Prisma logo
  • Products
    Products
    Platform
    • Prisma Cloud
      Protect applications from code to cloud
    Categories
    • Cloud Security Posture Management
      Gain visibility, compliance and governance across multicloud environments
    • Cloud Workload Protection
      Secure host, containers, Kubernetes (K8s) and serverless functions
    • Application Security
      Shift left and secure applications by design
    • Cloud Infrastructure Entitlement Management Enforce least privilege access to cloud infrastructure
    • Web Application & API Security Protect applications and APIs against web based attacks
    • Cloud Network Security Secure the network that connects applications
    • Cloud Discovery & Exposure Management Combat rogue cloud deployments
    • Data Security Posture Management Classify and secure sensitive data
    • AI Security Posture Management Secure AI powered applications
  • Solutions
    Solutions
    Use Cases
    • Risk Prevention
    • Secure code by design
    • Fix misconfigurations in IaC
    • Manage OSS vulnerabilities (SCA)
    • Avoid secrets exposure
    • Protect CI/CD pipelines
    • Visibility & Control
    • Detect misconfigurations
    • Generate compliance reports
    • Reduce excessive permissions
    • Prevent cloud data breaches
    • Manage shadow clouds
    • Vulnerability management
    • Runtime Protection
    • Detect threats
    • Container and Kubernetes security
    • Protect Hosts / VMs
    • Defend serverless functions
    • Protect web applications
    • API security
    Industries
    • Government
  • Environments
    Environments
    Environments We Secure
    • Cloud Service Providers
    • Alibaba Cloud
    • Amazon Web Services
    • Google Cloud
    • Microsoft Azure
    • Oracle Cloud Infrastructure
    • Application Platforms
    • Docker
    • Kubernetes
    • Red Hat OpenShift
    • ServiceNow
    • VMWare Tanzu
    • Cloud Automation
    • HashiCorp
  • Product Tour
  • Resources
    Resources
    Product Information
    • Datasheets
    • Explore Demos
    • Technical Documentation
    • Knowledge Base
    • Support
    • Professional Services
    • Technology Partners
    • Open Source
    Learn & Connect
    • Blog
    • Research
    • DevSecTalks
    • Cloud Security Cyberpedia
    • Customer Success Stories
    • Analyst & Research Reports
    • Whitepapers
    • eBooks
    • Bootcamps
    • Videos
    • Developer Resources
    The State of Cloud-Native Security 2024 Report
    CXO Research
    The State of Cloud-Native Security 2024 Report
    Get your copy
    The Complete Cloud Security Platform.<br>End-to-End of Story.
    ON-DEMAND VIRTUAL EVENT
    The Complete Cloud Security Platform.
    End-to-End of Story.
    Watch now
palo alto networks logo icon white arrow icon pointing left to return to main Palo Alto Networks site
Search
  • Tech Docs

PAN-OS 9.0 Features

60+ additional capabilities to prevent successful cyberattacks

Fast, smart, efficient enterprise protection

With PAN-OS 9.0 we released features to keep you on the cutting edge with tightly integrated innovations. This release simplifies your operations through analytics and automation while giving you consistent protection through exceptional visibility and control across the data center, perimeter, branch, mobile and cloud networks.

 

Try the integrated DNS Security service

The DNS Security service applies predictive analytics to disrupt attacks that use DNS for command and control (C2) or data theft. Tight integration with the next-generation firewall gives you automated protections and eliminates the need for stand-alone tools. Threats hidden in DNS traffic are rapidly identified with shared threat intelligence and machine learning. Cloud-based protections are always up to date and scale infinitely, giving your organization a critical new control point to stop attacks that use DNS.

Visit the webpage

 

Stunning performance improvements

Enhancements in PAN-OS 9.0 make the PA-7000 Series the fastest Next-Generation Firewall ever. The Network Processing Card (NPC), Switch Management Card (SMC), and Log Forwarding Card (LFC) intelligently distribute processing demands, each with massive amounts of computing power and dedicated memory. The combination of amazing performance and advanced prevention capabilities makes it possible for the new PA-7000 Series to stop the most sophisticated cyberattacks even at the highest throughput levels.

 

Close dangerous policy gaps using Policy Optimizer

Moving from port-based legacy firewall rules to App-ID™ technology-based ones greatly reduces the opportunity for attack. However, that transformation takes time, effort and resources. The new Policy Optimizer makes it easy. It uses simple workflows and intelligence gathered by PAN-OS to move from legacy rules to App-ID-based controls and strengthen your security.

 

Look beneath the content with URL Filtering

URL Filtering enhancements let you go beyond black-and-white categorization, using analytics to build a security profile of each site to reduce web-based threat exposure. The service automatically examines different layers of a website’s characteristics for granular policy enforcement, including new multiple URL categories and risk ratings. With PAN-OS 9.0, URL Filtering continues to improve phishing detection with innovative new machine learning-based image recognition techniques to find and stop the most evasive phishing attempts.

Visit the webpage

 

Expand the diversity of your cloud environments

We’ve expanded the line of public, private/SDN and hybrid cloud environments supported by our VM-Series virtualized next-generation firewalls, allowing you to securely diversify your multi-cloud initiatives. In the public cloud, VM-Series firewalls now support Oracle Cloud® and Alibaba Cloud, complementing our existing support for AWS®, Microsoft Azure® and Google Cloud Platform. In the virtualized data center/SDN and hybrid arena, Cisco Enterprise Network Compute System (ENCS), VMware Cloud on AWS/NSX®-T and Nutanix® are now supported. Cisco ACI® unmanaged mode is now supported using a Panorama plugin.

