Palo Alto Networks Firewall
runZero pulls data from your Palo Alto Networks Firewalls through the PAN-OS XML API to add network visibility and context, and to improve reporting.
Getting started
To set up the Palo Alto Networks Firewall integration, you’ll need to:
- Create or obtain API Keys to use with the Palo Alto Networks Firewall XML API.
- Add the Palo Alto Networks Firewall API key in runZero.
- Synchronize your Palo Alto Networks Firewall data.
Requirements
- Before you set up the Palo Alto Networks Firewall integration, make sure you have an API Key for the PAN-OS XML API.
- To use trusted authentication, scan your Palo Alto Networks Firewall with a runZero Explorer before you add the credential (optional).
Step 1: Add the Palo Alto Networks Firewall credential to runZero
- Go to the Add credential page in runZero. Provide a name for the credentials, like PAN-OS Firewall.
- Choose Palo Alto Networks Firewall API Key from the list of credential types.
- Fill in these fields:
- Palo Alto Networks API key - The API key to use with the Palo Alto Networks Firewall integration. First enable the XML API by following this guide: https://docs.paloaltonetworks.com/ngfw/api/api-authentication-and-security/pan-os-api-authentication. Then generate the API key by following this guide: https://docs.paloaltonetworks.com/ngfw/api/api-authentication-and-security/generate-api-key
- Palo Alto Networks insecure - Set this to
Yesto attempt authentication without a verified thumbprint. - Palo Alto Networks thumbprints (optional) - A set of
IP[:port]=SHA256:B64HASHorhostname.domain.tld=SHA256:B64HASHpairs to trust for authentication.- To get the TLS thumbprint, scan your Palo Alto Networks firewalls with runZero. The PAN API thumbprints service attribute report lists all previously seen thumbprints.
- CIDR allow list - The IP addresses allowed to receive this API Key.
- To let all other organizations use this credential, select the Make this a global credential option. Otherwise, you can grant access per organization.
- Save the credential.
Step 2: Synchronize Palo Alto Networks Firewall data
Enable Palo Alto Networks Firewall synchronization as part of a scan task. Any task that scans your Palo Alto Networks Firewalls can synchronize PAN-OS data.
On the Credentials tab of the scan setup, use the toggle switch to enable the Palo Alto Networks credentials you want.
When the scan runs, the Explorer uses the credentials to authenticate with any Palo Alto Networks Firewall it finds that the credentials are configured to trust. runZero imports the data it discovers about the firewalls automatically and merges it with the other information it finds by scanning.
Step 3: View Palo Alto Networks Firewall assets
To filter to Palo Alto Networks Firewall assets, run this query:
View all Palo Alto Networks Firewall assets:
attribute:pan.api.thumbprint
Click an asset to see its attributes. runZero shows the attributes returned by Palo Alto Networks.