Link the Cloud NGFW to Palo Alto Networks Management
Table of Contents
Expand all | Collapse all
-
- About Cloud NGFW for AWS
- Getting Started from the AWS Marketplace
- Register Your Cloud NGFW Tenant with a Palo Alto Networks Support Account
- Cloud NGFW for AWS Pricing
- Cloud NGFW Credit Distribution and Management
- Link Your PAYG Account with Cloud NGFW Credits
- Cloud NGFW for AWS Free Trial
- Cloud NGFW for AWS Limits and Quotas
- Subscribe to Cloud NGFW for AWS
- Locate Your Cloud NGFW for AWS Serial Number
- Cross-Account Role CFT Permissions for Cloud NGFW
- Invite Users to Cloud NGFW for AWS
- Manage Cloud NGFW for AWS Users
- Deploy Cloud NGFW for AWS with the AWS Firewall Manager
- Enable Programmatic Access
- Terraform Support for Cloud NGFW AWS
- Provision Cloud NGFW Resources to your AWS CFT
- Configure Automated Account Onboarding
- Usage Explorer
- Create a Support Case
-
-
- Prepare for Panorama Integration
- Link the Cloud NGFW to Palo Alto Networks Management
- Unlink the Cloud NGFW from Palo Alto Networks Management
- Associate a Linked Panorama to the Cloud NGFW Resource
- Use Panorama for Cloud NGFW Policy Management
- View Cloud NGFW Logs and Activity in Panorama
- View Cloud NGFW Logs in Strata Logging Service
- Tag Based Policies
- Enterprise Data Loss Prevention (E-DLP) Integration with Cloud NGFW for AWS
-
- Strata Cloud Manager Policy Management
Link the Cloud NGFW to Palo Alto Networks Management
Link Cloud NGFW to Panorama
You have two options for linking:
- Link the Cloud NGFW to Palo Alto Networks with Panorama for policy management only.
- Link the Cloud NGFW tenant with Panorama for policy management and Strata Logging Service for log management.
You must be subscribed to the Cloud NGFW service using
AWS Marketplace to integrate Cloud NGFW with Panorama. After linking your Cloud NGFW
tenant to Panorama, you can view the tenants and resources, along with their status,
in the Panorama console under the AWS plugin.
See Unlink the Cloud NGFW from Palo Alto Networks
Management to remove an existing Panorama virtual appliance from the
Cloud NGFW resource. If you're using AWS Firewall Manager, you can't unlink Panorama
from your Cloud NGFW resource. See Create a support case to unlink Cloud NGFW from Panorama when
using AWS Firewall Manager for additional information.
To link your Cloud NGFW tenant to Panorama using the Cloud NGFW:
- SelectIntegrations.
- In theIntegrationspage, clickAdd Panorama.If you're using a tenant linked to Panorama that was created using the AWS Firewall Manager you can't unlink the Cloud NGFW resource.
- In theAdd Panoramascreen, enter aLink Name. Select thePrimary Panorama Serial Numberfrom the drop-down. For HA environments, select theSecondary Panorama Serial Numberfrom the drop-down.This screen displays two different icons describing the state of the Panorama license; a Panorama linked to Strata Logging Service, and a Panorama that isn't linked to Strata Logging Service. The image below illustrates these icons:If you select a Panorama serial number that isn't linked to Strata Logging Service, you must specify an option to either cancel the linking process, in which case you agree to procure a Strata Logging Service license and associate it with your Panorama appliance, or you agree to continue using Panorama for policy management only:If you select a Panorama license that is already connected to a Strata Logging Service, you're asked toConfirmthe association before continuing with the integration process.After selecting the Panorama license, clickContinue. TheIntegrationspage displays theLink IDand the linkedPanorama Serial Number:The Cloud NGFW tenant automatically pulls the Strata Logging Service information from Panorama. If you don't plan to use Strata Logging Service, you can send logs to AWS. For more information, see Configure Logging for Cloud NGFW on AWS.TheIntegrationspage displays theLink IDand the linkedPanorama Serial Number.For additional information, including the Strata Logging Service ID associated with the linked Panorama, click theLink IDin theIntegrationspage. TheLink Panoramawindow appears:
Unsubscribe a Cloud NGFW Tenant from AWS Marketplace
To unsubscribe a Cloud NGFW tenant from AWS Marketplace:
- Sign in to the AWS Management Console.
- Go to theMy Subscriptionspage.
- Select the subscription for the product that you want to cancel.
- ChooseCancel subscription. After canceling your subscription, you can't launch your application.For more information, see Cancel your subscription.
Create a Support Case to Unlink Panorama from Cloud NGFW When Using AWS Firewall
Manager
If you're using AWS Firewall Manager and linked a Cloud NGFW resource to
Panorama, you must contact Palo Alto Networks Support to unlink the Cloud NGFW
resource from Panorama. When creating the support case, you may be asked to
provide additional information, like the AWS account ID, and the tenant ID for
the resource.
To create a support case using the Cloud NGFW console:
- Locate yourAWS Account ID. SelectAWS Accounts.
- If required, use the Panorama console to determine additional information for the support case, like the tenant ID, or the Panorama serial number.Locate thePanorama serial numberusing theDashboard:Locate theTenant IDfor the Cloud NGFW resource:
- On theOverviewpage in the Cloud NGFW console, clickCreate a case.