Managing Firewalls at Hyperscale: OpenConfig on PAN-OS and the Future of Enterprise Network Automation

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Community Blogs
8 min read
Community Team Member

JayGolf_0-1790187253940.png

This blog was written by Feroz Vellaparambil

 

Imagine managing tens of thousands of network devices across a global infrastructure — different vendors, different APIs, different data formats. Every vendor has its own configuration syntax and its own telemetry format. Building automation that works consistently across all of them means writing and maintaining a different integration for each one.

 

This is the reality that large enterprises and hyperscalers face every day — and it's exactly the challenge that OpenConfig was designed to address.

 

OpenConfig is a vendor-neutral approach to network device management — a common set of data models and protocols that let operators configure, query, and stream telemetry from network devices regardless of vendor. When PAN-OS firewalls speak the same OpenConfig language as your routers, switches, and load balancers, your automation platform doesn't need to know it's talking to a firewall. It just works.

 

"We need our firewalls to behave like first-class citizens in our automation and observability platforms — the same APIs, the same data models, the same telemetry pipeline we use everywhere else."

 

We built the PAN-OS OpenConfig Plugin to make that possible.

 

JayGolf_1-1790186891886.png

 

Figure 1 — PAN-OS OpenConfig Architecture. Firewalls expose a gNMI server on port 9339. Collectors subscribe via dial-in (client-initiated); firewalls initiate continuous dial-out streams to customer-specified collector endpoints. Both paths deliver standard OpenConfig YANG data to the observability layer.

 

What OpenConfig Actually Means for Your Network

 

At its core, OpenConfig is two things: a set of vendor-neutral YANG data models that describe network configuration and state in a standardized way, and gNMI — the gRPC Network Management Interface — a high-performance protocol for interacting with those models.

The shift from SNMP polling to gNMI Subscribe is significant. With SNMP, your monitoring platform reaches out to the device on a schedule and asks for data. With gNMI Subscribe, the device pushes updates to your platform the moment something changes — or at precisely the interval you define. At scale, that difference can significantly reduce both device overhead and collector complexity.

 

The PAN-OS OpenConfig Plugin supports gNMI Capabilities, Get, Set, and Subscribe against a broad catalog of standard OpenConfig YANG models. It also implements gNOI (gRPC Network Operations Interface), which extends that same standards-based infrastructure to operational services alongside the core telemetry and configuration capabilities. Your existing OpenConfig toolchain, whether it's gnmic, a commercial NMS, or a custom collector, works with PAN-OS firewalls the same way it works with any other OpenConfig device on your network.

 

Broad Model Coverage: From BGP to Security Zones

 

A common question when adopting OpenConfig is whether it covers the capabilities that network operations teams already depend on.

PAN-OS OpenConfig supports a broad set of standard OpenConfig models covering key networking capabilities, including BGP, interfaces, network instances, OSPF, routing policy, LLDP, LACP, VLANs, system state, routing information, security zones, hardware components, high availability, and local routing.

 

This broad coverage helps customers use a consistent, model-driven approach across the network functions that matter most to automation and monitoring workflows.

 

Beyond standard OpenConfig models, the plugin also provides PAN-OS-specific models for capabilities such as logging and reporting, configuration, packet capture, XML API access, and file upload.

 

The result is a combination of standardized networking models and PAN-OS-specific capabilities through the OpenConfig framework.

For many operations teams, SNMP has been a foundation of network monitoring for years. As customers adopt OpenConfig, they need confidence that the operational data they rely on today can also be accessed through a standards-based interface.

 

Palo Alto Networks continues to expand OpenConfig coverage for operational information traditionally retrieved through SNMP, including system and hardware inventory, high-availability state, LACP, and BGP peer information. This expanded coverage helps customers progressively modernize their monitoring workflows without losing access to the operational data their teams depend on.

 

Instead of maintaining separate workflows for different interfaces, teams can increasingly access network state through the same OpenConfig and gNMI-based framework used for their broader automation and observability environment.

 

Example: Hardware inventory information such as component serial numbers and part numbers can be accessed through OpenConfig paths, making it available through the same model-driven framework used for other network state.

 

Two Telemetry Models for Different Operational Needs

 

One of the capabilities that large enterprise customers ask for most directly is flexible telemetry delivery — the ability to integrate PAN-OS streaming data into existing collector infrastructure without redesigning the architecture around a fixed model. PAN-OS OpenConfig supports both telemetry patterns enterprises use.

