---
sourceDocument: Xanadu IT Operations Management
sourceDocumentLink: https://www.servicenow.com/docs/r/xanadu/it-operations-management

 Release :

    - xanadu

ft:locale :

    - en-US

ft:publication_title :

    - Xanadu IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# Palo Alto Networks firewall

# Palo Alto Networks firewall discovery {#ariaid-title1}

* Release version: Xanadu
* 
* Updated January 30, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

The ServiceNow
Discovery application uses the Next-Generation Palo Alto Firewall pattern to find Palo Alto Networks firewalls. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
The discovery pattern uses a set of SNMP calls to find the Palo Alto Networks
firewalls. Discovery uses the pattern to run horizontal discovery.

## Request apps on the Store {#palo-alto-fw-discovery__section_crv_1zm_slb}

Visit the [ServiceNow Store](https://store.servicenow.com/sn_appstore_store.do#!/store/home) website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the [ServiceNow Store version history release notes](https://www.servicenow.com/docs/bundle/store-release-notes/page/release-notes/store/sn-store-release-notes.html).{#palo-alto-fw-discovery__inline-send-to-store}

## Prerequisites {#palo-alto-fw-discovery__section_jtr_bzm_slb}

* Ensure that your network firewall device has SNMP access.
* On the ServiceNow instance, configure SNMP credentials. For more information, see [SNMP credentials](https://www.servicenow.com/docs/access?context=c_SNMPCredentials&version=xanadu&pubname=xanadu-platform-security&ft:locale=en-US).
* Add the SNMP system OID record for the Palo Alto Networks device to the ServiceNow instance. Update the following:
  * Classifier: Palo Alto Firewall
  * Class: Palo Alto Firewall Device
  {#palo-alto-fw-discovery__ul_pxv_3zm_slb}
* Deploy the pattern as follows:
  1. Download and install [Firewall extension classes](https://www.servicenow.com/docs/access?context=cmdb-ci-class-models-fw&version=xanadu&pubname=xanadu-servicenow-platform&ft:locale=en-US) from the ServiceNow Store. The app adds the new CMDB classes required for network firewall discovery.
  2. Download and install the discovery pattern from the ServiceNow Store.
  3. Sync the pattern with the appropriate MID Server.
  {#palo-alto-fw-discovery__ol_qmp_kzm_slb}
{#palo-alto-fw-discovery__ul_vfj_dzm_slb}

## Data collected by Discovery during horizontal discovery {#palo-alto-fw-discovery__section_vtj_4zm_slb}

Discovery populates the data in the CMDB when running the Next-Generation Palo Alto Firewall Pattern.  
{#palo-alto-fw-discovery__table_hrc_kh1_m2c__entry__2}

| Field | Description |
|-|-|
| IP Address \[ip_address\] | IP address of the Palo Alto device. |
| Serial number \[serial_number\] | Serial number of the Palo Alto device. |
| Fully qualified domain name \[fqdn\] | Fully qualified domain name (FQDN) of the Palo Alto device. |
| Manufacturer \[manufacturer\] | Palo Alto device manufacturer. |
| Model ID \[model_id\] | Model ID of the Palo Alto device. |
| Operational status \[operational_status\] | Indicates whether the Palo Alto device is in active state. |
| Hardware OS \[hardware_os\] | OS running on the hardware. |
| Hardware OS Version \[hardware_os_version\] | OS version running on the hardware. |
| Description \[short_description\] | Short description of the Palo Alto device. |
| Firmware version \[firmware_version\] | Palo Alto device firmware version. |
[Table 1. Palo Alto Firewall Device \[cmdb_ci_firewall_device_palo_alto\]]

{#palo-alto-fw-discovery__table_hrc_kh1_m2c}  
{#palo-alto-fw-discovery__table_zxb_5g1_m2c__entry__2}

| Field | Description |
|-|-|
| IP Address \[ip_address\] | IP address of the network adapter. |
| Alias \[alias\] | The user-assigned name for the network adapter. |
| Netmask \[netmask\] | Netmask of the network adapter. |
| MAC address \[mac_address\] | MAC address of the network adapter. |
| Name \[name\] | Name of the network adapter. |
| Configuration Item \[cmdb_ci\] | References the Palo Alto Firewall Device \[cmdb_ci_firewall_device_palo_alto\] table. |
[Table 2. Network Adapter \[cmdb_ci_network_adapter\]]

{#palo-alto-fw-discovery__table_zxb_5g1_m2c}  
{#palo-alto-fw-discovery__table_lh4_ch1_m2c__entry__2}

| Field | Description |
|-|-|
| IP Address \[ip_address\] | IP address of the Palo Alto firewall. |
| Netmask \[netmask\] | Netmask of the Palo Alto firewall. |
| Nic \[nic\] | References the Network Adapter \[cmdb_ci_network_adapter\] table. |
[Table 3. IP Address \[cmdb_ci_ip_address\]]

{#palo-alto-fw-discovery__table_lh4_ch1_m2c}  
{#palo-alto-fw-discovery__table_vpg_w2y_m2c__entry__2}

| Field | Description |
|-|-|
| Name \[name\] | Domain Name System (DNS) name of the Palo Alto firewall device. |
| IP Address \[ip_address\] | Host IP address. |
[Table 4. DNS Name \[cmdb_ci_dns_name\]]

{#palo-alto-fw-discovery__table_vpg_w2y_m2c}

## CI relationships {#palo-alto-fw-discovery__section_ond_31n_slb}

These relationships are created to support Palo Alto Networks firewall discovery:  
{#palo-alto-fw-discovery__table_ihs_gfy_m2c__entry__3}

| CI | Relationship | CI |
|-|-|-|
| IP Address \[cmdb_ci_ip_address\] | References | Netwrk Adapter \[cmdb_ci_network_adapter\] |
| Network Adapter \[cmdb_ci_network_adapter\] | Owns::Owned by | IP Address \[cmdb_ci_ip_address\] |
| Netwrk Adapter \[cmdb_ci_network_adapter\] | References | Palo Alto Firewall Device \[cmdb_ci_firewall_device_palo_alto\] |
| Palo Alto Firewall Device \[cmdb_ci_firewall_device_palo_alto\] | Extends from | Firewall Device \[cmdb_ci_firewall_device\] |
| Palo Alto Firewall Device \[cmdb_ci_firewall_device_palo_alto\] | Owns::Owned by | Netwrk Adapter \[cmdb_ci_network_adapter\] |
| Palo Alto Firewall Device \[cmdb_ci_firewall_device_palo_alto\] | Owns::Owned by | IP Address \[cmdb_ci_ip_address\] |
| Palo Alto Firewall Device \[cmdb_ci_firewall_device_palo_alto\] | Uses::Used by | Router Interface \[dscy_router_interface\] |
| Router Interface \[dscy_router_interface\] | References | Palo Alto Firewall Device \[cmdb_ci_firewall_device_palo_alto\] |
| Serial Number \[cmdb_serial_number\] | References | Palo Alto Firewall Device \[cmdb_ci_firewall_device_palo_alto\] |
[ ]

{#palo-alto-fw-discovery__table_ihs_gfy_m2c}

