Palo Alto Networks Next Generation Firewall (PA-Series, VM-Series, CN-Series)
About the product
Next Generation Firewall (NGFW) from Palo Alto Networks is an advanced network security platform that integrates traditional firewall functions with modern security mechanisms, application identification, and identity-based access control. Palo Alto NGFW solutions are available for physical environments (PA series), public and private clouds (VM series), and Kubernetes-based container platforms (CN series). All solutions offer complete visibility and control over network traffic from layer 2 (data link) to layer 7 (application) of the ISO/OSI model.
Palo Alto NGFWs are built on a unique Single-Pass Parallel Processing (SP3) architecture that combines two key elements, Single Pass Software and Parallel Processing Hardware, to deliver low latency while analyzing applications, users, content, and threats in real time. Single Pass Software means that each packet is processed only once using all available network and security features, such as App-ID, User-ID, Device-ID, and Content-ID. Parallel Processing Hardware is the simultaneous execution of tasks such as routing, user and application identification, content inspection, and management by specialized and dedicated groups of processors. Palo’s NGFW architecture distributes traffic processing and management tasks across different groups of processors, preventing management issues during NGFW traffic processing and performance degradation during intensive administrative work.
A key component is the patented App-ID mechanism for identifying, classifying, and controlling applications in network traffic regardless of the ports, protocols, or encryption used. App-ID uses a combination of signature analysis, protocol decoding, and heuristics to classify traffic in real time.
The User-ID mechanism allows network traffic to be mapped to users regardless of their assigned IP address, enabling administrators to create security rules based on user identity regardless of their IP address.
Device ID is a mechanism for identifying and classifying devices on a network based on their characteristics and behavior, using logs collected by the firewall and analyzed by the Palo Alto IoT Security service. Analysis of metadata, protocols, and sessions leads to the creation of device profiles and device-based security policy recommendations, which increases the precision of traffic management and network protection.
Content-ID is a content inspection mechanism that analyzes processed network traffic for threats such as malware, exploits, phishing, unauthorized data transfer, and unwanted content. Content-ID operates within Single Pass Software, which minimizes the impact of content inspection on firewall performance, even with numerous security features enabled. Content-ID uses advanced methods to detect known and unknown threats, including integration with the WildFire service, which analyzes suspicious files in a SandBox environment, enables web traffic filtering based on URL categories, blocks malicious websites, and controls the transfer of files and confidential data.
Palo Alto NGFW solutions offer a range of network security features such as IDS/IPS, DNS protection, WildFire sandbox, SSL/TLS decryption, web proxy, and SD-WAN.
All versions of the Palo Alto NGFW solution can be managed individually by an administrator or through one of two central management platforms. Palo Alto Networks offers two central management solutions: Panorama, available as a physical or virtual solution, and Strata Cloud Manager (SCM), available as a Software as a Service (SaaS) solution.
Adventages of the solution
App-ID – precise identification and control of applications regardless of ports, protocols or encryption.
User-ID – access control based on user identity.
Content-ID – real-time content inspection (AV, URL Filtering, DLP, IPS).
Device ID – classification of devices based on their characteristics and behavior (IoT)
WildFire – advanced threat analysis in a sandbox environment with machine learning mechanisms.
Single-Pass Architecture – single-pass packet processing with minimal impact on performance.
Support for hybrid and multicloud environments – hardware, virtual, cloud, and container versions.
Centralized management and visibility – through the Panorama or Strata Cloud Manager platform.
Benefits of Implementation
Increased protection against zero-day and APT attacks through automatic threat analysis.
Risk reduction through granular control of applications, devices, and users.
Simplified security management in distributed environments.
Increased performance while maintaining full traffic inspection.
Easy integration with existing IT infrastructure and SIEM/SOAR systems.
Scalable security for physical, virtual, cloud, and container environments.
See other products Palo Alto Networks 17
Cortex XDR
Cortex XDR is the world's first extended threat detection and response platform that collects and integrates all security data, making it easier to block sophisticated attacks.
Palo Alto Networks Prisma Access
Palo Alto Networks Prisma Access is a comprehensive Secure Service Edge (SSE) platform that integrates advanced security features with cloud-based software-defined WAN technology (Prisma SD-WAN), delivering the Secure Access Service Edge (SASE) model.
Palo Alto Networks Prisma SDWAN
Palo Alto Networks Prisma SD-WAN is an advanced, cloud-delivered software-defined WAN solution that transforms traditional WANs into a virtualized, secure infrastructure.
Palo Alto Networks Threat Prevention (NGFW’s module)
In Palo Alto Networks solutions, IDS (Intrusion Detection System) and IPS (Intrusion Prevention System) functionalities are an integral part of the ATP (Advanced Threat Prevention) module, which extends the functionality of Palo Alto NGFW.
Palo Alto Networks NGFW Webproxy
Next Generation Firewall (NGFW) from software version 11.0 offers the ability to configure a web proxy feature that allows you to inspect and control HTTP/HTTPS traffic in one of two ways: explicit or transparent.
Palo Alto Networks Advanced DNS Security
Advanced DNS Security (ADNS) is a modern solution for Palo Alto Networks that protects against threats hidden in the DNS (Domain Name System) layer.
Palo Alto Networks SSL Decryption (build-in within PA-Series, VM-series, Prisma Access)
Palo Alto Networks SSL Decryption is an advanced feature built into Palo Alto Networks' Next Generation Firewall that enables SSL/TLS traffic decryption for threat detection, security policy enforcement, and prevention of hidden attacks.
Palo Alto Networks Enterprise DLP
Palo Alto Networks Enterprise Data Loss Prevention (DLP) is an advanced security solution that enables the detection and prevention of data leaks in network traffic.
Prisma Cloud (Cloud Security)
The Cloud Security module of Palo Alto Prisma Cloud provides security and regulatory compliance for cloud environments.
Palo Alto Networks Cortex XSOAR
Palo Alto Networks Cortex XSOAR (formerly DEMISTO) is dedicated SOAR (Security Orchestration, Automation, and Response) software that has been on the market since 2015.
Cortex XSIAM (Extended Security Intelligence and Automation Management)
The needs of SOC teams have evolved. Detecting security incidents and neutralizing them after detection takes organizations too much time.
Palo Alto Networks Advanced WildFire
Palo Alto Networks Advanced WildFire (AWF) is an advanced malware analysis and prevention solution that combines sandboxing, machine learning, and global real-time analysis to protect against known and unknown threats.
Palo Alto Xpanse
Palo Alto Networks Xpanse is an advanced ASM solution that enables automatic detection and monitoring of all your organization's Internet-facing assets, regardless of who created them or where they are located.
Palo Alto Networks CASB
The Palo Alto Networks CASB (Cloud Access Security Broker) solution is an advanced cloud security platform designed to monitor, control, and protect access to SaaS applications and other cloud services in real time.
Palo Alto Networks Secure Web Gateway
Secure Web Gateway (SWG) is an advanced security solution from Palo Alto Networks designed to protect internet and cloud traffic from modern threats.
Palo Alto Networks Prisma Access Browser
Prisma Access Browser (PAB) is an advanced web browser based on the Chromium engine, natively integrated with the Prisma Access SSE solution, designed specifically for enterprises to secure both managed and unmanaged devices.
Palo Alto ITDR
Identity-related threats and malicious insiders are currently significant attack vectors for organizations. These threats involve unauthorized access to user accounts as a result of theft or the use of weak credentials, phishing attacks, or social engineering techniques.