Palo Alto Networks CN-Series Medium Container Firewall in Dubai, UAE
CN-Series Medium is a sizing profile for Palo Alto Networks’ container-native firewall platform. It is intended for supported Kubernetes deployments that require Layer 7 visibility, policy enforcement and threat-prevention controls closer to cloud-native workloads, while retaining central management through Panorama.
Container-native NGFW
Supported Kubernetes
Panorama required
CN-NGFW vCPU usage
Direct answer for business buyers
Palo Alto Networks CN-Series Medium is not a conventional rack-mounted appliance. It is a medium resource profile within the CN-Series container firewall architecture for securing supported Kubernetes workloads. Organisations should consider it when they need application-level visibility and security policy enforcement for inbound, outbound or east-west container traffic, with governance through Panorama. Before proceeding, confirm the exact PAN-OS release, Kubernetes platform, deployment method, CNI compatibility, node capacity, anticipated traffic and required security subscriptions. The word “Medium” describes a deployment size rather than a universal fixed performance guarantee; actual results depend on the allocated resources, traffic mix, enabled inspection features and cluster design.
What the CN-Series Medium does
The platform brings Palo Alto Networks next-generation firewall controls into containerised environments. It can identify applications at Layer 7, use Kubernetes context when building policy, inspect permitted traffic and apply security controls to traffic paths that traditional perimeter firewalls may not see clearly.
CN-Series is deployed as container components rather than as a standalone physical box. The distributed architecture includes management and firewall pods, and the selected mode determines how traffic is redirected or processed. This makes architecture validation essential before licensing or implementation.
Who should consider it
The Medium profile may be relevant to organisations operating production Kubernetes clusters with a meaningful level of application traffic, multiple namespaces, regulated workloads or a requirement to align container security with existing Palo Alto Networks policies. It can be considered by platform engineering, DevSecOps, network security and cloud architecture teams working together.
It is less suitable when the environment is not supported, when the buyer expects a physical appliance, or when the organisation does not have the operational capability to manage Panorama, Kubernetes resources, certificates, images, policy and lifecycle updates as one coordinated service.
Business challenges and how the platform responds
Limited east-west visibility
Container workloads can communicate dynamically across namespaces, services and nodes. CN-Series can help security teams apply application-aware controls within supported traffic paths rather than relying only on an external perimeter.
Policy inconsistency
Organisations already using Palo Alto Networks may want a consistent policy and management approach across physical, virtual, cloud and container environments. Panorama provides the central management plane for CN-Series configuration and licensing.
Rapid cluster change
Kubernetes nodes and workloads can scale or move quickly. CN-Series deployment methods use Kubernetes-native patterns, Helm charts and supported templates so security can be incorporated into a controlled DevOps workflow.
Unclear security ownership
The platform creates a practical control point where network security teams define policy while platform teams manage cluster resources and deployment pipelines. Clear ownership remains necessary for upgrades, incident response and change control.
Core capabilities buyers should evaluate
Identify and control traffic based on applications rather than only ports and IP addresses.
Use workload context such as namespaces and services where supported by the deployment.
Inspect permitted traffic and apply threat-prevention functions according to licensed services and policy.
Manage configuration and licensing through Panorama alongside other Palo Alto Networks firewalls.
Product-fit decision matrix
| Requirement | Suitable when | Confirm before ordering |
|---|---|---|
| Container traffic control | You need policy for supported Kubernetes traffic paths | Deployment mode and traffic redirection design |
| Medium deployment profile | Small sizing lacks planned capacity or headroom | CPU, memory, throughput assumptions and enabled services |
| Unified operations | Panorama is part of the security management strategy | Panorama version, plugin and operational ownership |
| Advanced inspection | Threat, DNS or URL controls are required | Applicable subscriptions, decryption design and resource impact |
| Cloud-native automation | Security deployment must fit controlled CI/CD processes | Helm, registry, secrets, rollback and change procedures |
Technical and purchasing information
| Brand | Palo Alto Networks |
|---|---|
| Product name | CN-Series Medium Container Firewall |
| Product type | Container-native next-generation firewall sizing profile |
| Deployment environment | Supported Kubernetes and OpenShift environments; exact compatibility depends on PAN-OS, platform, CNI and deployment mode |
| Architecture | Distributed CN-MGMT and CN-NGFW container components |
| Management | Panorama is required for configuration and license management |
| Deployment tooling | Helm charts are recommended; supported templates and workflows vary by environment |
| Licensing | Based on the total vCPUs used by deployed CN-NGFW pods; current credit and subscription structure must be confirmed |
| Security services | License and subscription dependent |
| Medium sizing resources | Version and deployment-mode dependent; confirm against the current official system-requirements table |
| High availability and resilience | Architecture dependent; requires cluster, management and traffic-path planning |
| Included components | Not confirmed; license entitlement, images, support and subscriptions must be validated in the quotation |
| Availability | Contact FourTeck for current UAE license and service options |
| Important note | CN-Series Medium is not available in every historical deployment mode or software release. Exact current support must be verified before purchase. |
Compatibility, licensing and resource dependencies
A correct CN-Series quotation cannot be prepared from the product name alone. Palo Alto Networks publishes compatibility and system-requirement guidance by PAN-OS release and deployment mode. A Medium profile that is supported in one service-based architecture may not be available in another mode or older release. The buyer should provide the Kubernetes distribution, version, container runtime, CNI, Linux kernel details where relevant, cloud provider, node instance type, planned number of firewall pods and expected traffic route.
