Omnixon Global
Palo Alto Networks CN-Series Container Firewall (CN-1200)

Palo Alto Networks CN-Series Container Firewall (CN-1200)

Brand: Palo Alto Networks | Category: Software

SKU: PALO-PANCN1200 | Part #: PAN-CN-1200 | MPN: PAN-CN-1200

Contact for Pricing — Request a Quote

Request a Quote Contact Us

About the Palo Alto Networks CN-Series Container Firewall (CN-1200)

The Palo Alto Networks CN-Series Container Firewall (CN-1200) is a cloud-native security appliance architected specifically for containerized workload protection within Kubernetes clusters. Launched in Q2 2023, it delivers inline threat prevention, advanced application control, and threat intelligence enforcement at the container network layer without requiring host agent installation or cluster network modifications. The solution integrates natively with Kubernetes API servers and container orchestration platforms, enabling security teams to enforce consistent policies across dynamic, ephemeral container lifecycles while maintaining microsegmentation across pods and namespaces.

The CN-1200 leverages Palo Alto Networks' third-generation security architecture, combining stateful threat prevention, SSL/TLS inspection, and machine learning-powered threat detection optimized for containerized traffic patterns. It operates as a standalone security appliance that can be deployed within or adjacent to Kubernetes clusters, providing east-west traffic inspection between pod-to-pod communications and north-south protection for ingress/egress workload flows. The platform supports both OpenShift and upstream Kubernetes distributions, with full policy integration through Kubernetes Custom Resource Definitions (CRDs) and native dashboard visibility into container-level security posture.

Delivering enterprise-grade threat prevention without operational overhead, the CN-1200 addresses the DevSecOps procurement category by enabling security policy management alongside application deployment pipelines. It supports automated policy discovery, role-based access control tuned for Kubernetes personas (cluster admins, namespace owners, security teams), and comprehensive logging compatible with enterprise SIEM ecosystems and container monitoring platforms.

Ideal for

  • Securing multi-tenant Kubernetes clusters in regulated industries (financial services, healthcare) requiring strict pod-to-pod microsegmentation and encrypted traffic inspection
  • Protecting containerized microservices architectures from lateral movement threats and zero-day exploits targeting container runtimes and application protocols
  • Enforcing consistent security policies across hybrid cloud deployments spanning on-premises OpenShift clusters and cloud-hosted Kubernetes environments
  • Enabling compliance validation (PCI-DSS, HIPAA, SOC 2) for containerized workloads through detailed threat logs, application-layer visibility, and policy audit trails
  • Detecting and blocking container escape attempts, malicious container image execution, and supply chain attacks targeting private container registries
  • Supporting rapid application deployment velocity while maintaining mandatory network segmentation and threat prevention requirements in DevSecOps workflows

Technical specifications

ManufacturerPalo Alto Networks
Product ModelCN-1200
Product CategoryKubernetes-Native Container Firewall (NGFW)
Deployment ModelAppliance-based inline security
Supported Kubernetes DistributionsOpenShift (4.x+), upstream Kubernetes (1.20+), EKS, AKS, GKE
Traffic InspectionStateful firewall, SSL/TLS decryption, application-layer threat prevention
Maximum Throughput10 Gbps (aggregate north-south and east-west)
Concurrent Sessions500,000+ concurrent connections
Policy Enforcement ScopePod-to-pod (east-west), namespace boundaries, ingress/egress north-south flows
Threat Prevention ModulesMalware protection, intrusion prevention (IPS/IDS), application control, DNS security, threat intelligence feeds
Machine Learning DetectionContainer anomaly detection, behavioral threat identification, zero-day exploit prevention
Policy ManagementKubernetes-native CRD policy definitions, YAML-based declarative security, role-based access control (RBAC)
Logging & TelemetryJSON-structured logs, syslog forwarding, native integration with Splunk, ELK, Datadog, Prometheus
API IntegrationKubernetes API server integration, container registry scanning APIs, CI/CD webhook support
Protocol SupportIPv4/IPv6, TCP, UDP, ICMP, GRE, IPv6-in-IPv4 tunneling, VXLAN encapsulation
Management InterfaceWeb-based management console, CLI, Kubernetes-native dashboard, RESTful APIs
High AvailabilityActive-active clustering with state synchronization, pod-aware failover
Container Runtime SupportDocker, containerd, CRI-O runtimes compatible via Kubernetes interface
Data EncryptionEncrypted policy transport (TLS 1.2+), support for encrypted pod-to-pod communication inspection

Available from Omnixon Global. Submit an RFQ and our team will confirm configuration and availability for your order.

Technical Specifications

BrandPalo Alto Networks
CategorySoftware
SKUPALO-PANCN1200
Part NumberPAN-CN-1200
ConditionNew
Product ModelCN-1200
Product CategoryKubernetes-Native Container Firewall (NGFW)
Deployment ModelAppliance-based inline security
Supported Kubernetes DistributionsOpenShift (4.x+), upstream Kubernetes (1.20+), EKS, AKS, GKE
Traffic InspectionStateful firewall, SSL/TLS decryption, application-layer threat prevention
Maximum Throughput10 Gbps (aggregate north-south and east-west)
Concurrent Sessions500,000+ concurrent connections
Policy Enforcement ScopePod-to-pod (east-west), namespace boundaries, ingress/egress north-south flows
Threat Prevention ModulesMalware protection, intrusion prevention (IPS/IDS), application control, DNS security, threat intelligence feeds
Machine Learning DetectionContainer anomaly detection, behavioral threat identification, zero-day exploit prevention
Policy ManagementKubernetes-native CRD policy definitions, YAML-based declarative security, role-based access control (RBAC)
Logging & TelemetryJSON-structured logs, syslog forwarding, native integration with Splunk, ELK, Datadog, Prometheus
API IntegrationKubernetes API server integration, container registry scanning APIs, CI/CD webhook support
Protocol SupportIPv4/IPv6, TCP, UDP, ICMP, GRE, IPv6-in-IPv4 tunneling, VXLAN encapsulation
Management InterfaceWeb-based management console, CLI, Kubernetes-native dashboard, RESTful APIs
High AvailabilityActive-active clustering with state synchronization, pod-aware failover
Container Runtime SupportDocker, containerd, CRI-O runtimes compatible via Kubernetes interface
Data EncryptionEncrypted policy transport (TLS 1.2+), support for encrypted pod-to-pod communication inspection

Frequently Asked Questions about Palo Alto Networks CN-Series Container Firewall (CN-1200)

What does the Palo Alto Networks CN-Series Container Firewall (CN-1200) do?

The Palo Alto Networks CN-Series Container Firewall (CN-1200) is enterprise IT hardware deployed in production data centers, server rooms, and edge sites across the GCC and EMEA region.

What are the headline specs of the Palo Alto Networks CN-Series Container Firewall (CN-1200)?

Key specifications for the Palo Alto Networks CN-Series Container Firewall (CN-1200): new condition; manufacturer Palo Alto Networks; product model CN-1200; product category Kubernetes-Native Container Firewall (NGFW); deployment model Appliance-based inline security; supported kubernetes distributions OpenShift (4.x+), upstream Kubernetes (1.20+), EKS, AKS, GKE; traffic inspection Stateful firewall, SSL/TLS decryption, application-layer threat prevention. Manufacturer part number PAN-CN-1200. For the full datasheet with electrical, environmental, and compliance details, contact our pre-sales engineering team.