Palo Alto NetworksNetwork Security

    CN-Series

    The container NGFW for Kubernetes — visibility and enforcement inside the cluster.

    The Palo Alto Networks CN-Series is the industry’s leading containerized Next-Generation Firewall, delivering App-ID visibility and threat prevention inside Kubernetes environments. It secures container traffic — north-south and east-west between pods — with the full PAN-OS security stack, protecting workloads that traditional perimeter firewalls cannot see. Faltrox deploys and operates it as the container-network defence layer.

    Overview

    What CN-Series is

    Kubernetes environments generate large volumes of ephemeral, east-west container traffic that traditional perimeter firewalls never see — leaving container-to-container communication as a blind spot for lateral movement and data exfiltration. The CN-Series is the containerized NGFW built to close that gap, bringing next-generation security inside the cluster.

    It delivers App-ID application visibility and enforcement of Kubernetes traffic, inline threat prevention, and the Cloud-Delivered Security Services, deployed as firewall pods that inspect north-south and east-west container traffic. Managed through Panorama alongside physical and virtual firewalls, it extends consistent policy into the container estate. Faltrox deploys it into your clusters, designs the container segmentation, and operates it as the container-network defence layer.

    Coverage

    What it protects

    The platforms, threats, and surfaces this product is built to defend.

    01

    Kubernetes Clusters

    Brings NGFW visibility and enforcement inside Kubernetes environments.

    02

    East-West Container Traffic

    Inspects pod-to-pod east-west traffic that perimeter firewalls never see.

    03

    North-South Traffic

    Secures traffic entering and leaving the cluster with full NGFW protection.

    04

    Container App Visibility

    App-ID identifies container applications for accurate policy inside the cluster.

    05

    Inline Threat Prevention

    Prevents threats to container workloads in real time.

    06

    Cloud-Delivered Services

    Subscribes to the full Cloud-Delivered Security Services suite.

    How it works

    The mechanism

    How the product moves from signal to protected state, step by step.

    1. 01

      Deploy

      CN-Series firewall pods are deployed into the Kubernetes cluster to inspect container traffic.

    2. 02

      Identify

      App-ID identifies container applications and Kubernetes traffic for accurate policy inside the cluster.

    3. 03

      Inspect

      North-south and east-west container traffic is inspected with the full NGFW security stack.

    4. 04

      Prevent

      Inline threat prevention and Cloud-Delivered Security Services stop threats to container workloads.

    5. 05

      Operate

      Faltrox designs the container segmentation, manages it via Panorama, and monitors the cluster as managed defence.

    Capabilities

    Key capabilities

    Container NGFW

    The industry’s leading containerized NGFW, bringing full security inside Kubernetes.

    Kubernetes Visibility

    App-ID visibility and enforcement of Kubernetes and container-application traffic.

    East-West Inspection

    Inspects pod-to-pod east-west traffic to contain lateral movement inside the cluster.

    North-South Protection

    Secures traffic entering and leaving the cluster with full NGFW protection.

    Inline Threat Prevention

    Prevents threats to container workloads in real time.

    Cloud-Delivered Security Services

    Subscribes to Advanced Threat Prevention, URL Filtering, WildFire, and DNS Security.

    Consistent Policy

    Managed via Panorama alongside physical and virtual firewalls for one policy model.

    Kubernetes-Native Deployment

    Deploys as firewall pods that scale with the cluster.

    Works with

    Part of the platform

    Palo Alto Networks products this pairs with, and the Faltrox services that operate it.

    Delivery

    You buy the outcome, not the console

    Managed by Faltrox

    Faltrox licenses, deploys, and tunes Palo Alto Networks CN-Series for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.

    See the service

    FAQ

    Common questions

    01Why do Kubernetes environments need a dedicated firewall?

    Container traffic — especially east-west, pod-to-pod communication — is ephemeral and internal, so traditional perimeter firewalls never see it. That leaves container-to-container movement as a blind spot for lateral movement and exfiltration. The CN-Series brings NGFW visibility and enforcement inside the cluster to close it.

    02Does it see east-west container traffic?

    Yes — it inspects both north-south (in/out of the cluster) and east-west (pod-to-pod) traffic with the full NGFW stack, which is exactly the traffic perimeter firewalls miss and where lateral movement happens.

    03How does it understand container applications?

    Through App-ID, which identifies container applications and Kubernetes traffic so policy can be written accurately for the cluster rather than treating container traffic as opaque.

    04Is it managed separately from our other firewalls?

    No — it is managed through Panorama alongside physical and virtual firewalls, so the container estate enforces consistent policy with the rest of the network. Faltrox runs that unified management.

    05How does Faltrox operate it?

    We deploy the CN-Series into your clusters, design the container segmentation and policy, manage it via Panorama, and monitor container traffic — delivering managed container-network defence alongside our container security service.

    Start an engagement

    Secure what’s next.

    Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.

    Contact us