Licensing is linked to the total number of vCPUs consumed by CN-NGFW pods. This means cluster growth, autoscaling and deployment changes can affect entitlement consumption. Security subscriptions may add functions such as advanced threat, DNS or URL controls, but they can also change resource requirements and policy design. Panorama, supported images, deployment files, authentication information, certificates and a controlled image registry process form part of the wider deployment dependency. FourTeck should review these items with the customer’s platform and security teams before finalising the bill of materials.
A practical purchase and deployment journey
Discover
Document clusters, workloads, traffic paths, compliance needs and the existing Palo Alto Networks estate.
Validate
Check current PAN-OS, Kubernetes, CNI, deployment-mode and Panorama compatibility.
Size
Estimate resource requirements, CN-NGFW vCPU consumption, traffic load and operational headroom.
Quote
Confirm licenses, subscriptions, support, implementation tasks and destination requirements.
Implement
Deploy through approved manifests or Helm workflows, test policy and document rollback procedures.
Application-aware policy inside Kubernetes
Traditional controls that depend mainly on fixed addresses and ports can be difficult to operate in a dynamic Kubernetes environment. Pods are recreated, services change and applications can communicate across namespaces or nodes. CN-Series is designed to give policy teams richer application and Kubernetes context. This can help an organisation express security intent in terms that remain meaningful even when workload placement changes.
The operational value is not simply “more inspection.” The main benefit is the opportunity to connect cloud-native traffic policy with the same governance model used across other Palo Alto Networks firewalls. Security administrators can define rules and review logs through Panorama, while platform engineers retain responsibility for cluster resources, service accounts, deployment manifests and release processes. That division of responsibility needs to be agreed before production launch.
Application identification and content inspection may require traffic to be routed through the correct enforcement path. Encrypted traffic creates additional design questions around certificate management, decryption policy, privacy and resource load. Buyers should therefore map important application flows first, then decide which flows need visibility, prevention, logging or exceptions. A broad “inspect everything” requirement without capacity planning can create avoidable performance and operational risk.
Central management without ignoring Kubernetes operations
Panorama provides a familiar management layer for organisations that already use Palo Alto Networks firewalls. It handles CN-Series configuration and licensing, supporting consistent security policy, logging and administrative control. However, Panorama is not a Kubernetes orchestrator. Cluster deployment, node scheduling, images, secrets, service accounts and lifecycle actions remain part of the Kubernetes operating model.
This distinction affects the project plan. Network security teams should not assume that purchasing the license automatically deploys a complete enforcement service. Platform teams should not assume that a Helm installation alone produces an approved security policy. A successful implementation needs coordinated work across network security, cloud engineering, application owners, risk teams and support functions.
FourTeck can help structure the discussion by separating the commercial bill of materials from the implementation scope. The commercial review covers credits, entitlement, subscriptions, support and available services. The technical review covers platform compatibility, resource reservations, image access, Panorama communication, traffic steering, logging, policy migration, testing and handover. This separation reduces the chance of omitted dependencies and gives procurement a clearer basis for comparing quotations.
Scaling, resilience and lifecycle control
The Medium profile should be selected through workload and resource analysis rather than by name alone. Sizing depends on the number of CN-NGFW pods, vCPUs allocated to each pod, the deployment architecture, traffic volume, packet characteristics, enabled subscriptions, logging and decryption requirements. Cluster autoscaling can also influence licensing consumption and operational behaviour.
Resilience should be designed across several layers. Kubernetes can restart pods and reschedule workloads, but the security architecture must still account for management availability, traffic-path continuity, image access, configuration retrieval, license state and log forwarding. Maintenance events, node drain procedures and version upgrades should be tested in a non-production environment before being introduced to critical clusters.
