{"id":99228,"date":"2019-06-04T06:00:41","date_gmt":"2019-06-04T13:00:41","guid":{"rendered":"https:\/\/www.paloaltonetworks.com\/blog\/?p=99228"},"modified":"2019-06-03T17:31:21","modified_gmt":"2019-06-04T00:31:21","slug":"cloud-google-cloud-palo-alto-networks-depth-look","status":"publish","type":"post","link":"https:\/\/www2.paloaltonetworks.com\/blog\/2019\/06\/cloud-google-cloud-palo-alto-networks-depth-look\/","title":{"rendered":"Google Cloud and Palo Alto Networks: A Closer Look"},"content":{"rendered":"<p><em>In this post, guest bloggers Vineet Bhan, Sheba Roy and Ashish Verma of Google Cloud share\u00a0a<span style=\"font-weight: 400;\">\u00a0closer look at product integrations between Google Cloud and Palo Alto Networks.<\/span><\/em><\/p>\n<p>&nbsp;<\/p>\n<p><img loading=\"lazy\" decoding=\"async\"  class=\" wp-image-96565 alignright lozad\"  data-src=\"https:\/\/www.paloaltonetworks.com\/blog\/wp-content\/uploads\/2019\/01\/google-cloud-event-banner_blog-500x319.png\" alt=\"\" width=\"484\" height=\"309\" srcset=\"https:\/\/www2.paloaltonetworks.com\/blog\/wp-content\/uploads\/2019\/01\/google-cloud-event-banner_blog-500x319.png 500w, https:\/\/www2.paloaltonetworks.com\/blog\/wp-content\/uploads\/2019\/01\/google-cloud-event-banner_blog-230x147.png 230w, https:\/\/www2.paloaltonetworks.com\/blog\/wp-content\/uploads\/2019\/01\/google-cloud-event-banner_blog-768x489.png 768w, https:\/\/www2.paloaltonetworks.com\/blog\/wp-content\/uploads\/2019\/01\/google-cloud-event-banner_blog-471x300.png 471w, https:\/\/www2.paloaltonetworks.com\/blog\/wp-content\/uploads\/2019\/01\/google-cloud-event-banner_blog-63x40.png 63w, https:\/\/www2.paloaltonetworks.com\/blog\/wp-content\/uploads\/2019\/01\/google-cloud-event-banner_blog.png 1251w\" sizes=\"auto, (max-width: 484px) 100vw, 484px\" \/><span style=\"font-weight: 400;\">Most enterprises have hybrid or multi-cloud deployments, and maintaining consistent security posture across all deployments is always one of their top priorities. In December 2018, we announced an <\/span><a href=\"https:\/\/cloud.google.com\/blog\/products\/identity-security\/expanding-our-partnership-with-palo-alto-networks-to-simplify-cloud-security-and-accelerate-cloud-adoption\" rel=\"nofollow,noopener\" ><span style=\"font-weight: 400;\">expanded partnership with Palo Alto Networks<\/span><\/a><span style=\"font-weight: 400;\"> with exactly that goal in mind. With <\/span><a href=\"https:\/\/cloud.google.com\/security\/products\/\" rel=\"nofollow,noopener\" ><span style=\"font-weight: 400;\">Google Cloud\u2019s native security toolkit<\/span><\/a> <span style=\"font-weight: 400;\">and deep integrations with Palo Alto Networks cloud security products such as the\u00a0<\/span><a href=\"https:\/\/www.paloaltonetworks.com\/cloud-security\/vm-series\"><span style=\"font-weight: 400;\">VM-Series<\/span><\/a><span style=\"font-weight: 400;\">, <\/span><a href=\"https:\/\/www.paloaltonetworks.com\/cloud-security\/public-cloud-products\"><span style=\"font-weight: 400;\">Prisma Public Cloud<\/span><\/a><span style=\"font-weight: 400;\">, and <\/span><a href=\"https:\/\/www.paloaltonetworks.com\/cloud-security\/prisma-saas\"><span style=\"font-weight: 400;\">Prisma SaaS<\/span><\/a><span style=\"font-weight: 400;\">, you can define a consistent security posture in Google Cloud and on-premises. Let\u2019s look into some of these integrations.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><b>Governance and compliance:<\/b><span style=\"font-weight: 400;\"> Prisma Public Cloud (formerly RedLock) provides continuous monitoring and compliance reporting for your resource configurations, network configurations, and user activity on Google Cloud. It can now detect risks and provide auto-remediation across ten core Google Cloud Platform (GCP) services, such as Compute Engine, Google Kubernetes Engine (GKE), and Cloud Storage. Prisma Public Cloud is also integrated with GCP\u2019s Security Baseline API<\/span><span style=\"font-weight: 400;\">alpha<\/span><span style=\"font-weight: 400;\"> , which provides visibility into the compliance posture of Google Cloud platform. With this integration, customers can get compliance visibility into their full stack. