Palo Alto Panorama
Integration & Setup Manual
Palo Alto Panorama Integration Guide
Overview
Cup’n’String Guard integrates with Palo Alto Panorama to enforce AI tool network policies across managed NGFW device groups. Guard uses the Panorama XML API to stage, commit, verify, and roll back rules inside a dedicated ownership-tagged rulebase section — it never touches rules outside its namespace.
Support level
Guard Firewall Orchestration — staged candidate-config commit with async job polling, drift detection, and synthetic rollback.
Recommended Guard mode
Start with Observe to audit rule drift, then promote to Enforce once baseline policies are validated.
Known limitations
- Panorama commit jobs are device-group-wide; Guard cannot commit only its own changes in isolation — it commits the full candidate config for the device group.
- Per-process rules are not available at the Panorama layer (enforcement is at network level).
Setup outline
- Confirm the supported platform and deployment requirements with your administrator.
- Use a dedicated integration identity with the minimum required permissions and validated TLS connections.
- Review policy in your environment before enabling enforcement, then verify the intended access outcomes.
Contact the Cup’n’String team for deployment-specific configuration and verification guidance. Never share credentials in support messages or screenshots.
Integration Info
Links
Verify what categories and runtimes this stack fits inside in the global compatibility dashboard.
Supported Environments Matrix