Palo Alto Networks Tap Interfaces Overview

Tap interfaces in Palo Alto Networks firewalls allow for passive monitoring of network traffic without impacting the flow of that traffic. This is achieved by connecting the firewall to a switch's SPAN or mirror port, enabling the firewall to receive a copy of the traffic for analysis.

Key Characteristics

Configuration Steps

  1. Connect the firewall's tap interface to a switch port configured for SPAN or mirroring.
  2. In the firewall's web interface, navigate to Network > Interfaces , select the desired interface, and set its type to Tap .
  3. Assign the tap interface to a security zone (e.g., TapZone).
  4. Create security profiles (e.g., antivirus, anti-spyware) with actions set to alert .
  5. Define a security policy rule with both source and destination zones set to the tap zone, allowing all traffic and applying the security profiles.
  6. Commit the configuration to activate tap mode monitoring.

Limitations

Use Cases

Additional Resources