Palo Alto NetworksNetwork Security Management

    PAN-OS

    The operating system behind every Palo Alto Networks firewall.

    PAN-OS is the software that powers every Palo Alto Networks Next-Generation Firewall — physical, virtual, containerized, and cloud. It provides App-ID, User-ID, Content-ID, the single-pass architecture, inline machine-learning threat prevention, and the framework for Cloud-Delivered Security Services, so policy and protection are identical across every form factor. Faltrox maintains, hardens, and tunes PAN-OS across your firewall estate.

    Overview

    What PAN-OS is

    What makes a Palo Alto Networks firewall consistent — whether it is a branch appliance, a hyperscale chassis, a virtual machine, a container firewall, or a cloud service — is that they all run the same operating system: PAN-OS. It is the foundation of the ML-Powered NGFW and the reason a policy behaves identically everywhere it is applied.

    PAN-OS delivers the core technologies: App-ID (identify applications), User-ID (tie policy to users), Content-ID (inspect content for threats and data), the single-pass parallel-processing architecture, inline machine learning for real-time prevention, TLS decryption, and the framework that connects to the Cloud-Delivered Security Services. Its releases add capabilities across the whole estate at once. Faltrox maintains PAN-OS versions, applies hardening and best-practice configuration, and tunes it across every firewall form factor as part of managed network defence.

    Coverage

    What it protects

    The platforms, threats, and surfaces this product is built to defend.

    01

    Every Form Factor

    Powers physical, virtual, containerized, and cloud firewalls with one software base.

    02

    App-ID & User-ID

    Identifies applications and ties policy to users as the basis of Zero Trust.

    03

    Inline ML Prevention

    Inline machine learning provides real-time threat prevention across the estate.

    04

    Single-Pass Architecture

    Identifies and inspects traffic once per packet for performance and consistency.

    05

    TLS Decryption

    Decrypts and inspects encrypted traffic so threats cannot hide in TLS.

    06

    CDSS Framework

    Connects every firewall to the Cloud-Delivered Security Services.

    How it works

    The mechanism

    How the product moves from signal to protected state, step by step.

    1. 01

      Identify

      App-ID, User-ID, and Content-ID identify applications, users, and content on every firewall.

    2. 02

      Single-Pass

      The single-pass parallel-processing architecture inspects each packet once for performance.

    3. 03

      Prevent

      Inline machine learning and the Cloud-Delivered Security Services prevent known and zero-day threats.

    4. 04

      Update

      PAN-OS releases add capabilities across every form factor at once, keeping the estate current.

    5. 05

      Operate

      Faltrox maintains versions, applies hardening and best practice, and tunes PAN-OS across the estate.

    Capabilities

    Key capabilities

    App-ID

    Identifies applications regardless of port, protocol, or evasion, as the basis of policy.

    User-ID

    Ties security policy to user identity for Zero Trust access control.

    Content-ID

    Inspects content in a single pass for threats, data, and URLs.

    Single-Pass Architecture

    Parallel-processing single-pass design sustains performance with full protection on.

    Inline Machine Learning

    Provides real-time prevention of known and zero-day threats on every firewall.

    TLS/SSL Decryption

    Decrypts and inspects encrypted traffic so threats cannot hide in TLS.

    CDSS Framework

    Connects every firewall to Advanced Threat Prevention, URL Filtering, WildFire, and DNS Security.

    Consistent Everywhere

    One software base means identical policy and protection across all form factors.

    Works with

    Part of the platform

    Palo Alto Networks products this pairs with, and the Faltrox services that operate it.

    Delivery

    You buy the outcome, not the console

    Managed by Faltrox

    Faltrox licenses, deploys, and tunes Palo Alto Networks PAN-OS for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.

    See the service

    FAQ

    Common questions

    01Is PAN-OS a product we buy separately?

    PAN-OS is the operating system that runs on every Palo Alto Networks firewall — it is what you are running whenever you run one of their NGFWs, physical or virtual. Its value is that it makes every form factor behave identically, and its releases add capability across the whole estate at once.

    02What are App-ID, User-ID, and Content-ID?

    They are the core PAN-OS technologies: App-ID identifies the actual application in traffic, User-ID ties policy to user identity, and Content-ID inspects content for threats, data, and URLs. Together they let you write policy on applications and users rather than ports — the basis of Zero Trust on the firewall.

    03Why does the single-pass architecture matter?

    It identifies and inspects each packet once rather than chaining separate engines, so full threat prevention runs without collapsing throughput. It is the design reason Palo Alto firewalls keep performance high with all protection enabled.

    04How does keeping PAN-OS current help security?

    PAN-OS releases add new detection and prevention capabilities and fix vulnerabilities across every form factor at once. Keeping versions current and correctly configured is a large part of the firewall estate’s real-world security — which is what Faltrox maintains.

    05How does Faltrox operate it?

    We maintain PAN-OS versions across your estate, apply hardening and best-practice configuration, tune App-ID and threat policy, and monitor the firewalls — delivering the software layer of managed network defence, not just the hardware.

    Start an engagement

    Secure what’s next.

    Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.

    Contact us