Skip to main content
Connect your Palo Alto Networks firewall (PAN-OS) so Myrmex can read its configuration, audit its hardening, help you clean up policies, and — with approval — apply changes. Myrmex reaches the device over SSH through a Collector on your network, on demand — nothing is stored on the Myrmex side.

What Myrmex Can Do

Read & troubleshoot

Inspect system state, interfaces, routing, sessions, Security policies, NAT, and VPNs — read-only diagnostics, pulled live.

Hardening audit

Run a Security Posture audit against PAN-OS hardening controls.

Policy hygiene

Find shadowed, unused, or overly-permissive Security rules and Security Profiles, and propose cleanups.

Backup & diff

Back up the running configuration on demand and compare revisions over time; with approval, apply rule, object, and VPN changes.

Before You Start

  • A Collector deployed on a network that can reach the firewall’s management IP over SSH. See Deploying the agent.
  • SSH enabled on the firewall management interface.
  • An administrator account Myrmex can use to log in (a read-only role is enough for analysis; a read-write role is required to apply changes).

Step 1 — Create the Access Account on Palo Alto

1

Enable SSH on the management interface

In Device → Setup → Management → Management Interface Settings, enable the SSH service. For a data-plane interface, attach an Interface Management Profile that permits SSH.
2

Create an Admin Role (optional, recommended)

In Device → Admin Roles, create a role scoped to what Myrmex should do — or use the predefined superreader (read-only) or superuser (read-write) roles.
3

Create the administrator

In Device → Administrators, add an administrator with a strong password, assign the role above, and Commit. Note the username and password — you’ll enter them in Myrmex.
Prefer least privilege: start with a read-only account, and only grant read-write once you want the agents to apply changes for you.

Step 2 — Add the Integration in Myrmex

From the Directory, choose Add Integration → Palo Alto Firewall, then fill in:

Connect

Click Connect to validate the SSH connection and finish. The firewall then appears under Environment → Integrations, and you can start asking the AI about it in the Workspace.
This integration is operated by the Integration Specialist agent, which runs the PAN-OS CLI on your behalf. Browse more connectors in the Integrations directory.