Configure Palo Alto Networks v10.1

Configure Guardian firewall integration with the Palo Alto Networks v10.1 firewall.

Make sure that you have administrator privileges.
Starting with version 10.0, PAN-OS provides a REST application programming interface (API). The Guardian integration that relies on this new API supports the same features as the previous Palo Alto integration, plus these:
  • Commit by user: Commits the current changes required by the user, which are represented by the credentials used for the API. Global commits are no longer performed
  • Dynamic Access Groups for Node Blocking: Dynamic Access Group references a tag, which is then assigned to a new internet protocol (IP) address for objects that are created on the firewall. This will automatically apply the global Guardian denylist rule to each new address without modifying the firewall ruleset
Note: This firewall integration supports IPv6 addresses.
  1. In the top navigation bar, select Administration icon - which looks like a gear cog
    The administration page opens.
  2. In the Settings section, select Firewall integration.
    The Firewall integration page opens.
  3. In the top right section, select +
    A dialog shows.
  4. From the Choose firewall dropdown, select Palo Alto Networks v10.1+.
    A dialog shows.
  5. If it is not populated already, in the Host (CA-Emitted TLS Certificate) field, enter the host IP address.

  6. Optional: In the Virtual System name (optional) field, enter a name.
  7. In the User field, enter your user name.
  8. In the Password field, enter your password.
  9. Optional: If necessary, in the Options section, select one or more of these options:
    1. For Firewall rules strategy, select one of these options:
      • Block active alerts
      • Block unlearned
    2. Select Enable nodes blocking.
    3. Select Enable links blocking.
    4. Select Enable session kill. Then select the specific alert type(s).
    5. Select Keep on selecting sessions.
    6. Select Policies are sent as enabled.
  10. Select Save.
The firewall integration has been configured.