4.1 4-About Palo Alto Networks
4.1 4-About Palo Alto Networks
4.1 4-About Palo Alto Networks
PCNSE:
A Palo Alto Networks Certified Network Security Engineer (PCNSE) is capable of designing,
deploying, configuring, maintaining and trouble-shooting the vast majority of Palo Alto
Networks Operating Platform implementations.
o The only firewall to identify, control & inspect your SSL encrypted traffic & applications.
o The only firewall with real-time content scanning to protect you against viruses.
o The only firewall to protect against spyware, data leakage & application vulnerabilities.
o The only next-generation firewall based on a stream-based threat prevention engine.
o Palo Alto unleashes the power of the cloud against threats known and unknown.
o Palo Alto is security application that allows or denies traffic by a single fingerprint.
o If one company experiences unique attack, all other subscribers’ networks are updated.
o You can allow certain functions of an application without blocking the entire application.
Parallel Processing:
o The other critical piece of Palo Alto Networks SP3 Architecture is hardware.
o It is use Parallel Processing hardware to ensure Single Pass software runs fast.
o Palo Alto Networks engineers designed separate data plan and control plane.
o This separation means you can update the device while still keep forwarding going.
o Palo Alto firewall using multiple cores and processors will run checks in parallel.
o It is not re-compile files in order to scan them but scan stream for signature.
o Identification Technologies Transform the Firewall, App-ID, User-ID, and Content-ID.
Single-Pass Architecture:
o PAN Firewall are optimized to only inspect the packet "ONE TIME", concurrently.
o At same time do Signature Matching, Security Processing & Networking Processing.
o All in Parallel to each other without having to re buffer same packet over & over again.
o Single-Pass performs the L7 classification and inspection Operations once per packet.
o Strength of Palo Alto Networks Firewall is its Single Pass Parallel Processing (SP3) engine.
o Every single layer of Protection Antivirus, Spyware, Data Filtering & Vulnerability protection.
o Palo Alto Networks Firewall all utilized the same stream-based signature format.
o allows PAN to buffer and inspect a packet at the same time, it can do all three in parallel.
Data Plane:
o Palo Alto Firewall Data Plan It is the Traffic Forwarding Plan with different chip sets.
o Three functions Signature Match process inspects traffic built on Regular Expressions.
o The second function is Security Processors matches against Palo Alto security policies.
o And the last function is Network Processor is used for traffic forwarding etc.
Networking:
Packet Routing, Flow lookup, Stat Counts, NAT & All performed on Dedicated Network Pro.
Security:
User-ID, App-ID, & Policy Engine, all occur on multicore, Encrypting, Decryption, Decompression
Signature:
Content-ID performs Signature Lookups via a Dedicated FPGA with dedicated Memory.