New NetSec Platform Features on Strata Cloud Manager (September 2025)
Focus
Focus
Strata Cloud Manager

New NetSec Platform Features on Strata Cloud Manager (September 2025)

Table of Contents


New NetSec Platform Features on Strata Cloud Manager (September 2025)

See all the new features made available for Strata Cloud Manager in September 2025.
These new features follow the Strata Cloud Manager release model of continuous feature deployment; as they're ready, we make them available to ensure the latest support for all products and subscriptions across the NetSec platform. There's no Strata Cloud Manager upgrade or management version requirement associated with these features; however, check if they have version or license dependencies associated with other parts of the NetSec platform (like a cloud-delivered security service subscription, or a Prisma Access version, for example).

Integrating Strata Cloud Manager Pro for NGFW with Enterprise Support Agreement (ESA)

September 26, 2025
Supported for: Strata Cloud Manager
Palo Alto Networks now enables you to leverage Strata Cloud Manager Pro for NGFW capabilities directly within your Enterprise Support Agreements (ESA), significantly enhancing your support experience while reducing time to resolution. This integration helps you maximize your investment in Palo Alto Networks solutions while simplifying management of your security infrastructure.
With the ESA and Strata Cloud Manager integration, you receive a single authentication code that activates both your support entitlements and Strata Cloud Manager Pro features for your NGFW deployments. This consolidation eliminates the need to purchase and manage separate subscriptions, creating a more streamlined experience. Your ESA agreement with Strata Cloud Manager Pro provides advanced monitoring, reporting, and management capabilities that help you identify and resolve security issues more quickly.
Through this integration, you gain the operational benefits of Strata Cloud Manager's advanced management capabilities combined with Palo Alto Networks support services, all within a single, cost-effective agreement that covers your entire NGFW deployment.

TechDocs Strata Copilot: Your AI Assistant on TechDocs

September 18, 2025
Supported on the Palo Alto Networks TechDocs website for network security products.
TechDocs Strata Copilot, an AI-powered assistant, is now available on the Palo Alto Networks TechDocs website. It simplifies how you find information by letting you ask questions in natural language, which eliminates the need to search through documentation or use specific keywords.
TechDocs Strata Copilot pulls answers to your queries from a comprehensive data source, such as our Network Security Documentation, Knowledge Base articles, and LIVEcommunity. Instead of just showing you a link, TechDocs Strata Copilot provides a concise summary to give you immediate clarity.
Every answer includes direct links to the source documentation, allowing you to explore the context and verify the information. This feature enhances your self-service experience by providing instant access to critical knowledge, reducing resolution times, and helping you more efficiently manage your network security solutions.

Strata Cloud Manager: Visibility into Agent Versions for Connected Devices

September 11, 2025
Supported for: Strata Cloud Manager
User Activity Insights in Strata Cloud Manager provides clear visibility into connected gateway agent (GlobalProtect and Prisma Access) versions and subversions for connected user devices in your deployment. Previously, GlobalProtect agent version information varied by its source (Strata Logging Service, ADEM, or SaaS agent) and lacked subversion details.
You can now access both the main agent version and detailed subversion information, including patch details. The subversion details for existing GlobalProtect devices populate over a 30-day period. However, for newly added devices, the subversion details are displayed immediately upon their first connection. The GlobalProtect agent subversions are displayed for devices connected to Prisma Access only. This clear view of your agent distribution landscape helps you identify version inconsistencies and plan updates more effectively.

Strata Cloud Manager: Admin Role Profile Configuration

September 23, 2025
Supported for: NGFW (Managed by Strata Cloud Manager)
Strata Cloud Manager™ now makes it easy to create and deploy custom admin roles for managed NGFWs, allowing you to control what each administrator is allowed to do.
By setting up roles with specific permissions and assigning them to administrators you can enforce the principle of least privilege, ensuring administrators have only the access necessary for their specific job functions.
This feature gives you fine-grained control across the web interface, CLI, REST API, and XML API. You can configure detailed access permissions over various functional areas, including device configuration, network settings, security policies, monitoring capabilities, and operational tasks. For example, you can create a network admin role that has permissions to manage interfaces and routing but is restricted from changing security profiles.
By configuring custom admin roles, you can enhance your security posture, simplify compliance, and create a more organized and efficient workflow for your administrators.

Strata Cloud Manager: Custom Defined Application Settings

September 23, 2025
Strata Cloud Manager (SCM) now provides users the ability to customize predefined local and cloud-based applications. For each given application, you can modify the TCP Timeout, TCP Half Closed, TCP Time Wait, and Risk values to more appropriately fit the needs of your organization's network security requirements.