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">In addition, with <\/span><a href=\"https:\/\/cloud.google.com\/security-command-center\/\" rel=\"nofollow,noopener\" ><span style=\"font-weight: 400;\">Cloud Security Command Center<\/span><\/a><span style=\"font-weight: 400;\"> integration, customers can incorporate Prisma Public Cloud findings into their single pane of glass view by simply enabling the integration in <\/span><a href=\"https:\/\/console.cloud.google.com\/marketplace\/details\/redlock-gcp\/redlock-cscc\" rel=\"nofollow,noopener\" ><span style=\"font-weight: 400;\">GCP marketplace<\/span><\/a><span style=\"font-weight: 400;\">.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><b>Security analytics: <\/b><span style=\"font-weight: 400;\">Along with security governance and compliance assurance, Prisma Public Cloud integrates with <\/span><a href=\"https:\/\/cloud.google.com\/vpc\/docs\/using-flow-logs\" rel=\"nofollow,noopener\" ><span style=\"font-weight: 400;\">VPC flow logs<\/span><\/a><span style=\"font-weight: 400;\"> to provide useful insight into east-west and north-south traffic flows by correlating data with various security intelligence sources. <\/span><\/p>\n<p>&nbsp;<\/p>\n<p><b>Security for GCP workloads: <\/b><span style=\"font-weight: 400;\">Palo Alto Networks VM-Series firewalls protect both container and compute workloads and can be deployed directly through <\/span><a href=\"https:\/\/console.cloud.google.com\/marketplace\/details\/paloaltonetworksgcp-public\/vmseries-payg-bundle2?id=d08fc3ff-30ec-49fb-8263-92575f370c03&amp;project=acme-1-235022&amp;organizationId=750492540376&amp;orgonly=true&amp;supportedpurview=project\" rel=\"nofollow,noopener\" ><span style=\"font-weight: 400;\">GCP Marketplace<\/span><\/a><span style=\"font-weight: 400;\">. Deploying the VM-Series with <\/span><a href=\"https:\/\/cloud.google.com\/load-balancing\/\" rel=\"nofollow,noopener\" ><span style=\"font-weight: 400;\">Google Cloud Load Balancers<\/span><\/a><span style=\"font-weight: 400;\"> allows horizontal scalability as your workloads grow and high availability to protect against failure scenarios. VM-Series also takes advantage of <\/span><a href=\"https:\/\/cloud.google.com\/armor\/\" rel=\"nofollow,noopener\" ><span style=\"font-weight: 400;\">Cloud Armor<\/span><\/a><span style=\"font-weight: 400;\"> to block malicious IP addresses at Google\u2019s edge, saving on compute cycles that analyze other critical traffic flows. <\/span><\/p>\n<p>&nbsp;<\/p>\n<p><b>Security for hybrid containerized workloads:<\/b> <a href=\"https:\/\/cloud.google.com\/anthos\/\" rel=\"nofollow,noopener\" ><span style=\"font-weight: 400;\">Anthos<\/span><\/a><span style=\"font-weight: 400;\"> (formerly Cloud Services Platform) lets you build and manage modern hybrid applications. Istio is an open service mesh that can be deployed on Google Kubernetes Engine (GKE) as part of Anthos to provide a uniform way to connect, manage, and secure microservices. With the NGFW policy engine (an Istio mixer adapter developed by Palo Alto Networks) customers can secure east-west traffic based on attributes such as source namespace, source service, destination namespace, destination service and protocol through Panorama<\/span><span style=\"font-weight: 400;\">. The <\/span><span style=\"font-weight: 400;\">NGFW policy engine <\/span><span style=\"font-weight: 400;\">also provides detailed telemetry from the service mesh for forensics and analytics. The NGFW policy engine can be deployed to a kubernetes cluster hosted on-premise or in the cloud directly through the <\/span><a href=\"https:\/\/console.cloud.google.com\/marketplace\/details\/redlock-gcp\/ngfw-policy-engine\" rel=\"nofollow,noopener\" ><span style=\"font-weight: 400;\">GCP marketplace<\/span><\/a><span style=\"font-weight: 400;\">.