PAN-OS Shield
Enable PAN-OS Shield to protect control traffic destined for the firewall management
plane against vulnerability exploits.
| Where Can I Use This? | What Do I Need? |
PAN-OS Shield provides vulnerability protection for firewalls with GlobalProtect gateway
or portal. When you enable PAN-OS Shield, the firewall scans inbound control traffic
using threat prevention signatures and takes action against detected exploits before they
reach the management plane. This protects PAN-OS services from
vulnerabilities—including critical exploits such as those targeting privilege escalation
after initial compromise—by inspecting traffic at the data plane before it is forwarded
to management plane processes.
PAN-OS Shield requires PAN-OS 12.2.2 or a later release. An Advanced Threat Prevention
license provides signatures through regular content packages, but the license is not
strictly required—signatures are also delivered through application-only content
updates.
You can enable PAN-OS Shield without GlobalProtect gateway or portal configured, but
the feature doesn't protect anything until GlobalProtect control traffic is
present.
PAN-OS Shield operates through a dedicated internal virtual system
(panos-shield-vsys) that the firewall creates automatically when
you enable the feature. This internal vsys hosts a vulnerability protection profile and a
security policy that are delivered and updated through content packages. You don't need
to configure multi-vsys mode or allocate additional vsys licenses—the internal vsys is
created independently of your licensed vsys capacity.
The vulnerability protection profile and security policy that PAN-OS Shield uses are
read-only—they are delivered through content updates and you cannot modify them directly.
However, you can add threat exceptions to override the action for specific threat IDs if
you encounter false positives that impact your environment. When a signature triggers,
the firewall generates a threat log with the matched threat ID, action taken, and
relevant session details.
PAN-OS Shield is disabled by default. After you enable or disable the feature, a commit
and reboot is required for the change to take effect. If you disable PAN-OS Shield, a
confirmation warning explains the security implications of removing the protection.
When PAN-OS Shield is enabled, a read-only vulnerability protection profile appears under
. You can add threat exceptions to this profile to change the action for
specific threat IDs.