Strata Cloud Manager: Device Quarantine List for Cloud Managed NGFWs

September 23, 2025
Supported for: NGFW (Managed by Strata Cloud Manager)
You can now manage device quarantine lists for NGFWs acting as GlobalProtect portals and gateways directly through Strata Cloud Manager. This capability enables you to block specific devices by adding their corresponding device information to a quarantine list while using Strata Cloud Manager as your primary management interface.
When you access the device quarantine list functionality in Strata Cloud Manager, you can view quarantined devices that have been flagged by Administrators.

Strata Cloud Manager: GRE Tunnel Termination

September 23, 2025
Supported for: Strata Cloud Manager
Strata Cloud Manager allows you to configure and deploy GRE (Generic Routing Encapsulation) tunnels on managed NGFW platforms to establish secure, point-to-point connectivity across untrusted networks. GRE tunnels enable you to encapsulate various network layer protocols inside virtual point-to-point links, allowing you to extend your network topology across geographically distributed locations.

Strata Cloud Manager: Hardware Security Module (HSM) Integration

September 24, 2025
Supported for: Strata Cloud Manager
You can now set up a Hardware Security Module (HSM) to generate, store, and manage digital keys through Strata Cloud Manager. An HSM is a physical appliance that, once connected, provides both physical and logical protection of these cryptographic keys. By utilizing the management options in Strata Cloud Manager, you can specify HSM servers that use one or more of the following providers: SafeNet Network, nCipher nCshield Connect, or Thales CipherTrust Manager.

Strata Cloud Manager: Log Forwarding Card (LFC) Support

September 24, 2025
Supported for: Strata Cloud Manager
You can now configure a PA-7000 Series Firewall Log Forwarding Card (LFC) using Strata Cloud Manager. The LFC is a physical, high-performance slot card that forwards all dataplane logs from the firewall to an external logging system. Once installed, you can choose to configure either interface LFC 1/1 or interface LFC 1/9, as well as IPv4 or IPv6 settings, depending on your deployment needs.

Strata Cloud Manager: Master Key Management for NGFWs

September 23, 2025
Supported for: NGFW (Managed by Strata Cloud Manager)
Now you can deploy a custom master key in Strata Cloud Manager™ to replace the default master key on your next-generation firewalls (NGFWs), adding an extra layer of protection for your sensitive data.
When you deploy a new master key, Strata Cloud Manager re-encrypts all key material to strengthen your security posture. You can define a custom lifetime for the master key (from 1 to 18, 250 days) and set reminder notifications (1 to 365 days before expiration). This allows you to rotate keys on schedule to help minimize disruption. Regular rotation is a best practice for cryptographic key management and helps you meet compliance requirements.
The Deploy Master Key feature supports both standalone and high-availability (HA) firewall configurations, with built-in validations to ensure secure key deployment.

Strata Cloud Manager: Netflow Monitoring

September 23, 2025
Supported for: NGFW (Managed by Strata Cloud Manager)
Strata Cloud Manager™ now provides the ability to configure and deploy NetFlow on managed next-generation firewall (NGFW) platforms. This new capability allows you to export detailed IP traffic statistics to a NetFlow collector, providing valuable data for security analysis, troubleshooting, and performance optimization. You can create server profiles to define collector destinations and export parameters, with support for Layer 3, Layer 2, virtual wire, tap, VLAN, loopback, and tunnel interfaces. This feature supports NetFlow Version 9 and both standard and enterprise templates.

Strata Cloud Manager: Policy Application Dependency Management

September 23, 2025
Strata Cloud Manager (SCM) now provides users the ability to view all dependent applications associated with a selected application while creating Security Policy Rules. This makes it easier to build security policies without unintentionally excluding required dependent applications. To view the dependent applications, access the relevant Security Policy Rule, and from the Application / Service menu, open the Application dropdown and select the Dependent Applications button. This opens the Dependent Applications pane, which displays all dependent apps contained within the selected application it relies on, as well as the rules they are used in. Additionally, you can also add these dependencies directly to your current rule or an existing rule.

Strata Cloud Manager: QoS Support

September 23, 2025
QoS enables you to prioritize and manage network traffic to ensure critical applications and services receive the necessary bandwidth and resources.
You can now configure QoS on the next-generation firewalls in Strata™ Cloud Manager. Enable QoS capabilities on NGFWs through the following configuration components for traffic prioritization and bandwidth management:
QoS Profile
  • Defines traffic classification rules and bandwidth allocation parameters
  • Establishes service level priorities for different application types
  • Configures queue management and traffic shaping policy rules
QoS Policy
  • Applies QoS Profiles to specific traffic flows based on defined criteria
  • Implements rule-based traffic classification and prioritization
  • Enables granular control over application and user-based QoS enforcement
QoS Egress Interface Configuration
  • Designates network interfaces for QoS policy rule enforcement
  • Configures outbound traffic shaping and bandwidth limits
  • Ensures proper queue management at interface level
By implementing QoS, you can improve overall network efficiency, enhance user experience for critical services, and align network resource allocation with your organization's priorities. With QoS, you can maximize the value of your existing network infrastructure while ensuring that your most important traffic always gets through, even during periods of high network utilization.

