What Myrmex Can Do
Read & troubleshoot
Inspect system state, interfaces, routing, sessions, Security policies, NAT, and VPNs — read-only diagnostics, pulled live.
Hardening audit
Run a Security Posture audit against PAN-OS hardening controls.
Policy hygiene
Find shadowed, unused, or overly-permissive Security rules and Security Profiles, and propose cleanups.
Backup & diff
Back up the running configuration on demand and compare revisions over time; with approval, apply rule, object, and VPN changes.
Before You Start
- A Collector deployed on a network that can reach the firewall’s management IP over SSH. See Deploying the agent.
- SSH enabled on the firewall management interface.
- An administrator account Myrmex can use to log in (a read-only role is enough for analysis; a read-write role is required to apply changes).
Step 1 — Create the Access Account on Palo Alto
1
Enable SSH on the management interface
In Device → Setup → Management → Management Interface Settings, enable the SSH service. For a data-plane interface, attach an Interface Management Profile that permits SSH.
2
Create an Admin Role (optional, recommended)
In Device → Admin Roles, create a role scoped to what Myrmex should do — or use the predefined superreader (read-only) or superuser (read-write) roles.
3
Create the administrator
In Device → Administrators, add an administrator with a strong password, assign the role above, and Commit. Note the username and password — you’ll enter them in Myrmex.
Step 2 — Add the Integration in Myrmex
From the Directory, choose Add Integration → Palo Alto Firewall, then fill in:Connect
Click Connect to validate the SSH connection and finish. The firewall then appears under Environment → Integrations, and you can start asking the AI about it in the Workspace.This integration is operated by the Integration Specialist agent, which runs the PAN-OS CLI on your behalf. Browse more connectors in the Integrations directory.