Overview
This service is designed to transform and optimize Layer 3 and Layer 4 security policies into advanced Layer 7 (App-ID) configurations on Palo Alto Networks devices already deployed in the customer’s AWS infrastructure. Focused on maximizing the performance of existing policies, it does not include design or architecture, ensuring a quick and efficient implementation.
What does the service include?
Advanced Configuration: Activation of App-ID, SSL decryption, QoS, and enabling of User-ID with identification sources (802.1x, RADIUS, LDAP, or XML API).
Policy Optimization: Migration of port-based rules to application-based rules. Custom configuration of Group Mapping and review of security rules based on customer needs.
Filtering and Protection: Deployment of SSL decryption policies for high-risk categories and content filtering using PANDB, including blocking critical categories.
Key Benefits
Better Visibility and Control: Active monitoring of traffic with session decryption and log validation.
Enhanced Protection: Enabling of Content-ID and recommendations for antivirus and antispyware profiles.
Guided Implementation: Up to 4 remote training sessions (4 hours each) to ensure correct usage and maintenance of the system.
This service is available exclusively for Palo Alto Networks devices already deployed on the customer’s network. The delivery includes detailed documentation of the changes made, ensuring a smooth transition focused on strengthening the security of your AWS environment.
Highlights
- Tailored Deployment of Cortex XDR: Progressive implementation of 60% to 80% of the acquired agents, accompanied by console setup aligned with recommended standards. Protection policies, security profiles, and prevention configurations will be adjusted to meet the client’s specific requirements.
- Enhanced Administration and Environment Visibility: Configuration of Directory Sync and Cloud Identity Engine, definition of ten key custom rules, assignment of administrative roles, and development of tailored reports — all aimed at enabling efficient and secure management of the technology environment.
- Technical Documentation and Final Validation: Delivery of the project timeline, comprehensive documentation of the deployed environment (including all configured components), and final adjustments involving the cleanup of temporary configurations and handling of exceptions. This ensures a fully validated solution supported by complete technical documentation.
Details
Unlock automation with AI agent solutions

Pricing
Custom pricing options
How can we make this page better?
Legal
Content disclaimer
Support
Vendor support
Our agreement offers 24/7 support* to ensure you always have help available when you need it. We are committed to a response time of under 15 minutes, providing you with quick and efficient assistance. Additionally, we have experts who take care of coordinating everything to resolve the issue smoothly. You can contact us anytime via phone, email, chat, or any other available platform, depending on what is most convenient for you. Some restrictions may apply. If you need more information, you can reach our technical support at +57 3042837142 or email us at helpdesk@andeantrade.com.coÂ