Category Archives: Cybersecurity
FortiGate ZTNA tags—called security posture tags in current FortiOS documentation—are dynamic endpoint attributes synchronized from FortiClient EMS to FortiGate. EMS evaluates zero-trust tagging rules against endpoint posture and identity context, then FortiGate receives the resulting IP/MAC mappings as read-only dynamic address objects that can be referenced in ZTNA rules, firewall policies, and NAC policies. Within […]
SLSA—Supply-chain Levels for Software Artifacts—is a specification for improving software supply-chain security through verifiable provenance and stronger controls around source and build systems. The current approved specification is version 1.2. A key current-state detail is that SLSA no longer has one universal “level” for everything: it has separate tracks, including a Build track and a […]
FortiManager Administrative Domains (ADOMs) partition devices, policy packages, objects, administrators, and version-specific management data into separate logical management areas. They are useful for managed service providers, large enterprises, multi-team environments, mixed device families, and firmware-lifecycle separation, but Fortinet best practices explicitly caution against creating more ADOMs than the business needs because each ADOM adds configuration […]
Palo Alto security operations sits at the intersection of network enforcement, routing, centralized configuration, SASE connectivity, device health, and user experience. PAN-OS firewalls no longer operate as isolated security appliances: Panorama can layer and push shared configuration, AIOps and Strata Cloud Manager can analyze health and security posture, Prisma Access extends policy to remote networks […]
FortiManager revision control is the combination of configuration history, change isolation, comparison, approval, and install discipline that lets teams make centralized firewall changes without losing the ability to explain or reverse them. Current FortiManager supports ADOM revisions for policy packages, objects, and VPN-console settings, policy-level revision history, and workspace/workflow modes that control how multiple administrators […]
PAN-OS Advanced Routing Engine turns the firewall into a more capable standards-oriented routing platform without separating routing from security enforcement. It uses logical routers instead of the legacy virtual-router model and supports BGP, MP-BGP, OSPFv2, OSPFv3, RIPv2, static routes, BFD, IPv4 multicast routing, redistribution, route maps, prefix lists, access lists, and RIB filtering. Within Palo […]
FortiSOAR playbooks automate security workflows across Fortinet and third-party systems through triggers, decisions, connectors, records, blocks, variables, and human interaction. Current FortiSOAR 8.0 design guidance emphasizes starting with a trigger, gating execution through decisions, grouping related logic in blocks, using reference blocks for reusable workflows, and choosing logging levels that support production operations without filling […]
Palo Alto AIOps for NGFW uses firewall telemetry to analyze device health, security posture, software behavior, and feature adoption. Current Strata Cloud Manager and AIOps capabilities include health alerts, security posture alerts, best-practice insights, feature-adoption visibility, predictive analysis, and software-upgrade recommendations for supported firewalls. Within Palo Alto Security Operations, AIOps is useful because it can […]
PAN-OS decryption troubleshooting begins with the reason a session was not decrypted successfully, not with the assumption that every failure means “SSL decryption is broken.” Current PAN-OS decryption monitoring combines decryption logs with ACC SSL Activity widgets so operators can identify common failure categories, affected server names, and the sessions associated with them. Within Palo […]
PAN-OS device telemetry collects firewall health, performance, configuration, and product-usage metrics and sends them to Palo Alto Networks cloud services for telemetry-powered capabilities. The current telemetry reference is unusually detailed: for each metric, Palo Alto documents category, collection frequency, telemetry tier, privacy considerations, and often the equivalent CLI command used to obtain similar state locally. […]
Security engineering is the discipline of turning security goals into systems that continue to work under real operational pressure. It includes identity, software supply chain integrity, cloud workload protection, certificate and secret lifecycles, runtime defenses, browser isolation, cryptographic transition, and visibility into technologies users adopt outside formal approval paths. The common theme is that a […]
Dynamic Address Groups (DAGs) let PAN-OS security policy refer to workloads by metadata rather than hard-coded IP address. The firewall evaluates a tag-based match expression and dynamically updates group membership as IP-to-tag registrations change at runtime. This is particularly useful in virtualized, cloud, and automated environments where instances appear, disappear, and move faster than administrators […]
Certificate lifecycle automation is the engineering system that discovers certificates, issues them, proves control of names or identities, deploys them, renews them before expiry, replaces keys when needed, revokes compromised credentials, and verifies that endpoints are actually serving the intended certificate. The goal is not simply “no expired certificates.” It is predictable trust state across […]
Palo Alto SD-WAN path quality determines when application traffic should stay on a link and when the firewall should steer new sessions to a better path. Path Quality Profiles define acceptable network conditions for applications, and SD-WAN policy rules attach those profiles to the traffic classes that need them. Within Palo Alto Security Operations, path […]
Cloud-Native Application Protection Platform (CNAPP) describes a unified approach to protecting cloud applications across development and runtime. Current Microsoft Defender for Cloud documentation frames CNAPP around three core components: Cloud Security Posture Management (CSPM), DevSecOps security for code and pipelines, and Cloud Workload Protection (CWPP) for running workloads. Other platforms package similar ideas under broader […]