Strata Cloud Manager: Response Page Customization

September 23, 2025
Supported for:
  • NGFW (Managed by Strata Cloud Manager)
  • Prisma Access (Managed by Strata Cloud Manager)
Strata Cloud Manager™ now offers expanded response page customization, allowing you to tailor additional page types for a more consistent and user-friendly experience. These pages appear during authentication challenges, security restrictions, or informational notices, helping users understand what is happening while maintaining your organization’s branding.
Newly supported customizable pages include:
  • GlobalProtect: Customize portal login pages, welcome screens, and help pages that guide users through the connection process.
  • Authentication Services: Modify Multi-Factor Authentication (MFA) login pages and SAML authentication error pages to provide clear guidance during authentication challenges.
  • SSL Decryption: Customize notification pages to inform users about traffic inspection policies and certificate errors.

Flexible Software Upgrades for NGFWs

September 23, 2025
Supported on:
  • Strata Cloud Manager
  • NGFW (Managed by Panorama)
Administrators can now skip reboots during PAN-OS software upgrades for cloud managed NGFWs, allowing you to decouple software installation from the reboot process and providing granular control over when your NGFWs restart after receiving software updates. You can schedule software downloads and installations to complete during designated maintenance windows while deferring the actual reboot to a time that minimizes operational impact on your network services. This separation of upgrade phases prevents unexpected downtime during critical business hours and allows you to coordinate reboots across multiple firewalls in your environment.
You configure this feature through the Software Upgrade Scheduler and configure the update to work with the needs of your business and network.

Strata Cloud Manager: Management Features

September 23, 2025
Strata Cloud Manager now provides comprehensive IPv6 capabilities to help you manage your network infrastructure in dual-stack environments. This enhancement brings IPv6 parity with PAN-OS management capabilities, allowing you to configure and manage both IPv4 and IPv6 addressing across your NGFW deployments through the cloud management platform.
You can now configure IPv6 addressing for management interfaces including dedicated management ports and auxiliary interfaces. The management interface configuration supports both static IPv6 addressing and dynamic DHCPv6 client options with configurable parameters such as non-temporary address options, temporary address options, rapid commit, and DUID type selection. For auxiliary interfaces, you can specify IPv6 addresses with prefix lengths and configure default IPv6 gateways to ensure proper routing in your management network.

Strata Cloud Manager: IPv6 Service Route Configuration

September 23, 2025
Supported for: Strata Cloud Manager
You can configure a data port (a regular interface) to access external services, such as DNS servers, external authentication servers, Palo Alto Networks® services such as software, URL updates, licenses and AutoFocus. Strata Cloud Manager now supports configuring and deploying IPv6 service routes (in addition to IPv4 service routes) for all managed NGFW platforms.

Stata Cloud Manager: Management Service Route

September 23, 2025
Supported for: Strata Cloud Manager
The firewall uses the management (MGT) interface by default to access external services, such as DNS servers, external authentication servers, Palo Alto Networks® services such as software, URL updates, licenses and AutoFocus. An alternative to using the MGT interface is to configure a data port (a regular interface) to access these services. A service route is the path from the interface to the service on a server. Strata Cloud Manager allows you to customize service routes for various services or Use Management Interface for all services.

Strata Cloud Manager: NDP Proxy

September 23, 2025
Supported for: Strata Cloud Manager
Strata Cloud Manager now supports Neighbor Discovery Protocol (NDP) Proxy to simplify address resolution in IPv6 environments. This feature allows the firewall to respond to link-layer address requests on behalf of devices behind it, performing a similar function to ARP for IPv4. Configuring NDP Proxy is required when you enable IPv6-to-IPv6 Network Prefix Translation (NPTv6). Key capabilities of NDP Proxy include:
  • Simplified Address Resolution: The firewall automatically responds to Neighbor Solicitation messages for configured IPv6 prefixes.
  • Selective Proxying: You can specify addresses for which the firewall will not act as a proxy (negated addresses).

Strata Cloud Manager: NGFW Alerts in September

September 22, 2025
Here are the NGFW alerts introduced in September 2025:
  • Invalid or Missing Device Certificate for CDSS
  • Device Certificate Auto-Renewal May Fail — PAN-OS Upgrade Required
Health alerts actively monitor the health and performance of your platform in real time. This approach helps in identifying issues, predicting potential problems, and implementing remediation actions to ensure your devices function optimally. Here are some key aspects:
  • Monitoring Metrics: Continuously monitor various metrics from the NGFWs, including CPU utilization, memory usage, disk space, network throughput, and other relevant performance indicators.
  • Anomaly Detection: Generate alerts that dynamically adjust based on the metric's historical value and your usage trends.
  • Predictive Analysis: Leverage historical data and patterns to predict when thresholds might be exceeded or specific events may occur. This helps forecast potential issues before they escalate.