Configuration: Security Services
Focus
Strata Cloud Manager

Configuration: Security Services

Table of Contents

Configuration: Security Services

Learn to manage your security services.
Where Can I Use This?What Do I Need?
  • Prisma Access (Managed by Panorama or Strata Cloud Manager)
  • NGFW, including those funded by Software NGFW Credits
Each of these licenses include access to Strata Cloud Manager:
→ The features and capabilities available to you in Strata Cloud Manager depend on which license(s) you are using.
Go to ConfigurationNGFW and Prisma AccessSecurity Services to manage your security services and protect your network, systems, and users.

Feature Highlights

Understand key features that help you define and enforce security policies within your Prisma Access and Next - Generation Firewall deployments.
  • Define and enforce how traffic is allowed or denied. All traffic that passes through your Strata Cloud Manager environment is evaluated against the security policy, and rules are applied in a top-down manner.
  • A security profile group is a set of security profiles that can be treated as a unit and then easily added to Security policies. Profiles that are often assigned together can be added to profile groups to simplify the creation of Security policies.
  • Anti-Spyware
    Blocks spyware from compromised hosts attempting to connect to external command-and-control (C2) servers, helping you to detect malicious outbound traffic.
  • Vulnerability Protection
    Protects systems from known vulnerabilities and exploits, preventing unauthorized access attempts as traffic enters the network.
  • Wildfire and Antivirus profiles
    Detects and prevents malware, worms, trojans, and spyware downloads using a stream-based malware prevention engine without significant performance impact. Scans files such as executables, PDFs, HTML and JavaScript malware,compressed files, and encrypted content if decryption is enabled.
  • DNS Security
    A cloud-based, continuously evolving threat prevention service that defends your network against advanced DNS-based threats.
  • URL Access Management
    Monitors and controls user access to web content over HTTP and HTTPS based on URL categories.
  • File Blocking
    Identifies and blocks or monitors specific file types to prevent unwanted file transfers.
  • HTTP Header Inspection
    Provides additional inspection by examining HTTP headers.
  • AI Security
    Protects AI-specific traffic. Available for AI Runtime Security: Network intercept firewalls.
  • Internet Security
    Applies internet security settings to protect against specific threats and vulnerabilities, without needing individual policy assignments.
  • Decryption
    Enables visibility into encrypted traffic. Start by importing your decryption certificates — for everything else, we've built in best practices settings that you can use to get up and running.
  • DoS Protection
    Protect critical systems against flood attacks. A DoS Protection profile specifies the threshold to trigger alarms and actions for new connection rates.