Automate cloud IP-Tag collection and distribution in Strata™ Cloud Manager to enable
dynamic security policies for your cloud workloads.
| Where Can I Use This? | What Do I Need? |
- NGFW
- NGFW (Managed by Strata Cloud Manager)
- Cloud NGFW
|
- Strata Cloud Manager Essentials with Strata Logging
Service
- VM-Series Firewall Funded with Software NGFW Credits or
Prisma AIRS AI Runtime Firewall
- Network Administrator or Superuser role on the Customer
Support Portal
|
IP-Tag Harvesting in Strata Cloud Manager (SCM) enables your firewalls to dynamically
receive IP-to-Tag mapping information from cloud providers. This feature organizes
cloud workload information into
Dynamic Address Groups (DAGs) within your
security policies. This allows you to create security policies based on logical tags
rather than static IP addresses, ensuring your policies automatically adapt as cloud
workloads scale. This approach eliminates the manual effort of updating security
rules for constantly changing cloud environments.
SCM acts as the central management platform for configuring and orchestrating IP-Tag
Harvesting. You onboard your cloud accounts, such as AWS, Azure, or GCP, to SCM.
This onboarding process, either manual with credentials or automated via Terraform,
establishes the necessary permissions for SCM to access cloud provider APIs and
harvest IP-Tag data. You then define Distribution Profiles in SCM, specifying
firewall dynamic address group membership and roles (contributor or receiver).
Additionally, you can harvest IP tags from Zero Networks; this allows you to collect
tags for integrated policy.
IP-Tag Distribution Profiles enable your security policies to dynamically adapt to
scaling cloud workloads. Firewalls (VM-Series, Prisma AIRS Runtime Firewall, and
Cloud NGFW) use these profiles to participate in IP-Tag distribution, defining their
roles as contributors or receivers. This mechanism dynamically applies security
policies to your cloud resources based on IP tags, adapting to ephemeral cloud
environments.
You have two options to configure IP-Tag Collection—Terraform templates (recommended)
or by manually entering the required information. Zero Networks integration does not
support Terraform template configurations.