Lifecycle planning should include the PAN-OS train, supported Kubernetes versions, CNI compatibility, Helm or YAML versions, container images, Panorama versions and plugins. A cluster upgrade can affect firewall compatibility, and a firewall upgrade can require new deployment files or operational steps. The buyer should assign owners for release monitoring, compatibility review, change approval, rollback and vendor support escalation.
Ideal environments and use cases
Regulated digital platforms
Financial, healthcare and government-related teams may need stronger visibility and documented policy controls between containerised services, subject to their compliance framework and architecture.
Hybrid application estates
Organisations operating physical, virtual, cloud and Kubernetes workloads may value a common firewall management approach across different infrastructure types.
Multi-team Kubernetes clusters
Clusters shared by several teams or namespaces can benefit from carefully designed segmentation and visibility, especially where native controls alone do not meet the organisation’s policy requirements.
Internet-facing container services
Inbound and outbound inspection may support protection of application services and control of communications to suspicious or unauthorised destinations, depending on subscriptions and routing.
Integration and operational considerations
Integration starts with supported platform components. Confirm the Kubernetes distribution, container runtime, CNI and kernel requirements for the intended PAN-OS release. Determine whether the deployment will use a DaemonSet, Kubernetes service or another supported mode, because resource behaviour and traffic handling differ. Confirm how images will be pulled into the customer’s registry, how credentials will be protected and how updates will be promoted across environments.
Logging and monitoring also need design. Decide which logs will remain in Panorama, which will be forwarded to a SIEM and how alerts will reach operations teams. Define who can change security policy, who can modify Kubernetes deployment values and how emergency changes will be reconciled with infrastructure-as-code repositories. Testing should include allowed and blocked flows, application identification, subscription-dependent prevention, pod restart, node failure, scale events and rollback.
Questions to resolve before requesting a quote
Procurement checklist
☐ Exact product and Medium profile confirmed
☐ Required quantity or cluster count
☐ Kubernetes and OpenShift versions
☐ CNI and container runtime details
☐ Selected deployment architecture
☐ CN-MGMT and CN-NGFW resource plan
☐ Panorama version and plugin readiness
☐ CN-NGFW vCPU license estimate
☐ Security subscription requirements
☐ Image registry and credential process
☐ Logging and SIEM integration scope
☐ Implementation, testing and handover scope
☐ Support term and escalation expectations
☐ UAE delivery or project coordination details
How FourTeck can assist
FourTeck can help translate a Kubernetes security requirement into a clearer commercial and technical request. The process can include reviewing the current cluster architecture, identifying the appropriate CN-Series deployment profile, checking which compatibility information must be validated, estimating the required CN-NGFW vCPU entitlement and discussing relevant security subscriptions. This does not replace vendor documentation or customer testing, but it can reduce ambiguity before procurement.
Where implementation assistance is requested, the scope can address preparation, configuration coordination, policy planning, test cases, logging, operational documentation and handover. The final quotation should state which services are included, which customer inputs are required and which activities remain with the cloud provider, application team or Palo Alto Networks support. For broader cybersecurity planning, explore FourTeck firewall services, review the enterprise security product range, or contact the Dubai technology team.
UAE availability and support guidance
Contact FourTeck to confirm current UAE availability for CN-Series licensing, subscriptions and related implementation services. Availability may depend on the selected license model, PAN-OS release, subscription term, quantity, region and vendor lead time. Delivery in this context may involve entitlement, software access, container images, support activation and project coordination rather than shipment of a physical appliance.
Businesses in Dubai, Abu Dhabi, Sharjah and Ajman can discuss requirement review, quotation preparation, licensing clarification, deployment planning and support scope through one coordinated enquiry. Installation and configuration activities should be listed separately in the quotation when required. Share the exact cluster environment, desired schedule and operational responsibilities so the proposed scope can be assessed accurately.
GCC Availability
FourTeck can assist organisations planning CN-Series projects across the GCC with requirement review, deployment-profile selection, licensing discussions, quotation coordination and implementation-scope planning. Buyers in the United Arab Emirates, Saudi Arabia, Kuwait, Qatar, Bahrain and Oman should provide the destination country, Kubernetes platform, cluster quantity, intended deployment mode, subscription needs and target schedule. These details matter because product entitlements, service arrangements, vendor lead times and project delivery conditions can vary by country and requirement.
