Configuration: IP Tag Collection
Focus
Strata Cloud Manager

Configuration: IP Tag Collection

Table of Contents

Configuration: IP Tag Collection

Automate cloud IP-Tag collection and distribution in Strata™ Cloud Manager to enable dynamic security policies for your cloud workloads.
Where Can I Use This?What Do I Need?
  • NGFW
  • NGFW (Managed by Strata Cloud Manager)
  • Cloud NGFW
  • Strata Cloud Manager Essentials with Strata Logging Service
  • VM-Series Firewall Funded with Software NGFW Credits or Prisma AIRS AI Runtime Firewall
  • Network Administrator or Superuser role on the Customer Support Portal
IP-Tag Harvesting in Strata Cloud Manager (SCM) enables your firewalls to dynamically receive IP-to-Tag mapping information from cloud providers. This feature organizes cloud workload information into Dynamic Address Groups (DAGs) within your security policies. This allows you to create security policies based on logical tags rather than static IP addresses, ensuring your policies automatically adapt as cloud workloads scale. This approach eliminates the manual effort of updating security rules for constantly changing cloud environments.
SCM acts as the central management platform for configuring and orchestrating IP-Tag Harvesting. You onboard your cloud accounts, such as AWS, Azure, or GCP, to SCM. This onboarding process, either manual with credentials or automated via Terraform, establishes the necessary permissions for SCM to access cloud provider APIs and harvest IP-Tag data. You then define Distribution Profiles in SCM, specifying firewall dynamic address group membership and roles (contributor or receiver). Additionally, you can harvest IP tags from Zero Networks; this allows you to collect tags for integrated policy.
IP-Tag Distribution Profiles enable your security policies to dynamically adapt to scaling cloud workloads. Firewalls (VM-Series, Prisma AIRS Runtime Firewall, and Cloud NGFW) use these profiles to participate in IP-Tag distribution, defining their roles as contributors or receivers. This mechanism dynamically applies security policies to your cloud resources based on IP tags, adapting to ephemeral cloud environments.
You have two options to configure IP-Tag Collection—Terraform templates (recommended) or by manually entering the required information. Zero Networks integration does not support Terraform template configurations.