Book Image

Securing Remote Access in Palo Alto Networks

By : Tom Piens aka Piens aka 'reaper'
Book Image

Securing Remote Access in Palo Alto Networks

By: Tom Piens aka Piens aka 'reaper'

Overview of this book

This book builds on the content found in Mastering Palo Alto Networks, focusing on the different methods of establishing remote connectivity, automating log actions, and protecting against phishing attacks through user credential detection. Complete with step-by-step instructions, practical examples, and troubleshooting tips, you will gain a solid understanding of how to configure and deploy Palo Alto Networks remote access products. As you advance, you will learn how to design, deploy, and troubleshoot large-scale end-to-end user VPNs. Later, you will explore new features and discover how to incorporate them into your environment. By the end of this Palo Alto Networks book, you will have mastered the skills needed to design and configure SASE-compliant remote connectivity and prevent credential theft with credential detection.
Table of Contents (11 chapters)
1
Section 1: Leveraging the Cloud and Enabling Remote Access
6
Section 2: Tools, Troubleshooting, and Best Practices

Using group mapping for credential detection

Before you proceed with this step, make sure you enabled SSL/TLS decryption, created a Group Mapping profile, and have a security rule with a URL filtering security profile set. Open URL Filtering Profile in Objects > Security Profiles > URL Filtering and access the User Credential Detection tab. Set the detection method to Use Group Mapping. An additional field will appear called Group Mapping Settings. The drop-down menu will show all the configured Group Mapping profiles, of which you can select one as illustrated in Figure 6.21:

Figure 6.21 – Use Group Mapping User Credential Detection

All usernames collected via this Group Mapping profile will be used to match User Credential Detection. This means that where Use IP User Mapping could only be used to match the current user-to-IP-mapped username to a website submission, now multiple credentials can be intercepted from a single user, closing the gap...