Configure Palo Alto Networks v10.1

Configure Guardian firewall integration with the Palo Alto Networks v10.1 firewall.

Before you begin

Make sure that you have administrator privileges.

About this task

Starting with version 10.0, PAN-OS provides a REST application programming interface (API). The Guardian integration that relies on this new API supports the same features as the previous Palo Alto integration, plus these:
  • Commit by user: Commits the current changes required by the user, which are represented by the credentials used for the API. Global commits are no longer performed
  • Dynamic Access Groups for Node Blocking: Dynamic Access Group references a tag, which is then assigned to a new internet protocol (IP) address for objects that are created on the firewall. This will automatically apply the global Guardian denylist rule to each new address without modifying the firewall ruleset
Note:
This firewall integration supports IPv6 addresses.

Procedure

  1. In the top navigation bar, select Administration icon - which looks like a gear cog
    The administration page opens.
  2. In the Settings section, select Firewall integration.
    The Firewall integration page opens.
  3. In the top right section, select +
    A dialog shows.
  4. From the Choose firewall dropdown, select Palo Alto Networks v10.1+.
    A dialog shows.
  5. If it is not populated already, in the Host (CA-Emitted TLS Certificate) field, enter the host IP address.
    Firewall configuration dialog for Palo Alto Networks v10.1 showing fields for host, virtual system name, user, and password, with options for firewall rules strategy, node and link blocking, session kill, and logging.

  6. Optional: In the Virtual System name (optional) field, enter a name.
  7. In the User field, enter your user name.
  8. In the Password field, enter your password.
  9. Optional: If necessary, in the Options section, select one or more of these options:
    1. For Firewall rules strategy, select a strategy.
      • Block active alerts: Guardian creates link-blocking policies when specific alerts are triggered. Guardian generates rules based on real-time detection events, not on node learning state. For more details, see Alert-based firewall rule creation.
      • Block unlearned: Guardian creates block policies for unlearned nodes and links. This is the default behavior.

      If you selected Block active alerts, select one or more alert types that should trigger firewall rule creation:

      • SIGN:MITM
      • SIGN:SCADA-INJECTION
      • SIGN:PACKET-RULE
      • SIGN:OUTBOUND-CONNECTIONS
      • SIGN:MALWARE-DETECTED
      • SIGN:MULTIPLE-ACCESS-DENIED
      • SIGN:MULTIPLE-UNSUCCESSFUL-LOGINS
      • SIGN:NETWORK-SCAN

      If SIGN:PACKET-RULE is selected, enter a Severity threshold value and a Risk threshold value. Guardian creates a firewall rule for SIGN:PACKET-RULE alerts only when both the alert severity and the risk score meet or exceed the configured thresholds.

    2. Select Enable nodes blocking.
    3. Select Enable links blocking.
    4. Select Enable session kill. Then select the specific alert type(s).
    5. Select Keep on selecting sessions.
    6. Select Policies are sent as enabled.
  10. Select Save.

Results

The firewall integration has been configured.