NGFW clusters support multiple virtual systems.
Multi-VSYS support for PA-7500 Series firewalls in clustering mode enables you to
efficiently use your firewalls with large virtual system capacity. This feature
brings parity with standalone systems, allowing you to configure up to 25 virtual
systems on your clustered PA-7500 Series firewalls. You can assign
virtual systems at the interface level,
including support for MC-LAG and Aggregate Ethernet interfaces. This capability is
crucial for customers migrating from PA-7050 NGFWs in HA active/passive or
active/active configurations to PA-7500 clustering, as it allows you to carry over
your existing multi-VSYS configurations.
The feature supports per-VSYS policies, including security rules, NAT rules, and
policy-based forwarding. It also enables role-based administration, local user
databases, and services such as syslog and SNMP for each virtual system. By
implementing multi-VSYS in NGFW clustering mode, you can efficiently separate
traffic and management functionality per department. This feature is particularly
valuable to large enterprises, service providers, and organizations across various
vertical markets that require robust network segmentation and multi-tenancy
capabilities in their high-performance firewall deployments.