VM-Series on Oracle Cloud
VM-Series on Alibaba Cloud

 

Scale performance, capacity and availability

Leveraging cloud-native services and infrastructure enhancements, the VM-Series can be deployed in both auto scaling and transitive architectures to scale up and scale out to secure dynamic and large-scale deployments. The results are a reduction in your administrative effort and a more cost-effective use of security resources. For organizations that require a data center-oriented approach to availability, the VM-Series on Azure can now be deployed in an active-passive, two-instance high availability configuration.

 

Accelerate the addition of cloud-centric security features

In PAN-OS 8.0, we released the Panorama Plugin Architecture to help accelerate the addition of new management feature velocity. PAN-OS 9.0 introduces the VM-Series Plugin Architecture to accelerate the addition of new cloud and virtualized data center security features. Support for Azure HA is delivered through the VM-Series plugin in this release. Future examples of how the plugin might be used include adding new hypervisors, licensing and provisioning/deprovisioning. For Panorama™ network security management, plugin examples include Dynamic Address Group capacity increases for AWS and Azure, delivered in October 2018, and Cisco ACI unmanaged mode, delivered with this release.

 

Manage network security on a whole new scale

New innovations to Panorama make it a whole lot easier to scale your network security. With the latest release, you can now manage up to 5,000 firewalls with a single instance of Panorama. That simplifies life for security teams and meets tight budget constraints. In addition, you can manage more firewalls using Panorama Interconnect, which links multiple Panorama instances so that you can manage up to 30,000 firewalls in a single deployment. This cuts the operational workload for administrators while also improving your company’s overall security posture.

 

Secure cellular IoT

Wide adoption of cellular IoT (CIoT) technologies for low-power wide area network (LPWAN) connectivity is enabling industrial digitalization. In particular, Narrowband IoT (NB-IoT) is one of the CIoT technologies well-suited for the LPWAN connectivity standard developed by 3GPP to enable a wide range of cellular devices and services. Complete visibility and control of the NB-IoT traffic on both signaling/control and data planes is essential to secure your CIoT services against DoS attacks from weaponized devices, malware, ransomware and other vulnerabilities.

Narrowband IoT brief


Learn

RECOMMENDED
Eye Read

Datasheet

PA-7000 Series Datasheet

RECOMMENDED
Eye Read

Datasheet

DNS Security Service

RECOMMENDED
Eye Read

Datasheet

VM-Series on Oracle Cloud

RECOMMENDED
Eye Read

Datasheet

VM-Series on Alibaba Cloud

RECOMMENDED
Eye Read

Datasheet

Advanced WildFire Privacy Datasheet

RECOMMENDED
Eye Read

Datasheet

Panorama Datasheet 

Get the latest news, invites to events, and threat alerts

By submitting this form, you agree to our Terms of Use and acknowledge our Privacy Statement.

Products and Services

  • AI-Powered Network Security Platform
  • Secure AI by Design
  • Prisma AIRS
  • AI Access Security
  • Cloud Delivered Security Services
  • Advanced Threat Prevention
  • Advanced URL Filtering
  • Advanced WildFire
  • Advanced DNS Security
  • Enterprise Data Loss Prevention
  • Enterprise IoT Security
  • Medical IoT Security
  • Industrial OT Security
  • SaaS Security
  • Next-Generation Firewalls
  • Hardware Firewalls
  • Software Firewalls
  • Strata Cloud Manager
  • SD-WAN for NGFW
  • PAN-OS
  • Panorama
  • Secure Access Service Edge
  • Prisma SASE
  • Application Acceleration
  • Autonomous Digital Experience Management
  • Enterprise DLP
  • Prisma Access
  • Prisma Access Browser
  • Prisma SD-WAN
  • Remote Browser Isolation
  • SaaS Security
  • AI-Driven Security Operations Platform
  • Cloud Security
  • Cortex Cloud
  • Application Security
  • Cloud Posture Security
  • Cloud Runtime Security
  • Prisma Cloud
  • AI-Driven SOC
  • Cortex XSIAM
  • Cortex XDR
  • Cortex XSOAR
  • Cortex Xpanse
  • Unit 42 Managed Detection & Response
  • Managed XSIAM
  • Threat Intel and Incident Response Services
  • Proactive Assessments
  • Incident Response
  • Transform Your Security Strategy
  • Discover Threat Intelligence

Company

  • About Us
  • Careers
  • Contact Us
  • Corporate Responsibility
  • Customers
  • Investor Relations
  • Location
  • Newsroom

Popular Links

  • Blog
  • Communities
  • Content Library
  • Cyberpedia
  • Event Center
  • Manage Email Preferences
  • Products A-Z
  • Product Certifications
  • Report a Vulnerability
  • Sitemap
  • Tech Docs
  • Unit 42
  • Do Not Sell or Share My Personal Information
PAN logo
  • Privacy
  • Trust Center
  • Terms of Use
  • Documents

Copyright © 2025 Palo Alto Networks. All Rights Reserved

  • Youtube
  • Podcast
  • Facebook
  • LinkedIn
  • Twitter
  • Select your language