A regional quotation should distinguish software or credit entitlement from configuration, remote assistance, onsite activity, training and ongoing support. It should also identify customer responsibilities for cloud access, Panorama, image registries, certificates and change approvals. FourTeck can coordinate the commercial discussion and help buyers prepare the information required for a more accurate response. For Kuwait-specific enquiries, visit FourTeck Kuwait technology support. Local stock, fixed delivery dates, certification and onsite coverage should be confirmed for the exact destination rather than assumed.
Africa Availability
Organisations evaluating CN-Series in Africa can contact FourTeck for product, licensing and deployment-planning guidance. The review may cover Kubernetes compatibility, required CN-NGFW vCPUs, subscriptions, Panorama dependencies, implementation scope, support expectations and renewal planning. Projects in East Africa, West Africa, Southern Africa or Central Africa can have different licensing, shipping, connectivity, power, data-residency and onsite-service considerations, even though CN-Series itself is a software and container-based platform.
Buyers should share the destination country, cluster architecture, quantity, preferred deployment schedule and whether remote or onsite assistance is expected. Fulfilment can depend on entitlement region, vendor lead time, access to required images, local project conditions and customer readiness. FourTeck does not assume immediate regional inventory or guaranteed installation coverage. Relevant regional contacts include FourTeck Kenya, FourTeck Uganda and the FourTeck Africa technology portal.
Related products and services to evaluate
Panorama management
Required for CN-Series configuration and licensing. Confirm version, capacity and operational ownership.
Security subscriptions
Threat, DNS, URL and other services may be relevant, subject to current licensing and architecture.
CN-Series Small or Large
Nearby sizing profiles may be more appropriate after resource and traffic analysis; do not choose solely by cluster count.
Implementation services
Planning, configuration, policy migration, testing and handover can be scoped separately from license procurement.
Virtual or cloud firewalls
VM-Series or cloud-delivered options may fit traffic paths that do not require a container-native enforcement point.
Network security consultation
Use Firewall Dubai by FourTeck to review wider firewall and cloud-security requirements.
Why businesses contact FourTeck
The practical value of a FourTeck discussion is requirement clarification. CN-Series projects combine product entitlement, Kubernetes architecture, security policy and ongoing operations. A request that states only “CN-Series Medium” does not identify the number of licensed vCPUs, required subscriptions, supported deployment mode or implementation responsibilities. FourTeck can help organise those questions before the buyer approves a purchase.
Support can include model and profile selection, bill-of-material guidance, compatibility review, quotation coordination, installation planning, configuration scope, migration discussion and renewal guidance. These activities are defined according to the project and should not be assumed to be included automatically. Learn more about FourTeck or use the contact page to share the technical requirement.
Frequently asked questions
Is CN-Series Medium a physical firewall appliance?
No. It is a medium sizing profile for Palo Alto Networks’ container-native firewall platform, deployed as container components in supported Kubernetes environments.
What is the Medium profile mainly used for?
It is considered when a supported CN-Series deployment needs more resources or operational headroom than a smaller profile. Final sizing depends on traffic, inspection, resource allocation and architecture.
Does CN-Series require Panorama?
Yes. Panorama is required for configuration and license management. Its version, plugins, connectivity and capacity must be checked during planning.
How is CN-Series licensed?
Licensing is based on the total number of vCPUs used by deployed CN-NGFW pods. Credits, deployment profiles, subscriptions and current commercial terms should be confirmed in the quotation.
Can CN-Series Medium be deployed in every mode?
No. Availability of the Medium profile can vary by PAN-OS release and deployment mode. Palo Alto Networks documentation notes historical restrictions, so current compatibility must be validated.
Which Kubernetes platforms are supported?
Support depends on PAN-OS, Kubernetes or OpenShift version, container runtime, CNI, kernel and deployment mode. The exact environment should be checked against the current compatibility matrix.
Are advanced security services included?
Do not assume they are included. Threat, DNS, URL and other capabilities can be subscription dependent and should be itemised in the proposal.
Can FourTeck help with deployment?
FourTeck can discuss assessment, configuration, policy planning, testing and handover. The precise remote or onsite scope must be defined and quoted separately.
What information is needed for a Dubai quote?
Provide the cluster platform, version, deployment mode, number of clusters and nodes, planned CN-NGFW vCPUs, Panorama details, subscriptions, support level and implementation expectations.
Is current UAE availability guaranteed?
No. License and service availability can depend on region, quantity, term, software version and vendor lead time. FourTeck will confirm current options after reviewing the requirement.
Plan the CN-Series requirement before licensing
Share your Kubernetes architecture, Panorama status, expected traffic, required subscriptions and implementation scope. FourTeck can help prepare a clearer sizing and quotation request for Dubai and regional projects.


Reviews
There are no reviews yet.