Virtualized Data Center
Problem: As a data center manager, you are under pressure to protect your infrastructure and applications from increasingly sophisticated and targeted threats. At the same time, your data centers are embracing technologies like virtualization and cloud computing that require security architectures to be more dynamic, automated and services-oriented. Data centers need a high-performance, flexible network security solution that not only safely enables applications and protects against modern threats, but can support the dynamic nature of a virtualized environment.
Solution: Palo Alto Networks next-generation firewalls offer you a network security solution that eliminates many of the unacceptable compromises previously endemic to data center network security. We enable you to deploy a simplified, high-performance, flexible network security infrastructure that safely enables the complex and growing number of applications in the data center. We also address key virtualization and cloud requirements including intra-host inspection of virtual machine traffic, tracking policies to virtual machine creation and movement, and integration with cloud orchestration software to automate policy changes. The same centralized management platform can be deployed for virtualized and physical firewalls, optimizing visibility, reducing operational complexity and decreasing policy configuration gaps. With consistent next-generation security features available in physical or virtual form factors and an optimized low-latency architecture, our firewalls can deliver security for any data center design without compromising performance.
|
Safe Application Enablement Palo Alto Networks next-generation firewalls identify, control, and safely enable applications while at the same time inspecting all content for all threats all the time. Visibility into all traffic in the data center reduces the scope of attacks by controlling non-compliant usage of applications, blocking rogue applications and distinguishing any unknown traffic. In addition, Palo Alto Networks next-generation firewalls feature a complete threat protection framework that addresses targeted attacks, exploits, malware and spyware on standard ports, non-standard ports and within encrypted traffic. Finally, differentiated access to data center applications can be enabled by user/group to support secure anytime, anywhere access by employees, extended business partners and mobile users. Safe application enablement features applied to security zones in the data center delivers meaningful segmentation, limits access, and delivers individual accountability to meet compliance mandates. |
|
Virtualization Security Features The dynamic and services-oriented nature of virtualization and cloud computing technologies require security architectures to correspondingly be more agile. Palo Alto Networks next-generation firewalls provide the ability to track security policies to virtual machine creation and movement via dynamic address objects. This ensures that security and regulatory compliance requirements continue to be met. In addition, the ability to integrate next-generation security policies with cloud orchestration software ensures that security does not slow down the automated nature of virtual workload provisioning. |
|
Flexible Networking Integration Palo Alto Networks next-generation firewalls support more deployment options than any other device in the network security market. We offer you deployment at L1, L2, L3, and tap modes (or a mixture of all on the same appliance) and couple that with powerful networking capabilities for integration (VLAN trunking, link aggregation) and high availability (separation of data and control planes, active/active and active/passive deployment options). This accommodates any data center architecture, and the flexibility to add additional security controls without re-architecting the network when the threat or application landscape changes. |
|
High-Performance Architecture Because the delivery of applications quickly and reliably is critical in a data center, the Palo Alto Networks next-generation firewalls support a single-pass software architecture that ensures low latency by processing all security functions once. In addition, hardware platforms feature a parallel-processing architecture, with dedicated, specialized processing for networking, security, and content scanning. This enables the full-suite of next-generation features to be delivered with high throughput and reliability |
|
Centralized, Consistent Management Panorama delivers a centralized, consistent management for global control over a network of Palo Alto Networks virtualized and physical next-generation firewalls. Panorama allows administrators to control all aspects of the devices and/or virtual systems under management (security, NAT, QoS, policy-based forwarding, decryption, application override, captive portal, and DoS protection). Centralized logging and reporting can be run across dynamic or logically queried data aggregated from managed virtualized and physical devices. |