Book Image

Securing Remote Access in Palo Alto Networks

By : Tom Piens aka Piens aka 'reaper'
Book Image

Securing Remote Access in Palo Alto Networks

By: Tom Piens aka Piens aka 'reaper'

Overview of this book

This book builds on the content found in Mastering Palo Alto Networks, focusing on the different methods of establishing remote connectivity, automating log actions, and protecting against phishing attacks through user credential detection. Complete with step-by-step instructions, practical examples, and troubleshooting tips, you will gain a solid understanding of how to configure and deploy Palo Alto Networks remote access products. As you advance, you will learn how to design, deploy, and troubleshoot large-scale end-to-end user VPNs. Later, you will explore new features and discover how to incorporate them into your environment. By the end of this Palo Alto Networks book, you will have mastered the skills needed to design and configure SASE-compliant remote connectivity and prevent credential theft with credential detection.
Table of Contents (11 chapters)
1
Section 1: Leveraging the Cloud and Enabling Remote Access
6
Section 2: Tools, Troubleshooting, and Best Practices

Configuring remote networks

The remote networks are different from a service connection as they have firewall rules, security profiles, and can connect to the internet. Just like mobile users, the remote network configuration needs the device group, template, and template stack to be activated. Navigate to Remote Network via Panorama > Cloud Services > Configuration > Remote Network and open the Settings menu to see the menu items, as shown in the following screenshot. In the Settings tab, make sure the templates have been populated properly and assign Remote_Network_Device_Group to the appropriate Parent Device Group. In DNS Proxy, a DNS proxy object can be configured to serve as an upstream DNS server to remote network clients. This DNS proxy will need to be assigned somehow to the clients, most likely by a DHCP server configuration on the local firewall in the office. In the Group Mapping Settings section, the username attribute needs to be set so that it matches the user...