160
•
Panorama
6.1
Administrator’s
Guide
©
Palo
Alto
Networks,
Inc.
Use
Panorama
for
Visibility
Monitor
Network
Activity
Use
Panorama
for
Visibility
In
addition
to
its
central
deployment
and
firewall
configuration
features,
Panorama
also
allows
you
to
monitor
and
report
on
all
traffic
that
traverses
your
network.
While
the
reporting
capabilities
on
Panorama
and
the
firewall
are
very
similar,
the
advantage
that
Panorama
provides
is
that
it
is
a
single
pane
view
of
aggregated
information
across
all
your
managed
firewalls.
This
aggregated
view
provides
actionable
information
on
trends
in
user
activity,
traffic
patterns,
and
potential
threats
across
your
entire
network.
Using
the
Application
Command
Center
(ACC),
the
App
‐
Scope,
the
log
viewer,
and
the
standard,
customizable
reporting
options
on
Panorama,
you
can
quickly
learn
more
about
the
traffic
traversing
the
network.
The
ability
to
view
this
information
allows
you
to
evaluate
where
your
current
policies
are
adequate
and
where
they
are
insufficient.
You
can
then
use
this
data
to
augment
your
network
security
strategy.
For
example,
you
can
enhance
the
security
rules
to
increase
compliance
and
accountability
for
all
users
across
the
network,
or
manage
network
capacity
and
minimize
risks
to
assets
while
meeting
the
rich
application
needs
for
the
users
in
your
network.
The
following
topics
provide
a
high
‐
level
view
of
the
reporting
capabilities
on
Panorama,
including
a
couple
of
use
cases
to
illustrate
how
you
can
use
these
capabilities
within
your
own
network
infrastructure.
For
a
complete
list
of
the
available
reports
and
charts
and
the
description
of
each,
refer
to
the
online
help.
Monitor
the
Network
with
the
ACC
and
AppScope
Both
the
ACC
and
the
AppScope
allow
you
to
monitor
and
report
on
the
data
recorded
from
traffic
that
traverses
your
network.
The
ACC
on
Panorama
displays
a
summary
of
network
traffic.
Panorama
can
dynamically
query
data
from
all
the
managed
firewalls
on
the
network
and
display
it
in
the
ACC.
This
display
allows
you
to
monitor
the
traffic
by
applications,
users,
and
content
activity—URL
categories,
threats,
data
filtering,
file
blocking,
HIP
match
for
GlobalProtect—across
the
entire
network
of
Palo
Alto
Networks
next
‐
generation
firewalls.
The
AppScope
helps
identify
unexpected
or
unusual
behavior
on
the
network
at
a
glance.
It
includes
an
array
of
charts
and
reports—Summary
Report,
Change
Monitor,
Threat
Monitor,
Threat
Map,
Network
Monitor,
Traffic
Map—that
allow
you
to
analyze
traffic
flows
by
threat
or
application,
or
by
the
source
or
destination
for
the
flows.
You
can
also
sort
by
session
or
byte
count.
Use
the
ACC
and
the
AppScope
to
answer
questions
such
as:
ACC
Monitor
>
AppScope
What
are
the
top
applications
used
on
the
network
and
how
many
are
high
‐
risk
applications?
Who
are
the
top
users
of
high
‐
risk
applications
on
the
network?
What
are
the
top
URL
categories
being
viewed
in
the
last
hour?
What
are
the
Application
usage
trends—what
are
the
top
five
applications
that
have
gained
use
and
the
top
five
that
have
decreased
in
use?
How
has
user
activity
changed
over
the
current
week
as
compared
to
last
week
or
last
month?