---
title: "Configure a Palo Alto Networks (PAN) Firewall with Firmware 8.0 and Up"
slug: "configure-a-palo-alto-networks-pan-firewall-with-firmware-8-0-and-up"
updated: 2026-05-22T19:36:00Z
published: 2026-05-22T19:36:00Z
canonical: "help.8x8.com/configure-a-palo-alto-networks-pan-firewall-with-firmware-8-0-and-up"
stale: true
---

> ## Documentation Index
> Fetch the complete documentation index at: https://help.8x8.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Configure a Palo Alto Networks (PAN) Firewall with Firmware 8.0 and Up

## Objective

Configuring a Palo Alto Networks Firewall for 8x8 services.

> [!NOTE]
> Note:
> 
> Guidance on Palo Alto Networks firewalls is publicly available within [Palo Alto Networks device documentation](https://docs.paloaltonetworks.com/hardware).

## Applies To

- Palo Alto Networks Firewalls

![Image result for palo alto firewall PA 220](https://cdn.us.document360.io/e3a59e39-abd3-4423-964c-0a4008dc5673/Images/Documentation/10278)

## Procedure

The purpose of this article is to provide a **sample configuration**. At the time of article creation, this device was in a known working state on the firmware used. **Keep in mind different firmware versions will interact with hosted VoIP services in different ways.** While this device may be fully functional on the tested and/or current firmware version, it is possible newer revisions will cause disruptions in service or make a device fully compliant with the required settings for hosted VoIP services where it was previously not.

For Palo Alto Firewalls on firmware 8.0 and above.

### Administrative Information

1. Make sure your firewall is powered on and connected to your network.
2. Connect the RJ-45 Ethernet cable from the RJ-45 port on your computer to the MGT port on the firewall.
3. If necessary, change the IP address on your computer to an address in the **192.168.1.0/24** range (e.g., 192.168.1.3).
4. In a browser on a computer on the same network as the Palo Alto Networks firewall, navigate to [**https://192.168.1.1**](https://192.168.1.1)
5. Log in (default credentials shown below).
  - Username: **admin**
  - Password: **admin**

> [!NOTE]
> **Note:**
> 
> If you are not able to connect to the web interface, consult the [quick start guide for your particular device model](https://docs.paloaltonetworks.com/hardware) for additional options.

### Configuring 8x8 Voice Services on Palo Alto Networks Firewalls

#### Add 8x8 Public IP Subnets

1. Go to **Objects** > **Addresses**.
2. Click **Add**.
3. Tags can be added only if they've been manually created under the Tags field, if not then leave it blank. ![PAN05.png](https://cdn.us.document360.io/e3a59e39-abd3-4423-964c-0a4008dc5673/Images/Documentation/10288)
4. For a complete list of 8x8 subnets, see [X Series Technical Requirements](/support/docs/x-series-technical-requirements).

#### Create an Address Group for 8x8 Public IP Subnets

1. Go to **Objects** > **Address Groups**.
2. Add all entries you created in the previous screen. (The Name can be whatever you prefer.) ![PAN06.png](https://cdn.us.document360.io/e3a59e39-abd3-4423-964c-0a4008dc5673/Images/Documentation/10281)