 

Dial-In: Your Collector, Your Control

 

In dial-in mode, your telemetry platform initiates the gNMI Subscribe session to the firewall. You specify exactly which paths to subscribe to, at what interval, and with what delivery mode. This integrates naturally with collector infrastructure that manages its own connection lifecycle — ideal for targeted subscriptions, ad-hoc investigation, or platforms that aggregate across many device types.

 

Dial-Out: Device-Initiated, Always-On Streaming

 

In dial-out mode, the firewall initiates the gNMI connection to a pre-configured collector endpoint and maintains it continuously — automatically reconnecting after any interruption. For enterprises that route telemetry through their own infrastructure, you specify the destination by Fully Qualified Domain Name and the firewall handles the rest. This is the right model for large fleets where managing thousands of inbound connections from a central collector is operationally impractical.

 

The gNMI Subscribe protocol gives you fine-grained control over exactly how data is delivered. Periodic sampling delivers metrics at a fixed interval. On-Change delivery sends an update only when state transitions — dramatically reducing data volume for event-driven paths like interface operational status or routing adjacency changes. For high-frequency interface counters, periodic sampling at 30-second intervals gives you consistent trending data without overwhelming your pipeline.

 

Built to Fit Into Your Automation Stack — Not Replace It

 

A core design principle behind the PAN-OS OpenConfig implementation is interoperability. The goal is not to create a new management silo — it is to make PAN-OS firewalls behave like first-class citizens in whatever OpenConfig-native toolchain you already operate.

 

That means wildcard path expressions work exactly as you'd expect. A subscription to /interfaces/interface[name=*]/state/counters returns counter data for every interface on the device without requiring you to enumerate interface names in advance. Multi-level wildcards traverse the model tree to any depth. This is essential for automation workflows that need to scale across devices with varying configurations without brittle, hard-coded path lists.

 

It also means the notification model is predictable. By default, the plugin bundles leaf updates from a single subscription into efficient batched notifications — reducing message volume for high-throughput paths. For event-sensitive paths — interface status changes, temperature thresholds, LACP state — the plugin delivers individual, unbundled notifications so your platform detects events as they happen, not in the next batch.

 

"We want our firewall telemetry to land in the same observability pipeline, with the same schema, as everything else we manage. That requires standard models — not just a REST API with a JSON payload."

 

On-Demand Packet Capture: Closing the Gap Between Telemetry and Forensics

 

Real-time telemetry tells you what's happening. When you need to understand why, you need packet-level visibility — without having to log into a device manually or write a one-off script to trigger a capture.

 

The PAN-OS OpenConfig Plugin includes a PCAP model that exposes on-demand packet capture through the standard gNMI Subscribe interface. You specify filter criteria — source and destination IPs, ports, protocol — along with termination conditions (file size, packet count, or duration) and an upload endpoint. The device runs the capture, then pushes the pcap file to your specified destination.

 

This brings forensic capability into the same programmatic surface as operational telemetry — no GUI dependency, no manual process, no operational gap between detection and investigation.

 

Customer Benefits

 

By bringing PAN-OS into a standards-based OpenConfig framework, customers can:

  • Simplify integration — use a common approach across multivendor infrastructure.
  • Scale automation — configure and manage large numbers of devices through standardized interfaces.
  • Improve visibility — stream operational telemetry into existing monitoring platforms.
  • Accelerate troubleshooting — use programmatic access to operational data and packet capture.
  • Reduce operational complexity — minimize dependence on separate vendor-specific integrations.

 

Getting Started

 

The OpenConfig plugin is available on supported PAN-OS releases, providing access to supported OpenConfig models and gNMI capabilities.

For customers looking to explore the capabilities, gnmic — an open-source gNMI client — provides a simple way to discover supported models and query or subscribe to data from a PAN-OS firewall.

 

For complete configuration instructions, supported models, gNMI paths, and operational procedures, see the PAN-OS OpenConfig Administrator's Guide.

 

A More Consistent Approach to Network Automation

 

PAN-OS OpenConfig helps reduce the integration friction between firewalls and the automation and observability platforms customers already use. With standardized data models, gNMI-based telemetry, wildcard queries, and programmatic diagnostics, customers can integrate PAN-OS into a more consistent network management workflow.

 

If your organization is building or evolving a vendor-neutral network automation platform, we'd like to show you what this looks like in practice. Reach out to your Palo Alto Networks account team to schedule a technical deep-dive.

 

 

 

 

 

 

 

 

  • 237 Views
  • 0 comments
  • 0 Likes
Labels
Contributors
Top Liked Authors