Procedure
- Go to and select Palo Alto Panorama or Firewalls.
- Provide the following information:
-
Server address
Note
The server address must be the IPv4 address or FQDN of the inline product. -
Server type
-
Panorama
-
Firewalls
Note
Deep Discovery Inspector supports Palo Alto Panorama and firewalls with virtual systems.On Panorama devices and firewalls with virtual systems, a policy rule must be configured to utilize the suspicious objects and C&C callback addresses. -
-
User name: Existing authentication credential
-
Password: Existing authentication credential
Valid Character Sets
User namePasswordMinimum length1 character1 characterMaximum length15 characters15 characters -
- (Optional) Click Test Connection.
- Under Object Distribution, click
Enabled.The Legal Statement opens.
- Read and accept the Legal Statement.
Note
To enable integration with this inline product/service, you must accept the Legal Statement. - (Optional) Select a new Frequency.
- To send object information from Deep Discovery Inspector to this inline product/service, configure the following
criteria:
-
Object type:
-
C&C Callback Address
-
IPv4 address
-
Domain
-
URL
-
-
Suspicious Object
-
IPv4 address
-
Domain
-
URL
-
-
-
Risk level:
-
High only
-
High and medium
-
High, medium, and low
-
-
- Under Advanced Settings, customize URL category
names:URL category names must include a minimum of one character and a maximum of 31 characters, and may include the following characters:
-
Uppercase (A-Z)
-
Lowercase (a-z)
-
Numeric (0-9)
-
Special characters: - _
-
Space
-
- Click Save.
- For PAN-OS 7.1 or later, enable XML API access.
- On the Palo Alto product console, go to and select or create an admin role.
- Select the XML API tab.
- Enable the following XML API features from the list.
-
Configuration
-
Operation Requests
-
Commit
-
- Click OK.
- Assign the admin role to an administrator account.
- (Optional) To view suspicious objects and C&C callback addresses sent by
Deep Discovery Inspector on the Palo
Alto product console, go to .Suspicious objects and C&C callback addresses distributed by Deep Discovery Inspector are displayed.