Security Subscriptions

Best-of-breed security built for tomorrow, ready today

Reduce complexity with integrated innovations

Cyber attacks are growing more frequent and sophisticated by the day. To combat this onslaught, many organizations have added proxies, intrusion prevention systems (IPSs), sandboxing, and other security point products to their old-school firewalls. But this siloed approach just leads to complexity and an even greater potential for breach. Our security technologies are natively integrated – not cobbled together – into our ML-Powered Next-Generation Firewalls, as well as our endpoint and cloud security offerings. Groundbreaking features reduce manual tasks and enhance your security posture by seamlessly working with our self-updating security platform, augmenting global threat intelligence to counter attacks automatically and in near-real time.

Threat Prevention

Go beyond a typical intrusion prevention system (IPS) to inspect all traffic for threats, regardless of port, protocol or encryption, and automatically blocks known vulnerabilities, malware, exploits, spyware, and command-and-control. Customers can import, sanitize, manage and completely automate workflows to rapidly apply IPS signatures in popular formats such as SNORT and Suricata, adding to our existing leading threat coverage.


Leverage cloud-based malware detection and multiple analysis techniques to identify and protect against unknown file-based threats, while resisting attacker evasion techniques. WildFire’s unique real-time signature streaming capability ensures your organization is protected against previously unknown threats in seconds after they are first discovered. In an industry first, WildFire deploys inline machine learning modules on the NGFW to identify and prevent new and unknown file-based threats, protecting users before a threat can even enter your network.

URL Filtering

Protect your organization against web-based threats such as phishing, malware, and command-and-control. In-line machine learning identifies and prevents new and unknown malicious websites instantly before they can be accessed by users. Web security rules are an extension of your NGFW policy, reducing complexity by giving you a single policy set to manage.

DNS Security Services

Apply predictive analytics, machine learning, and automation to block attacks that use DNS. Tight integration with the Next-Generation Firewall gives you automated protections, prevents attackers from bypassing security measures, and eliminates the need for independent tools or changes to DNS routing. Comprehensive analytics allow deep insights into threats and empower security personnel with the context to optimize their security posture.

Global Protect

Provide unmatched threat prevention capabilities to protect users against evasive application traffic, phishing, credential theft, and more. GlobalProtect™ extends the protection of our Next-generation Firewall to your mobile users.


With security natively integrated with an SD-WAN architecture, you can connect your branch offices without compromising on security. Leverage the SD-WAN subscription on your Palo Alto Networks next-generation firewall and simply enable SD-WAN and security on a single, intuitive interface.

Enterprise Data Loss Prevention (DLP)

Palo Alto Networks’ Enterprise DLP is the industry’s first cloud-delivered solution that comprehensively protects sensitive data across all networks, clouds, and users. It easily enables data protection and compliance in minutes, eliminating deployment and ongoing management cycles to ensure the most cost-effective enterprise DLP on the market. Embedded in Next-Generation FirewallVM-SeriesPrisma AccessPrisma Cloud, and Prisma SaaS, our service uses the same configuration and detection rules across control points, providing consistent data protection everywhere, eliminating the need of creating and maintaining separate sets of policies.

IoT Security

The industry’s first complete IoT security solution, delivering a machine learning-based approach to discover all unmanaged devices, detect behavioral anomalies, recommend policy based on risk, and automate enforcement without the need for additional sensors or infrastructure. This unique combination of IoT visibility and the NGFW enables context-aware network segmentation to reduce risk exposure and applies our leading security subscriptions to keep IoT and IT devices secure from all threats.

Advanced Threat Prevention

One of the leading problems for network defenders today involves the rise of highly evasive and automated attacks. With access to these sophisticated tools, adversarial “asa-service” offerings, and versions of popular red team tools, bad actors have dramatically improved the speed and success of long-term and covert attacks. The 73% year over year rise in attacks using the highly available and customizable Cobalt Strike tool is just the start of this new wave of highly evasive attacks plaguing organizations today.1 Encryption is another method attackers are leveraging to bypass traditional security controls, with reports showing that the vast majority of malware is now delivered through encrypted connections.2 Network security must evolve to stop highly evasive and unknown threats.

Advanced URL Filtering

Palo Alto Networks Advanced URL Filtering provides best-in-class web protection for the modern enterprise. Bringing together the best of both worlds, Advanced URL Filtering combines our renowned malicious URL database capabilities with the industry’s first real-time web protection engine powered by deep learning. Now, you can automatically detect and prevent new malicious and targeted web-based threats instantly. Welcome to real-time protection.