CN-Series
The container NGFW for Kubernetes — visibility and enforcement inside the cluster.
The Palo Alto Networks CN-Series is the industry’s leading containerized Next-Generation Firewall, delivering App-ID visibility and threat prevention inside Kubernetes environments. It secures container traffic — north-south and east-west between pods — with the full PAN-OS security stack, protecting workloads that traditional perimeter firewalls cannot see. Faltrox deploys and operates it as the container-network defence layer.
Overview
What CN-Series is
Kubernetes environments generate large volumes of ephemeral, east-west container traffic that traditional perimeter firewalls never see — leaving container-to-container communication as a blind spot for lateral movement and data exfiltration. The CN-Series is the containerized NGFW built to close that gap, bringing next-generation security inside the cluster.
It delivers App-ID application visibility and enforcement of Kubernetes traffic, inline threat prevention, and the Cloud-Delivered Security Services, deployed as firewall pods that inspect north-south and east-west container traffic. Managed through Panorama alongside physical and virtual firewalls, it extends consistent policy into the container estate. Faltrox deploys it into your clusters, designs the container segmentation, and operates it as the container-network defence layer.
Coverage
What it protects
The platforms, threats, and surfaces this product is built to defend.
Kubernetes Clusters
Brings NGFW visibility and enforcement inside Kubernetes environments.
East-West Container Traffic
Inspects pod-to-pod east-west traffic that perimeter firewalls never see.
North-South Traffic
Secures traffic entering and leaving the cluster with full NGFW protection.
Container App Visibility
App-ID identifies container applications for accurate policy inside the cluster.
Inline Threat Prevention
Prevents threats to container workloads in real time.
Cloud-Delivered Services
Subscribes to the full Cloud-Delivered Security Services suite.
How it works
The mechanism
How the product moves from signal to protected state, step by step.
- 01
Deploy
CN-Series firewall pods are deployed into the Kubernetes cluster to inspect container traffic.
- 02
Identify
App-ID identifies container applications and Kubernetes traffic for accurate policy inside the cluster.
- 03
Inspect
North-south and east-west container traffic is inspected with the full NGFW security stack.
- 04
Prevent
Inline threat prevention and Cloud-Delivered Security Services stop threats to container workloads.
- 05
Operate
Faltrox designs the container segmentation, manages it via Panorama, and monitors the cluster as managed defence.
Capabilities
Key capabilities
Container NGFW
The industry’s leading containerized NGFW, bringing full security inside Kubernetes.
Kubernetes Visibility
App-ID visibility and enforcement of Kubernetes and container-application traffic.
East-West Inspection
Inspects pod-to-pod east-west traffic to contain lateral movement inside the cluster.
North-South Protection
Secures traffic entering and leaving the cluster with full NGFW protection.
Inline Threat Prevention
Prevents threats to container workloads in real time.
Cloud-Delivered Security Services
Subscribes to Advanced Threat Prevention, URL Filtering, WildFire, and DNS Security.
Consistent Policy
Managed via Panorama alongside physical and virtual firewalls for one policy model.
Kubernetes-Native Deployment
Deploys as firewall pods that scale with the cluster.
Works with
Part of the platform
Palo Alto Networks products this pairs with, and the Faltrox services that operate it.
Delivery
You buy the outcome, not the console
Managed by Faltrox
Faltrox licenses, deploys, and tunes Palo Alto Networks CN-Series for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.
FAQ
Common questions
01Why do Kubernetes environments need a dedicated firewall?
Container traffic — especially east-west, pod-to-pod communication — is ephemeral and internal, so traditional perimeter firewalls never see it. That leaves container-to-container movement as a blind spot for lateral movement and exfiltration. The CN-Series brings NGFW visibility and enforcement inside the cluster to close it.
02Does it see east-west container traffic?
Yes — it inspects both north-south (in/out of the cluster) and east-west (pod-to-pod) traffic with the full NGFW stack, which is exactly the traffic perimeter firewalls miss and where lateral movement happens.
03How does it understand container applications?
Through App-ID, which identifies container applications and Kubernetes traffic so policy can be written accurately for the cluster rather than treating container traffic as opaque.
04Is it managed separately from our other firewalls?
No — it is managed through Panorama alongside physical and virtual firewalls, so the container estate enforces consistent policy with the rest of the network. Faltrox runs that unified management.
05How does Faltrox operate it?
We deploy the CN-Series into your clusters, design the container segmentation and policy, manage it via Panorama, and monitor container traffic — delivering managed container-network defence alongside our container security service.
Start an engagement
Secure what’s next.
Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.
Contact us