Topology selection
Span port, Inline behind or in front of existing firewall, or firewall replacement



- Application visibility and control: Accurate identification of the applications traversing the network enables policy-based control over application usage.
- SSL inspection: Identifies and decrypts applications that use SSL, enabling policy-based control over the ever increasing amounts of SSL traffic.
- Visualization tools: Graphical visibility tools, customizable reporting and logging enables administrators to make a more informed decision on how to treat the applications traversing the network.
- Policy-based application control: The policy-editor takes full advantage of existing firewall knowledge to streamline creation and deployment of application usage control policies.
- Legacy firewall support: Support for traditional inbound and outbound port-based firewall rules mixed with application-based rules smoothes the transition to a Palo Alto Networks next generation firewall.
- Application browser: Helps administrators quickly research what the application is, its’ behavioral characteristics and underlying technology resulting in a more informed decision making process on how to treat the application.
- User-based visibility and control: Seamless integration with Microsoft Active Directory (AD) facilitates application visibility and policy creation based on user and group information in AD, not just IP address.
- Real-time threat prevention: Detects and blocks viruses, spyware, worms and application vulnerabilities in real-time, dramatically improving performance and accuracy.
- High performance: Purpose-built platform with function-specific processing for networking, security, threat prevention and management delivers the performance required to protect today’s high speed networks and eliminate security bottlenecks commonly associated with computationally intensive security applications.
- Networking architecture: Support for dynamic routing, site-to-site IPSec VPN, virtual wire mode and layer 2/layer 3 modes facilitates deployment in nearly any networking environment.

