Book Image

Securing Remote Access in Palo Alto Networks

By : Tom Piens aka Piens aka 'reaper'
Book Image

Securing Remote Access in Palo Alto Networks

By: Tom Piens aka Piens aka 'reaper'

Overview of this book

This book builds on the content found in Mastering Palo Alto Networks, focusing on the different methods of establishing remote connectivity, automating log actions, and protecting against phishing attacks through user credential detection. Complete with step-by-step instructions, practical examples, and troubleshooting tips, you will gain a solid understanding of how to configure and deploy Palo Alto Networks remote access products. As you advance, you will learn how to design, deploy, and troubleshoot large-scale end-to-end user VPNs. Later, you will explore new features and discover how to incorporate them into your environment. By the end of this Palo Alto Networks book, you will have mastered the skills needed to design and configure SASE-compliant remote connectivity and prevent credential theft with credential detection.
Table of Contents (11 chapters)
1
Section 1: Leveraging the Cloud and Enabling Remote Access
6
Section 2: Tools, Troubleshooting, and Best Practices

Configuring the remote firewalls

Once Prisma Access has been fully configured, the remote firewalls still need to be configured so that they can connect to Prisma to establish the virtual network.

In the Configuring the service connections section earlier in this chapter, I set the remote peer to dynamic and behind a NAT device. The corresponding configuration on the remote firewall should look similar to what's shown in the following screenshot. While setting up your environment, set the configuration so that it reflects the actual situation in your deployment (that is, it will be likely that an actual data centre or HQ location will have a static IP and will not be behind a NAT device; these settings were set purely for demonstration purposes):

Figure 4.34 – Configuring the HQ firewall IKE gateway

The next step is to create an IPSec tunnel so that the firewall can establish the service connection. Make sure that you add all the relevant...