PAN-OS Shield
Focus
Focus
Next-Generation Firewall

PAN-OS Shield

Table of Contents

PAN-OS Shield

Enable PAN-OS Shield to protect control traffic destined for the firewall management plane against vulnerability exploits.
Where Can I Use This?What Do I Need?
  • NGFW
  • PAN-OS 12.2.2 and later
PAN-OS Shield provides vulnerability protection for firewalls with GlobalProtect gateway or portal. When you enable PAN-OS Shield, the firewall scans inbound control traffic using threat prevention signatures and takes action against detected exploits before they reach the management plane. This protects PAN-OS services from vulnerabilities—including critical exploits such as those targeting privilege escalation after initial compromise—by inspecting traffic at the data plane before it is forwarded to management plane processes.
PAN-OS Shield requires PAN-OS 12.2.2 or a later release. An Advanced Threat Prevention license provides signatures through regular content packages, but the license is not strictly required—signatures are also delivered through application-only content updates.
You can enable PAN-OS Shield without GlobalProtect gateway or portal configured, but the feature doesn't protect anything until GlobalProtect control traffic is present.
PAN-OS Shield operates through a dedicated internal virtual system (panos-shield-vsys) that the firewall creates automatically when you enable the feature. This internal vsys hosts a vulnerability protection profile and a security policy that are delivered and updated through content packages. You don't need to configure multi-vsys mode or allocate additional vsys licenses—the internal vsys is created independently of your licensed vsys capacity.
The vulnerability protection profile and security policy that PAN-OS Shield uses are read-only—they are delivered through content updates and you cannot modify them directly. However, you can add threat exceptions to override the action for specific threat IDs if you encounter false positives that impact your environment. When a signature triggers, the firewall generates a threat log with the matched threat ID, action taken, and relevant session details.
PAN-OS Shield is disabled by default. After you enable or disable the feature, a commit and reboot is required for the change to take effect. If you disable PAN-OS Shield, a confirmation warning explains the security implications of removing the protection.
When PAN-OS Shield is enabled, a read-only vulnerability protection profile appears under ObjectsPAN-OS ShieldVulnerability Protection. You can add threat exceptions to this profile to change the action for specific threat IDs.