com
        • South Africaza.pae.hawkeye.services-edge.paloaltonetworks.com
  4. Click OK.
  5. Commit the configuration.