Management and Data Planes of Palo Alto Firewall
The management plane and data-plane functionality is integral to Palo Alto Networks firewalls (on both physical and virtual firewalls). These two planes have dedicated hardware resources (CPU, RAM, and Storage), which makes them independent of each other. The heavy use of one plane will not adversely impact the other planes performance, if we have this kind of separation. For example, if a very processor-intensive report is run by the administrator, the ability to process the packets would not be affected by this job because of this separation of the data and control planes.
The management features, which are provided by the control plane of the firewall are:
- Firewall configuration
- Logging
- Reporting
The data processing features, which are provided by the data plane of the firewall are:
- Signature matching
- Security processing
- Network processing










