Book Image

Securing Remote Access in Palo Alto Networks

By : Tom Piens aka Piens aka 'reaper'
Book Image

Securing Remote Access in Palo Alto Networks

By: Tom Piens aka Piens aka 'reaper'

Overview of this book

This book builds on the content found in Mastering Palo Alto Networks, focusing on the different methods of establishing remote connectivity, automating log actions, and protecting against phishing attacks through user credential detection. Complete with step-by-step instructions, practical examples, and troubleshooting tips, you will gain a solid understanding of how to configure and deploy Palo Alto Networks remote access products. As you advance, you will learn how to design, deploy, and troubleshoot large-scale end-to-end user VPNs. Later, you will explore new features and discover how to incorporate them into your environment. By the end of this Palo Alto Networks book, you will have mastered the skills needed to design and configure SASE-compliant remote connectivity and prevent credential theft with credential detection.
Table of Contents (11 chapters)
1
Section 1: Leveraging the Cloud and Enabling Remote Access
6
Section 2: Tools, Troubleshooting, and Best Practices

Configuring Cortex Data Lake

The last step is to make sure CDL storage is distributed across the different log types. By default, the total log space is unassigned, so no logs will be collected until a certain number of logs have been assigned to each type of log you are interested in. Access CDL directly via https://logging-service.apps.paloaltonetworks.com/storage/status?instance=<instancename> if you know the instance name, or go to apps.paloaltonetworks.com and click the Cortex Data Lake tile.

As shown in the following screenshot, access the Configuration menu and set storage quotas (in %) for the log types that are of interest. Any log types that are left empty will not receive quotas:

Figure 4.38 – Assigning log storage to log types

Once storage has been assigned, logs can be viewed in the Explore section. If some troubleshooting needs to be done, the Prisma system logs can be accessed through the Explore menu as well.