Book Image

Securing Remote Access in Palo Alto Networks

By : Tom Piens aka Piens aka 'reaper'
Book Image

Securing Remote Access in Palo Alto Networks

By: Tom Piens aka Piens aka 'reaper'

Overview of this book

This book builds on the content found in Mastering Palo Alto Networks, focusing on the different methods of establishing remote connectivity, automating log actions, and protecting against phishing attacks through user credential detection. Complete with step-by-step instructions, practical examples, and troubleshooting tips, you will gain a solid understanding of how to configure and deploy Palo Alto Networks remote access products. As you advance, you will learn how to design, deploy, and troubleshoot large-scale end-to-end user VPNs. Later, you will explore new features and discover how to incorporate them into your environment. By the end of this Palo Alto Networks book, you will have mastered the skills needed to design and configure SASE-compliant remote connectivity and prevent credential theft with credential detection.
Table of Contents (11 chapters)
1
Section 1: Leveraging the Cloud and Enabling Remote Access
6
Section 2: Tools, Troubleshooting, and Best Practices

Practical troubleshooting for GlobalProtect issues

When you're troubleshooting connectivity issues, there are several places where information can be gathered to try and determine the cause of a user not being able to connect. Starting from PAN-OS 9.1, most of the useful GlobalProtect logs can be found in Monitor > Logs > GlobalProtect, while the authentication logs can still be found in Monitor > Logs > System, as shown in the following screenshot. Before PAN-OS 9.1, all these logs were contained in the system log. Common issues such as a missing client certificate, a wrongly entered username or password, or an agent that tries to authenticate with an expired cookie can be found here so that the user can be directed accordingly:

Figure 2.38 – GlobalProtect and system logs

The currently connected users can be accessed from the portal and gateway pages via Network > GlobalProtect. The Current User section of the portal will show which...