Book Image

Securing Remote Access in Palo Alto Networks

By : Tom Piens aka Piens aka 'reaper'
Book Image

Securing Remote Access in Palo Alto Networks

By: Tom Piens aka Piens aka 'reaper'

Overview of this book

This book builds on the content found in Mastering Palo Alto Networks, focusing on the different methods of establishing remote connectivity, automating log actions, and protecting against phishing attacks through user credential detection. Complete with step-by-step instructions, practical examples, and troubleshooting tips, you will gain a solid understanding of how to configure and deploy Palo Alto Networks remote access products. As you advance, you will learn how to design, deploy, and troubleshoot large-scale end-to-end user VPNs. Later, you will explore new features and discover how to incorporate them into your environment. By the end of this Palo Alto Networks book, you will have mastered the skills needed to design and configure SASE-compliant remote connectivity and prevent credential theft with credential detection.
Table of Contents (11 chapters)
1
Section 1: Leveraging the Cloud and Enabling Remote Access
6
Section 2: Tools, Troubleshooting, and Best Practices

Learning about advanced configuration features

In this section, we will take a look at the less common and more advanced features that can be set in GlobalProtect to provide more flexibility or increase security, or both. First, we will look at integrating authentication with Security Assertion Markup Language (SAML).

Integrating SAML into authentication methods

With more and more services moving to the cloud, it makes sense for organizations to also move (part of) their Active Directory into the cloud. This makes setting up authentication for GlobalProtect a little more challenging as there may no longer be an option, or a need, to use older protocols such as LDAP or RADIUS in favour of newer authentication standards such as SAML.

Configuring Microsoft Azure for SAML SSO

Microsoft Azure provides a user-friendly experience and has a free option with limited features but sufficient capabilities for you to experiment with, so I will start from Azure as a template for other...