Palo Alto Networks Next Generation Firewalls
Partners — Palo Alto Networks Next Generation Firewalls

Palo Alto Networks Next Generation Firewalls security platform lets you safely enable applications through granular visibility and policy based control, and then prevent both known and unknown threats from moving laterally (VM to VM), thereby reducing risk and improving your security efficacy overall. Plus, Palo Alto Networks Next Generation Firewalls centralized management and native automation features ensure that security keeps pace with your business. Today’s cyberthreats commonly compromise an individual workstation, or user, and then move across the network, looking for a target. Within your virtual network, cyberthreats move laterally from VM to VM in an east — west manner, placing your mission—critical applications and data at risk. Exerting application—level control using Zero Trust principles in between VMs will reduce the threat footprint while applying policies to block both known and unknown threats. Security best practices dictate that your mission—critical applications and data should be isolated in secure segments using Zero Trust (“never trust, always verify”) principles as a means of controlling access.

Virtualization is fueling an upheaval in today’s datacenters, resulting in architectures that are oftentimes a mix of private and public cloud computing environments. The benefits of cloud computing are well—known, so too are the security challenges, exemplified by recent high—profile security incidents. Just as an attack or compromise within your physical data center is a significant incident, the impact of a compromise in your virtualized environment is amplified because your workloads, some of which use varied trust levels, and the associated data are centralized, without any security barriers in between to keep them segmented. If your virtual environment is compromised, the attacker has access to your entire virtualized environment. The term “normal business hours” no longer applies. To keep pace with the online—all—the—time world, virtualization technology allows your applications and data to be deployed across public, private, and hybrid cloud—computing environments to more easily adapt and support your business demands.

Palo Alto Networks Next Generation Firewalls – VM Series

Palo Alto Networks Next Generation Firewalls VM—Series is a virtualized form factor of Palo Alto Networks next—generation firewall that can be deployed in a range of private and public cloud computing environments based on technologies from VMware, Amazon Web Services, Microsoft, Citrix and KVM. Palo Alto Networks Virtual Next Generation Firewalls VM—Series natively analyzes all traffic in a single pass to determine the application identity, the content within, and the user identity. These core elements of your business can then be used as integral components of your security policy, enabling you to improve your security efficacy through a positive control model and reduce your incident response time though complete visibility into applications across all ports. In both private and public cloud environments, the Palo Alto Networks Next Generation Firewalls VM—Series can be deployed as a perimeter gateway, an IPsec VPN termination point, and a segmentation gateway, protecting your workloads with application enablement and threat prevention policies.

Securing The Public And Private Clouds

Defined as an environment in which you are responsible for the management of all aspects of the virtualization, hardware, compute, networking and security, a private cloud is often considered to be synonymous with your data center, and in fact, many data centers are 100 percent virtualized using VMware, Microsoft Hyper V, KVM or other private cloud technologies. The Palo Alto Networks Next Generation Firewalls VM—Series allows you to protect your private cloud infrastructure using application enablement policies while simultaneously preventing known and unknown threats. The Palo Alto Networks VM—Series supports the following private cloud environments: VMware ESXi and NSX, Citrix NetScaler SDX, Microsoft Hyper V and KVM/OpenStack. In a public cloud, ensuring your applications and data are kept safe from attackers is your responsibility, and that is where the Palo Alto Networks Next Generation Firewalls VM—Series can help. The Palo Alto Networks Next Generation Firewalls VM—Series protects your public cloud infrastructure using application enablement policies while simultaneously preventing known and unknown threats.

Palo Alto Networks Next Generation Firewalls

Allowing you to define granular, context—aware policy control, Palo Alto Networks Aperture gives you the ability to drive enforcement, and the quarantine of users and data, as soon as a violation occurs. This enables you to quickly and easily satisfy data risk compliance requirements, such as PCI and PII, while still maintaining the benefits of cloud—based applications. The use of SaaS applications is creating new risks and gaps in security visibility for malware propagation, data leakage and regulatory non—compliance.

Palo Alto Networks Aperture delivers complete visibility and granular enforcement across all user, folder and file activity within sanctioned SaaS applications, providing detailed analysis and analytics on usage without requiring any additional hardware, software or network changes. Palo Alto Networks Aperture provides complete visibility across all user, folder and file activity, providing detailed analysis that helps you transition from a position of speculation to one of knowing exactly what’s happening at any given point in time. This gives you the ability to view deep analytics into day—to—day usage, which enables you to quickly determine if there are any data risk or compliance related policy violations.

Preventing successful cyber attacks — the end goal of security is to enable your operations to flourish and keep your organization out of the headlines associated with cyber breaches. This means reducing the likelihood of a successful attack. By focusing on preventing successful attacks, the Palo Alto Networks next—generation security platform reduces cybersecurity risk so that it is manageable and quantifiable, allowing organizations to compartmentalize their biggest threats and focus on business operations.

The Palo Alto Networks next—generation security platform protects your digital way of life by safely enabling applications and preventing known and unknown threats across the network, cloud, and endpoints. The native integration of the platform delivers a prevention architecture that can provide superior security at lower total cost of ownership. Palo Alto Networks Panorama network security management lets you view all firewall traffic, manage device configuration, push global policies, and generate reports on patterns or incidents — all from one central location. Palo Alto Networks Panorama network security management provides static rules and dynamic security updates in an ever—changing threat landscape.

With a few clicks, you gain visibility into the application bandwidth and session consumption, the associated threats, as well as the source and destination of the application traffic. With this knowledge, you can proactively align application usage with your business requirements. Palo Alto Networks malware protections reduce the number of available attack vectors by terminating malware downloads. The blocked malware name, malicious URL or application, and the victim user are logged within the UI, so you have the contextual information needed to apply additional policies, if necessary.

Palo Alto Networks IPS, available within the threat prevention subscription, prevents exploits at the network level, using targeted vulnerability and exploit kit based signatures to thwart multiple variations of exploits and a wide variety of exploit kits. The Palo Alto Networks skilled threat research team, whose job it is to continuously investigate and reverse engineer network and application vulnerabilities, creates these protections and automatically pushes them to all subscribed devices on a weekly and emergency basis, fortifying your network against the latest exploits.

Defined as an environment in which you are responsible for the management of all aspects of the virtualization, hardware, compute, networking and security, a private cloud is often considered to be synonymous with your data center, and in fact, many data centers are 100 percent virtualized using VMware, Microsoft Hyper V, KVM or other private cloud technologies. The Palo Alto Networks VM—Series allows you to protect your private cloud infrastructure using application enablement policies while simultaneously preventing known and unknown threats.

The Palo Alto Networks VM—Series supports the following private cloud environments: VMware ESXi and NSX, Citrix NetScaler SDX, Microsoft Hyper V and KVM/OpenStack. In a public cloud, ensuring your applications and data are kept safe from attackers is your responsibility, and that is where the Palo Alto Networks VM—Series can help. The Palo Alto Networks VM—Series protects your public cloud infrastructure using application enablement policies while simultaneously preventing known and unknown threats. The Palo Alto Networks VM—Series supports the following public cloud environments: VMware vCloud Air, Amazon Web Services (AWS) and Microsoft Azure.