| Where Can I Use This? | What Do I Need? |
Before configuring Advanced Device-ID, you must have an active
Device Security subscription. You don't need any additional license for
Advanced Device-ID. Add the Device Security license to the firewall
where you want to enable Advanced Device-ID for Security policy rules. By
default, both Device Security and PAN-OS start in legacy
Device-ID mode, even after upgrading to PAN-OS 12.1. If you
have not previously used Device-ID, you can upgrade to
Advanced Device-ID. If you have an existing legacy Device-ID
configuration, you must enable Hybrid Mode before upgrading to
Advanced Device-ID.
When using Advanced Device-ID, you must configure the Device-ID
objects in Device Security. Unlike legacy Device-ID, you can’t create
Advanced Device-ID objects on the firewall or in Panorama. You can
create up to 4,000 Advanced Device-ID objects.
When your firewalls receive traffic from overlapping IP address blocks,
use multi-vsys support for Device-ID so that each vsys applies policy
against the correct device. Multi-vsys support assigns device context segments
to firewalls and vsys, and their traffic gets scoped to the corresponding segment.
The segment identifier helps scope device context to the correct firewall or vsys,
preventing merged baselines when the same address appears in more than one part of
your network.