#### Create a Security Rule on PAN System

1. Go to **Policies** > **Security**.
2. Click **Add**. ![PAN12.png](https://cdn.us.document360.io/e3a59e39-abd3-4423-964c-0a4008dc5673/Images/Documentation/10289)
3. On the General tab, name the Security Rule and add a Description as desired.
4. On the Source tab, set **Source Address** or **Source Zone** (this is any subnet or zone that will have 8x8 phones or 8x8 8x8 Work Desktop or Mobile running on it). ![PAN14.png](https://cdn.us.document360.io/e3a59e39-abd3-4423-964c-0a4008dc5673/Images/Documentation/10286)
5. Leave the User tab blank.
6. On the Destination tab, set the **Destination Address** by adding the **Destination Address group** you created earlier
7. ***Untrust (WAN/Internet)*** the zone for your network. ![PAN15.png](https://cdn.us.document360.io/e3a59e39-abd3-4423-964c-0a4008dc5673/Images/Documentation/10277)
8. On the Application tab, click **+ add** and add the following applications:
  - **8x8**
  - **web-browsing**
  - **vidyo**
  - **stun**
  - **ssl**
  - **sip-application**
  - **sip**
  - **rtp**
  - **rtp-base**
  - **rtmpt**
  - **rtmp**
  - **rtcp**
  - **jabber**
9. Set the **Service/URL Category** to **ANY** **![service-url-any.png](https://cdn.us.document360.io/e3a59e39-abd3-4423-964c-0a4008dc5673/Images/Documentation/10279)**
10. On the Actions tab, set **Action Setting** to **Allow**.
11. Click **OK**.
12. **Move the newly created security rule to the top of rule list to avoid rule conflicts.**

#### Create an Application Override Rule for UDP

1. Go to **Policies** > **Application Override**.
2. Click **Add**. ![PAN07.png](https://cdn.us.document360.io/e3a59e39-abd3-4423-964c-0a4008dc5673/Images/Documentation/10290)
3. On the General tab, name the rule and add a description.(Example below) ![PAN08.png](https://cdn.us.document360.io/e3a59e39-abd3-4423-964c-0a4008dc5673/Images/Documentation/10282)
4. On the Source tab, set **Source Address** or **Source Zone** (this is any subnet or zone that will have 8x8 phones or 8x8 8x8 Work Desktop or Mobile running on it). ![PAN09.png](https://cdn.us.document360.io/e3a59e39-abd3-4423-964c-0a4008dc5673/Images/Documentation/10283)
5. On the Destination tab, set the **Destination Address** by adding the **Destination Address group** you created earlier.
6. ***Untrust*** the zone for your network. ![PAN10.png](https://cdn.us.document360.io/e3a59e39-abd3-4423-964c-0a4008dc5673/Images/Documentation/10284)
7. On the Protocol/Application tab, select UDP. ![PAN_udpportcfg_03242021.png](https://cdn.us.document360.io/e3a59e39-abd3-4423-964c-0a4008dc5673/Images/Documentation/10287)
8. Add the following UDP ports into the **Port** field as indicated in picture below:
  - 16150
  - 26384
  - 28591-28597
  - 28693
  - 5060
  - 5061
  - 5196-5199
  - 5299
  - 5399
  - 5301
  - 5401
  - 5443

(*See* [X Series Technical Requirements](/support/docs/x-series-technical-requirements) *for more information on port ranges and services.*)

1. For **Application**, select **8x8 App**. ![PAN_app_03242021.png](https://cdn.us.document360.io/e3a59e39-abd3-4423-964c-0a4008dc5673/Images/Documentation/10276)
2. Click **OK**.
3. **Commit Changes**

## Additional Information

The phones require a minimum UDP and TCP time out of 660 seconds or 11 minutes, depending on the network setup these settings may need to be modified on the PAN

#### *Known Issues*

- Specifically Fax services don't work reliably with the higher resolution codecs.

### Additional Configuration

If needed, the 8x8 XML file can be uploaded to your Palo Alto Firewall. Follow the steps below if you would like to import the XML file to the PAN firewall.

1. Download the ![](https://cdn.us.document360.io/e3a59e39-abd3-4423-964c-0a4008dc5673/Images/Documentation/global_doc.gif)[8x8_Palo_Alto_Networks_XML](https://cdn.us.document360.io/e3a59e39-abd3-4423-964c-0a4008dc5673/Images/Documentation/8x8_Palo_Alto_Networks_XML.xml.zip) file to your computer and extract the file.
2. Go to **Objects** > **Applications**.
3. Click **Import**. ![PANXML.png](https://cdn.us.document360.io/e3a59e39-abd3-4423-964c-0a4008dc5673/Images/Documentation/10285)
4. Import the downloaded XML file.
