Palo Alto Introduction

This section refers to the Palo Alto Networks integration with Horizon, used to deploy certificates on PAN-OS firewalls.

This integration involves at least two infrastructure components:

  • A Palo Alto PAN-OS firewall or a Panorama appliance

  • EverTrust Horizon

Two connectors are available, both relying on the PAN-OS XML API:

  • The Panorama connector connects to a Panorama appliance and deploys certificates in a template, template stack or virtual system (VSYS). It can optionally commit the configuration to the managed firewalls.

  • The PAN-OS Firewall connector connects to a standalone firewall and deploys certificates on it, optionally in a given virtual system (VSYS).

Using triggers, Horizon deploys the certificate and its private key on enrollment and renewal, and removes it from the target on revocation or expiration. A certificate is only removed if it is still found under the name Horizon gave it; if it was renamed or moved, the removal is skipped.

Only PAN-OS 10.2 and later is supported.