PAN-OS
The operating system behind every Palo Alto Networks firewall.
PAN-OS is the software that powers every Palo Alto Networks Next-Generation Firewall — physical, virtual, containerized, and cloud. It provides App-ID, User-ID, Content-ID, the single-pass architecture, inline machine-learning threat prevention, and the framework for Cloud-Delivered Security Services, so policy and protection are identical across every form factor. Faltrox maintains, hardens, and tunes PAN-OS across your firewall estate.
Overview
What PAN-OS is
What makes a Palo Alto Networks firewall consistent — whether it is a branch appliance, a hyperscale chassis, a virtual machine, a container firewall, or a cloud service — is that they all run the same operating system: PAN-OS. It is the foundation of the ML-Powered NGFW and the reason a policy behaves identically everywhere it is applied.
PAN-OS delivers the core technologies: App-ID (identify applications), User-ID (tie policy to users), Content-ID (inspect content for threats and data), the single-pass parallel-processing architecture, inline machine learning for real-time prevention, TLS decryption, and the framework that connects to the Cloud-Delivered Security Services. Its releases add capabilities across the whole estate at once. Faltrox maintains PAN-OS versions, applies hardening and best-practice configuration, and tunes it across every firewall form factor as part of managed network defence.
Coverage
What it protects
The platforms, threats, and surfaces this product is built to defend.
Every Form Factor
Powers physical, virtual, containerized, and cloud firewalls with one software base.
App-ID & User-ID
Identifies applications and ties policy to users as the basis of Zero Trust.
Inline ML Prevention
Inline machine learning provides real-time threat prevention across the estate.
Single-Pass Architecture
Identifies and inspects traffic once per packet for performance and consistency.
TLS Decryption
Decrypts and inspects encrypted traffic so threats cannot hide in TLS.
CDSS Framework
Connects every firewall to the Cloud-Delivered Security Services.
How it works
The mechanism
How the product moves from signal to protected state, step by step.
- 01
Identify
App-ID, User-ID, and Content-ID identify applications, users, and content on every firewall.
- 02
Single-Pass
The single-pass parallel-processing architecture inspects each packet once for performance.
- 03
Prevent
Inline machine learning and the Cloud-Delivered Security Services prevent known and zero-day threats.
- 04
Update
PAN-OS releases add capabilities across every form factor at once, keeping the estate current.
- 05
Operate
Faltrox maintains versions, applies hardening and best practice, and tunes PAN-OS across the estate.
Capabilities
Key capabilities
App-ID
Identifies applications regardless of port, protocol, or evasion, as the basis of policy.
User-ID
Ties security policy to user identity for Zero Trust access control.
Content-ID
Inspects content in a single pass for threats, data, and URLs.
Single-Pass Architecture
Parallel-processing single-pass design sustains performance with full protection on.
Inline Machine Learning
Provides real-time prevention of known and zero-day threats on every firewall.
TLS/SSL Decryption
Decrypts and inspects encrypted traffic so threats cannot hide in TLS.
CDSS Framework
Connects every firewall to Advanced Threat Prevention, URL Filtering, WildFire, and DNS Security.
Consistent Everywhere
One software base means identical policy and protection across all form factors.
Works with
Part of the platform
Palo Alto Networks products this pairs with, and the Faltrox services that operate it.
Delivery
You buy the outcome, not the console
Managed by Faltrox
Faltrox licenses, deploys, and tunes Palo Alto Networks PAN-OS for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.
FAQ
Common questions
01Is PAN-OS a product we buy separately?
PAN-OS is the operating system that runs on every Palo Alto Networks firewall — it is what you are running whenever you run one of their NGFWs, physical or virtual. Its value is that it makes every form factor behave identically, and its releases add capability across the whole estate at once.
02What are App-ID, User-ID, and Content-ID?
They are the core PAN-OS technologies: App-ID identifies the actual application in traffic, User-ID ties policy to user identity, and Content-ID inspects content for threats, data, and URLs. Together they let you write policy on applications and users rather than ports — the basis of Zero Trust on the firewall.
03Why does the single-pass architecture matter?
It identifies and inspects each packet once rather than chaining separate engines, so full threat prevention runs without collapsing throughput. It is the design reason Palo Alto firewalls keep performance high with all protection enabled.
04How does keeping PAN-OS current help security?
PAN-OS releases add new detection and prevention capabilities and fix vulnerabilities across every form factor at once. Keeping versions current and correctly configured is a large part of the firewall estate’s real-world security — which is what Faltrox maintains.
05How does Faltrox operate it?
We maintain PAN-OS versions across your estate, apply hardening and best-practice configuration, tune App-ID and threat policy, and monitor the firewalls — delivering the software layer of managed network defence, not just the hardware.
Start an engagement
Secure what’s next.
Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.
Contact us