Book Image

Securing Remote Access in Palo Alto Networks

By : Tom Piens aka Piens aka 'reaper'
Book Image

Securing Remote Access in Palo Alto Networks

By: Tom Piens aka Piens aka 'reaper'

Overview of this book

This book builds on the content found in Mastering Palo Alto Networks, focusing on the different methods of establishing remote connectivity, automating log actions, and protecting against phishing attacks through user credential detection. Complete with step-by-step instructions, practical examples, and troubleshooting tips, you will gain a solid understanding of how to configure and deploy Palo Alto Networks remote access products. As you advance, you will learn how to design, deploy, and troubleshoot large-scale end-to-end user VPNs. Later, you will explore new features and discover how to incorporate them into your environment. By the end of this Palo Alto Networks book, you will have mastered the skills needed to design and configure SASE-compliant remote connectivity and prevent credential theft with credential detection.
Table of Contents (11 chapters)
1
Section 1: Leveraging the Cloud and Enabling Remote Access
6
Section 2: Tools, Troubleshooting, and Best Practices

Leveraging quarantine to isolate agents

In Chapter 1, Centralizing Logs, we learned about built-in actions in log forwarding profiles and we saw that there is a quarantine option. So, how can this option be leveraged to protect the core network?

If suspected devices are not allowed to connect under any circumstance, access can be declined by checking the Block login for quarantined devices checkbox as shown in the following screenshot, which will make it impossible for devices that were placed in quarantine to connect. This could make remediation more difficult as IT will not be able to simply connect to the device over a secured connection. This could cause some frustration with a quarantined user as they may be confused about why they are unable to connect, and they won't be able to do anything until staff have resolved the situation:

Figure 2.33 – Blocking access completely for quarantined devices

The quarantine message can be customized via...