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><b>Data Protection for G Suite: <\/b><span style=\"font-weight: 400;\">Prisma SaaS (formerly Aperture) is a SaaS security service that connects directly to SaaS applications for data classification, Data Loss Prevention, and threat detection. \u00a0It leverages an out-of-band, API-based approach that enables granular inspection of data at rest in G Suite as well as ongoing monitoring of user activity and administrative configurations.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"font-weight: 400;\">Learn more about our partnership and integrations at <\/span><a href=\"https:\/\/ignite.paloaltonetworks.com\/usa\/usa_home.html\"><i><span style=\"font-weight: 400;\">Ignite \u201819<\/span><\/i><\/a><span style=\"font-weight: 400;\">: <\/span><\/p>\n<p>&nbsp;<\/p>\n<ul>\n<li style=\"font-weight: 400;\"><b>Visit the Google Cloud booth (#603).<\/b><span style=\"font-weight: 400;\"> See our interactive demos such as Google Cloud SCC, Cloud Armor, VPC service controls, and integrations with Palo Alto Networks products.<\/span><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul>\n<li style=\"font-weight: 400;\"><b>Attend our sessions. <\/b><span style=\"font-weight: 400;\">On Tuesday, June 4th at 1:00 PM we\u2019ll share a comprehensive look at container security with Google Cloud. On Wednesday, June 5th at 2:10 PM join us to learn how to build highly scalable and secure deployments on Google Cloud.<\/span><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul>\n<li style=\"font-weight: 400;\"><b>Schedule 1:1 time with us. <\/b><span style=\"font-weight: 400;\">Talk with our team about whatever security questions you have. Fill out <\/span><a href=\"https:\/\/forms.gle\/qcou9pBYDLbup6Y1A\" rel=\"nofollow,noopener\" ><span style=\"font-weight: 400;\">this form<\/span><\/a><span style=\"font-weight: 400;\"> to schedule time. <\/span><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><span style=\"font-weight: 400;\">We hope to see you there,<\/span><\/p>\n<p><b>The Google Cloud Team<\/b><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In this post, guest bloggers Vineet Bhan, Sheba Roy and Ashish Verma of Google Cloud share\u00a0a\u00a0closer look at product integrations between Google Cloud and Palo Alto Networks<\/p>\n","protected":false},"author":646,"featured_media":96565,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[6768],"tags":[4378,5933,6790,6791,309],"coauthors":[6792,6793,6795],"class_list":["post-99228","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-secure-the-cloud","tag-google-cloud","tag-ignite-19-usa","tag-prisma-public-cloud","tag-prisma-saas","tag-vm-series"],"jetpack_featured_media_url":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-content\/uploads\/2019\/01\/google-cloud-event-banner_blog.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts\/99228","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/users\/646"}],"replies":[{"embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/comments?post=99228"}],"version-history":[{"count":11,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts\/99228\/revisions"}],"predecessor-version":[{"id":99343,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts\/99228\/revisions\/99343"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/media\/96565"}],"wp:attachment":[{"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/media?parent=99228"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/categories?post=99228"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/tags?post=99228"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/coauthors?post=99228"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}