Book Image

Securing Remote Access in Palo Alto Networks

By : Tom Piens aka Piens aka 'reaper'
Book Image

Securing Remote Access in Palo Alto Networks

By: Tom Piens aka Piens aka 'reaper'

Overview of this book

This book builds on the content found in Mastering Palo Alto Networks, focusing on the different methods of establishing remote connectivity, automating log actions, and protecting against phishing attacks through user credential detection. Complete with step-by-step instructions, practical examples, and troubleshooting tips, you will gain a solid understanding of how to configure and deploy Palo Alto Networks remote access products. As you advance, you will learn how to design, deploy, and troubleshoot large-scale end-to-end user VPNs. Later, you will explore new features and discover how to incorporate them into your environment. By the end of this Palo Alto Networks book, you will have mastered the skills needed to design and configure SASE-compliant remote connectivity and prevent credential theft with credential detection.
Table of Contents (11 chapters)
1
Section 1: Leveraging the Cloud and Enabling Remote Access
6
Section 2: Tools, Troubleshooting, and Best Practices

Configuring mobile users

Once the service infrastructure has been provisioned (you can check its status from the Panorama > Cloud Services > Status menu; a percentage will indicate its progress and a green light will indicate its completion), the Mobile Users tab will also become available.

To activate mobile users, we need to activate the Template and Template Stack options for mobile users, create a zone inside Mobile_User_Template, and then assign those zones inside Mobile User Zone Mapping. Follow these steps to get that set up:

  1. In Panorama > Cloud Services > Configuration > Mobile Users, click Settings.
  2. Review the Template Stack and Template information and, if needed, change the Device Group parent. Click OK.
  3. Navigate to Templates > Network > Zones and switch to Mobile_User_Template.
  4. Create a prisma-trust zone and a prisma-untrust zone: in the context of Prisma Access, the prisma-trust zone will not only encompass remote users connected...