Link the Cloud NGFW to Palo Alto Networks Management
Table of Contents
Expand all | Collapse all
-
- About Cloud NGFW for AWS
- Getting Started from the AWS Marketplace
- Register Your Cloud NGFW Tenant with a Palo Alto Networks Support Account
- Cloud NGFW for AWS Pricing
- Cloud NGFW Credit Distribution and Management
- Cloud NGFW for AWS Free Trial
- Cloud NGFW for AWS Limits and Quotas
- Subscribe to Cloud NGFW for AWS
- Locate Your Cloud NGFW for AWS Serial Number
- Cross-Account Role CFT Permissions for Cloud NGFW
- Invite Users to Cloud NGFW for AWS
- Manage Cloud NGFW for AWS Users
- Deploy Cloud NGFW for AWS with the AWS Firewall Manager
- Enable Programmatic Access
- Terraform Support for Cloud NGFW AWS
- Provision Cloud NGFW Resources to your AWS CFT
- Configure Automated Account Onboarding
- Usage Explorer
- Create a Support Case
- Cloud NGFW for AWS Certifications
- Cloud NGFW for AWS Privacy and Data Protection
-
-
- Prepare for Panorama Integration
- Link the Cloud NGFW to Palo Alto Networks Management
- Unlink the Cloud NGFW from Palo Alto Networks Management
- Associate a Linked Panorama to the Cloud NGFW Resource
- Use Panorama for Cloud NGFW Policy Management
- View Cloud NGFW Logs and Activity in Panorama
- View Cloud NGFW Logs in Strata Logging Service
- Tag Based Policies
- Configure Zone-based Policy Rules
- Enterprise Data Loss Prevention (E-DLP) Integration with Cloud NGFW for AWS
-
- Strata Cloud Manager Policy Management
Link the Cloud NGFW to Palo Alto Networks Management
Link Cloud NGFW to Panorama
You have two options for linking:
- Link the Cloud NGFW to Palo Alto Networks with Panorama for policy management only.
- Link the Cloud NGFW tenant with Panorama for policy management and Strata Logging Service for log management.
Consider the following when linking Cloud NGFW to Palo Alto Networks management:
- Be subscribed to the Cloud NGFW service using AWS Marketplace to integrate Cloud NGFW with Panorama. After linking your Cloud NGFW tenant to Panorama, you can view the tenants and resources, along with their status, in the Panorama console under the AWS plugin.
- See Unlink the Cloud NGFW from Palo Alto Networks Management to remove an existing Panorama virtual appliance from the Cloud NGFW resource. If you're using AWS Firewall Manager, you can't unlink Panorama from your Cloud NGFW resource. See Create a support case to unlink Cloud NGFW from Panorama when using AWS Firewall Manager for additional information.
- You must unlink Panorama and relink it if you want to use Strata Logging Service with Panorama.
To link your Cloud NGFW tenant to Panorama using the Cloud NGFW:
- Select Integrations.In the Integrations page, click Add Panorama.If you're using a tenant linked to Panorama that was created using the AWS Firewall Manager you can't unlink the Cloud NGFW resource.In the Add Panorama screen, enter a Link Name. Select the Primary Panorama Serial Number from the drop-down. For HA environments, select the Secondary Panorama Serial Number from the drop-down.This screen displays two different icons describing the state of the Panorama license; a Panorama linked to Strata Logging Service, and a Panorama that isn't linked to Strata Logging Service. The image below illustrates these icons:If you select a Panorama serial number that isn't linked to Strata Logging Service, you must specify an option to either cancel the linking process, in which case you agree to procure a Strata Logging Service license and associate it with your Panorama appliance, or you agree to continue using Panorama for policy management only:If you select a Panorama license that is already connected to a Strata Logging Service, you're asked to Confirm the association before continuing with the integration process.After selecting the Panorama license, click Continue. The Integrations page displays the Link ID and the linked Panorama Serial Number:The Cloud NGFW tenant automatically pulls the Strata Logging Service information from Panorama. If you don't plan to use Strata Logging Service, you can send logs to AWS. For more information, see Configure Logging for Cloud NGFW on AWS.The Integrations page displays the Link ID and the linked Panorama Serial Number.For additional information, including the Strata Logging Service ID associated with the linked Panorama, click the Link ID in the Integrations page. The Link Panorama window appears:
Unsubscribe a Cloud NGFW Tenant from AWS Marketplace
To unsubscribe a Cloud NGFW tenant from AWS Marketplace:- Sign in to the AWS Management Console.Go to the My Subscriptions page.Select the subscription for the product that you want to cancel.Choose Cancel subscription. After canceling your subscription, you can't launch your application.For more information, see Cancel your subscription.
Create a Support Case to Unlink Panorama from Cloud NGFW When Using AWS Firewall Manager
If you're using AWS Firewall Manager and linked a Cloud NGFW resource to Panorama, you must contact Palo Alto Networks Support to unlink the Cloud NGFW resource from Panorama. When creating the support case, you may be asked to provide additional information, like the AWS account ID, and the tenant ID for the resource.To create a support case using the Cloud NGFW console:- Locate your AWS Account ID. Select AWS Accounts.If required, use the Panorama console to determine additional information for the support case, like the tenant ID, or the Panorama serial number.Locate the Panorama serial number using the Dashboard:Locate the Tenant ID for the Cloud NGFW resource:On the Overview page in the Cloud NGFW console, click Create a case.