Book Image

Mastering Palo Alto Networks

By : Tom Piens aka Piens aka 'reaper'
Book Image

Mastering Palo Alto Networks

By: Tom Piens aka Piens aka 'reaper'

Overview of this book

To safeguard against security threats, it is crucial to ensure that your organization is effectively secured across networks, mobile devices, and the cloud. Palo Alto Networks’ integrated platform makes it easy to manage network and cloud security along with endpoint protection and a wide range of security services. With this book, you'll understand Palo Alto Networks and learn how to implement essential techniques, right from deploying firewalls through to advanced troubleshooting. The book starts by showing you how to set up and configure the Palo Alto Networks firewall, helping you to understand the technology and appreciate the simple, yet powerful, PAN-OS platform. Once you've explored the web interface and command-line structure, you'll be able to predict expected behavior and troubleshoot anomalies with confidence. You'll learn why and how to create strong security policies and discover how the firewall protects against encrypted threats. In addition to this, you'll get to grips with identifying users and controlling access to your network with user IDs and even prioritize traffic using quality of service (QoS). The book will show you how to enable special modes on the firewall for shared environments and extend security capabilities to smaller locations. By the end of this network security book, you'll be well-versed with advanced troubleshooting techniques and best practices recommended by an experienced security engineer and Palo Alto Networks expert.
Table of Contents (18 chapters)
1
Section 1: First Steps and Basic Configuration
4
Section 2: Advanced Configuration and Putting the Features to Work
10
Section 3: Maintenance and Troubleshooting

Integrating Palo Alto Networks with Splunk

Splunk is a popular log aggregator and analyzer that can collect logs from many different sources and return information gathered from those logs in a wide variety of dashboards and "single panes of glass." To connect a firewall to Splunk, you will first need to set up a syslog-ng server to receive syslog messages from the firewall. Take the following steps to prepare your Splunk instance.

Depending on your flavor of Linux, the following instructions may vary. I've included yum and apt-get:

  1. You may need to uninstall rsyslog as per Splunk's recommendations:
    sudo rpm -e --nodeps rsyslog
    sudo apt-get remove rsyslog
  2. Install syslog-ng:
    sudo yum-get install syslog-ng
    sudo apt-get install syslog-ng
  3. Once the installation is complete, start syslog:
    sudo systemctl start syslog-ng.service
    sudo systemctl enable syslog-ng.service
  4. Lastly, verify whether syslog-ng is running by fetching the process ID:
    sudo pidof...