Palo Alto Firewall – Platforms and Architecture

network-firewall-device
03/19/2019 •

Palo Alto Firewall – Platforms and Architecture

Control Plane and Dataplane Overview

Debug functions run on either the control plane or the Dataplane

Logging (to the hard drive) is controlled by the control plane

The control plane also referred as Management plane, is where configurations are defined and configured. The control plane considered to be the brain of the firewall and the Dataplane is the muscle of the firewall.

Configuration made within the control plane are pushed by a commit operation to the Dataplane.

The component of the control plane and the Dataplane vary for each platform, series of the firewall.

Palo Alto Firewall - Platforms and Architecture
Architecture front

Different items can leverage the single pass other items can leverage parallel processing

Picture1
  • Signature match is done in parallel.
    The stream passes and is scanned for “signatures”  or patterns.
  • Security Processing requires computation to calculate keys for SSL, IPSEC, opening SSL and setting up sessions.
    This is a simple CPU set of tasks.
    The actual rules are processed here too and the logs are created. So report & Enforce.
    Network processing does networking, like NAT and QoS.

Palo Alto Firewall models 

PA-200 Model and Features

PA-200 front

PA-500 Model and Features

PA-500 front

PA-2000 Model and Features

PA-2000s front

PA-3020 Model and FeaturesPA-3020 front

PA-3050 Model and Features

PA-3050 front

PA-5000 Models and Features

PA-5000 front

PA-7000 Models and Features

PA-7000 front

Palo Alto Virtual Firewalls 

VM series firewalls front

https://www.paloaltonetworks.com

https://sanchitgurukul.com/tutorials-cat

Disclaimer: This article may contain information that was accurate at the time of writing but could be outdated now. Please verify details with the latest vendor advisories or contact us at admin@sanchitgurukul.com.

Discover more from

Subscribe now to keep reading and get access to the full archive.

Continue reading