At this release, you can use Strata Cloud Manager to globally apply a security
rule to the Cloud NGFW resources comprising a folder. All NAT policy rules
(including DNS proxy) are applied using the Azure portal.
You can optionally forward logs to Azure, which
requires you to configure the Azure portal.
Important Considerations
When using SCM for Cloud NGFW as a policy management, consider the following:
- When you first connect to SCM, Cloud NGFW resources (for example, the
resource ID) may fail to display. These resources will appear after a
few moments if there are no underlying connection issues.
- Best practices for Cloud NGFW SCM policy management differ from those
using Panorama policy management with your Cloud NGFW resource. For
example, some pass-through traffic in a Panorama managed environment may
be dropped in an SCM managed Cloud NGFW resource.
- X-Forwarded-For (XFF) functionality isn't supported in an SCM policy
management for your Cloud NGFW resource.
- Cloud certificate isn't supported.
- Data loss prevention (DLP) isn't supported.
- When configuring security rules for your SCM-managed Cloud NGFW
resource, you must specify ANY for the security rule. However, from/to
zone appears as public/private in the Strata Logging Service.
- User-ID and tag-based policy rules are not yet supported.
- Operational visibility and metrics are not supported.
To use SCM for Cloud NGFW policy management: