| Where Can I Use This? | What Do I Need? |
- NGFW (Managed by Panorama or Strata Cloud Manager)
- Prisma Access (Managed by Panorama or Strata Cloud Manager)
|
- SaaS Security Inline license
- NGFW or Prisma Access license
Or any of the following licenses that include the SaaS Security Inline license:
|
To unlock the
SaaS Security Inline capabilities—SaaS
visibility, SaaS policy rule recommendations, and
App-ID Cloud Engine (ACE), simply activate
SaaS Security Inline using one of the following activation types,
depending on whether you have an Enterprise Level Activation (ELA) license type or
non-ELA:
- (non-ELA)
Activation email that you received.
- (ELA) Hub ELA Activations menu.
- (ELA) Customer Support Portal Enterprise Agreements page.
If you're adding
SaaS Security Inline to a
firewall that is already enforcing App-ID based security policy rules,
activating
SaaS Security Inline might result in unexpected changes in
policy enforcement. These unexpected changes might occur because the App-ID
Cloud Engine (ACE) included with
SaaS Security Inline gives you visibility
and control into thousands of applications that were previously identified
generically as
SSL or
web-browsing applications. When ACE identifies
an application that was previously classified as
SSL or
web-browsing, it reclassifies the application
with the new specific App-ID. Traffic for this App-ID will be blocked or allowed
based on the first security policy rule it matches. Because the application is
now classified with a specific App-ID, it will no longer match rules that are
configured for the generic
SSL or
web-browsing App-IDs. The firewall might now
block traffic that it previously allowed, possibly resulting in unintentional
business interruption. Conversely, the firewall might allow traffic that it
previously blocked, potentially leading to security gaps.
If you're enabling
SaaS Security Inline for Next-Generation CASB,
activate in SASE Cloud Management
Console using the activation email you received.
After activation, your NGFW contact the cloud service and begin to download any
SaaS policy rule recommendations that you created.
SaaS Security Inline activation:
- Creates a URL for SaaS Security Inline login.
- Pushes the SaaS Security Inline license to the NGFW that you select. Panorama does not require a license.
- Enables a secure and encrypted connection and successful, mutual authentication between SaaS Security Inline, Palo Alto Networks
NGFW, Panorama, and Strata Logging Service.
Before
you activate:
- Ensure that your environment meets all the activation requirements for the SaaS Security Inline features you want to enable. (SaaS
administrator)
| Requirement |
SaaS Visibility
|
SaaS Policy Recommendations and ACE
|
|
One or more NGFW running PAN-OS 10.1 or
later with or without Panorama.
|
N/A
|
Yes
|
|
One new or existing Strata Logging Service license
per SaaS tenant.
|
Yes
|
Yes
|
|
Same Support Account for SaaS tenant, Strata Logging Service, Enterprise DLP, and
NGFW.
|
Yes
|
Yes
|
|
One SaaS Security Inline license per firewall.
|
Yes
|
Yes
|
|
Enterprise DLP license on NGFW and in
the same Customer Support Portal account as the SaaS
tenant.
Only required if you want to use the Data Profiles
option for SaaS policy rule recommendations
|
N/A
|
Yes
|
Because SaaS Security Inline requires network traffic data for
analysis, you must enable NGFW to forward logs with that data
to Strata Logging Service. Your SaaS Security Inline
subscription requires that you also have an active Strata Logging Service instance, which stores the data logs from NGFW and streams them to SaaS Security Inline.
- Start the ACE deployment. (NGFW administrator / SaaS Policy Rule Recommendations)
ACE
deployment is required if you want ACE and SaaS policy rule recommendations.
ACE deployment isn’t required for displaying SaaS app visibility data,
though you must still configure
log forwarding. Without logs for
all
NGFW,
SaaS Security Inline can’t display SaaS app
visibility data and might not be able to enforce policy rule
recommendations.
- Bring the NGFW and Panorama (if using)
online.
- Install the device certificate.
After
you activate: