Firewall Features Overview
Firewall Features Overview
Firewall Features Overview
Next-Generation Firewall
Feature Overview
The face of the enterprise is changing. Attacks are constantly and automatically morphing.
New devices are proliferating rapidly and without notice. Your business needs are driving
rapid changes. Typical security products force you to react to these changes manually,
straining your resources and leaving your organization exposed.
Strata by Palo Alto Networks | ML-Powered Next-Generation Firewall Feature Overview | Whitepaper 1
The world needs a new type of firewall—one with machine learning and analytics at its core, capable
of identifying new threats, devices, and more without relying on fingerprinting or signatures. It must
continuously update the machine learning models by analyzing data using unlimited cloud computing.
It must also continuously collect telemetry and recommend policy and configuration changes to reduce
risk and reduce chances of error.
Confidently lead digital transformation with the world’s first ML-Powered Next-Generation Firewall,
proactively securing your organization. Embrace machine learning to deliver the industry’s only inline
malware and phishing prevention to stop unknown threats as they reach your network. Automatical-
ly reprogram your network with zero-delay signature updates for all other threats. Provide accurate
signatureless identification of all unmanaged internet of things (IoT) devices. Use telemetry to optimize
security policy and eliminate breaches due to misconfiguration. Adopt a consistent, integrated, and
best-in-class network security platform available in physical, virtual, containerized, and cloud-deliv-
ered form factors—all managed centrally.
Strata by Palo Alto Networks | ML-Powered Next-Generation Firewall Feature Overview | Whitepaper 2
However, the issue of user identity goes beyond user-based policy and reporting. Protecting user
identity is equally important. Phishing and the use of stolen credentials were the top two threat action
types.1 In fact, 90% of security incidents in 2021 involved phishing.2 Attackers use stolen credentials to
gain access to organizations’ networks, where they find valuable applications and data they can steal.
To prevent credential-based attacks, our Next-Generation Firewalls:
• Stop unknown and highly evasive phishing attacks via Advanced URL Filtering, using detections
powered by inline deep learning for real-time analysis and prevention of both known and unknown
web-based threats, stopping 40% more threats than traditional filtering databases.
• Stop users from submitting corporate credentials to unknown sites, protecting them from targeted
attacks that use new, unknown phishing sites to go undetected.
• Automate responses that adapt and follow user behavior via Dynamic User Groups (DUGs). Wheth-
er a user’s credentials are compromised, or you need to provide temporary access to users, DUGs
enable you to leverage user behavior data from Cortex XDR, user and entity behavior analytics
(UEBA), and security information and event management (SIEM) systems to automatically enforce
security policies in real time.
• Allow you to enforce multifactor authentication (MFA) for any application you deem sensitive,
including legacy applications that do not lend themselves easily to MFA. This protects you if an
adversary already possesses stolen credentials. You can use this capability with the identity vendor
of your choice.
Strata by Palo Alto Networks | ML-Powered Next-Generation Firewall Feature Overview | Whitepaper 3
decryption for specific transactions that may contain personal data. The rest
of your traffic can be decrypted and secured. If you’re unsure where to start,
you can use our Next-Generation Firewalls to gain full visibility into the
details of all encrypted connections. Time Spent on Encrypted
Support for hardware security modules allows you to manage digital keys Websites and Apps
securely. Perfect Forward Secrecy ensures the compromise of one encrypted
session does not lead to the compromise of multiple encrypted sessions.
Advanced WildFire
Advanced WildFire is the largest cloud-based malware analysis and prevention engine that uses ma-
chine learning and crowdsourced intelligence to protect organizations from highly evasive threats.
Utilizing over 25 patented detection engines and inline machine learning modules on the NGFW to
identify and prevent 99% of known and unknown file-based threats, Advanced WildFire can protect
users before a threat even enters your network.
DNS Security
DNS Security applies predictive analytics, machine learning, and automation to block the latest and
most sophisticated attacks that use DNS. Tight integration with the Next-Generation Firewall gives you
automated protections, prevents attackers from bypassing security measures, and eliminates the need
for independent tools or changes to DNS routing. Comprehensive analytics allow deep insights into
threats and empower security personnel with the context to optimize their security posture. DNS Secu-
rity offers industry-first detections, giving your 40% more threat coverage against DNS-layer attacks.
IoT Security
IoT Security is the industry’s most comprehensive Zero Trust security for IoT devices, delivering
ML-powered visibility, prevention, and enforcement in a single platform. This unique combination of IoT
visibility and the Next-Generation Firewall enables context-aware network segmentation to reduce risk
exposure and applies our leading security subscriptions to keep IoT and IT devices secure from all threats.
Strata by Palo Alto Networks | ML-Powered Next-Generation Firewall Feature Overview | Whitepaper 4
In order to meet the specific needs of different industry verticals, we have designed two separate IoT
security products:
• Medical IoT Security makes it push-button easy for you to see, secure, govern, and report on your
specialized medical devices like infusion pumps, MRI machines, and patient monitors, and helps you
achieve HIPAA compliance.
• Enterprise IoT Security makes it push-button easy to see, secure, govern, and report on all of your IoT
devices, like printers, security cameras, and HVAC systems, and meet FedRAMP and NIST guidelines.
Next-Generation CASB
As SaaS apps rapidly proliferate and collaboration apps emerge in highly distributed workforces, tra-
ditional CASB solutions fail to adequately secure them. Legacy approaches limit visibility and scale and
offer poor data protection while being costly.
Our Next-Gen CASB solution has the capacity to keep any and all of your SaaS apps secure across your
entire enterprise in real time. With comprehensive data protection that’s leading the industry, you can
contain rapid implementation of SaaS products with confidence while securely enabling your hybrid
workforce.
Dynamic Machine
analysis learning
ADV
WF
Static Intelligent runtime
analysis memory analysis
Web URL
Malware, URLs,
Protections
DNS, C2
Unknowns
Flash SWF
Scripts JS
Updated within
seconds, globally
Archive ZIP
Binaries DLL
Prevent highly
Documents RTF
evasive measures
Strata by Palo Alto Networks | ML-Powered Next-Generation Firewall Feature Overview | Whitepaper 5
Zero Trust
Conventional security models operate on the outdated assumption that everything inside an organiza-
tion’s network can be trusted. These models are designed to protect the perimeter. Meanwhile, threats
that get inside the network go unnoticed and are left free to compromise sensitive, valuable business
data. In the digital world, trust is nothing but a vulnerability. Zero Trust is a cybersecurity strategy
that prevents data breaches. In Zero Trust, each step a user makes through the infrastructure must be
validated and authenticated across all locations. Our Next-Generation Firewalls directly align with Zero
Trust, including enabling secure access for all users irrespective of location, inspecting all traffic, en-
forcing policies for least-privileged access control, and detecting and preventing advanced threats. This
significantly reduces the pathways for adversaries, whether they are inside or outside your organiza-
tion, to access your critical assets.
Single-Pass Architecture
Protection against the evolving threat landscape often requires new security functions to be introduced.
Palo Alto Networks Next-Generation Firewalls are built on a single-pass architecture, which offers pre-
dictable performance and native integration—features that cannot be attained by layering new capabil-
ities on legacy architecture that still works on IP addresses, ports, and protocols. Our Next-Generation
Firewalls perform a full-stack, single-pass inspection of all traffic across all ports, providing complete
context around the application, associated content, and user identity to form the basis of your secu-
rity policy decisions. This architecture allows us to add innovative, new capabilities easily—as we’ve
already done with Advanced WildFire and, more recently, IoT Security.
Flexible Deployment
Our Next-Generation Firewalls can be deployed in multiple form factors:
• PA-Series: A blend of power, intelligence, simplicity, and versatility protects enterprise and service
provider deployments at headquarters, data centers, and branches.
• VM-Series: Our Virtual Next-Generation Firewalls protect your hybrid cloud and branch deploy-
ments by segmenting applications and preventing threats.
• CN-Series: Our containerized firewall is the best-in-class next-generation firewall purpose-built to
secure your Kubernetes environment from network-based attacks.
• Cloud NGFW: With Cloud NGFW for Amazon Web Services (AWS), customers gain both best-in-
class security and an easy, managed cloud-native experience delivered by Palo Alto Networks on
the AWS platform.
• Prisma Access: Our secure access service edge (SASE) offering delivers operationally efficient security
globally from the cloud.
You can choose one of these or a combination to match your requirements by location, and manage all
deployments centrally through Panorama network security management.
Strata by Palo Alto Networks | ML-Powered Next-Generation Firewall Feature Overview | Whitepaper 6
2. Streamline configuration sharing with templates and device groups. Scale log collection as logging
needs increase.
3. Obtain deep visibility and monitor network traffic and security threats with Application Command
Center (ACC), reporting, and detailed log views.
4. Use built-in automation and customize security workflows using APIs to integrate with third-par-
ty systems and operational tools.
5. Benefit from the latest security innovations with a straightforward, single reboot upgrade process
that fits into a typical maintenance window. This simplifies the upgrade for HA pairs.
Strata by Palo Alto Networks | ML-Powered Next-Generation Firewall Feature Overview | Whitepaper 7
Why Palo Alto Networks Next-Generation Firewalls?
Our ML-Powered Next-Generation Firewalls empower you to stop zero-day threats using ML, AI, and
inline deep learning. The consolidated platform approach simplifies network security for our customers
with the addition of AIOps to help improve security posture and IoT Security to quickly discover and
protect devices against known and unknown threats. We’ve been recognized as a Leader in Gartner’s
Magic Quadrant for Network Firewalls eight times in a row, and our firewalls have received a Recom-
mended rating from NSS Labs—the highest rating NSS Labs offers.
Welcome to the era of intelligent security—protecting your enterprise from the threats of tomorrow.
Here are some helpful resources to get you started:
✓ Want to learn more about our Next-Generation Firewalls? Visit our Secure the Network page.
✓ Ready to get your hands on our Next-Generation Firewalls? Take an Ultimate Test Drive.
✓ Ready to see what’s on your network right now? Request a free Security Lifecycle Review to gain un-
precedented visibility into the threats and risks present in your environment.
3000 Tannery Way © 2023 Palo Alto Networks, Inc. Palo Alto Networks is a registered t rademark
Santa Clara, CA 95054 of Palo Alto Networks, Inc. A list of our trademarks can be found at https://
www.paloaltonetworks.com/company/trademarks.html. All other marks
Main: +1.408.753.4000 mentioned herein may be trademarks of their respective companies.
Sales: +1.866.320.4788 parent_wp_ml-powered-ngfw-feature-overview-021523
Support: +1.866.898.9087
www.paloaltonetworks.com