Book Image

Securing Remote Access in Palo Alto Networks

By : Tom Piens aka Piens aka 'reaper'
Book Image

Securing Remote Access in Palo Alto Networks

By: Tom Piens aka Piens aka 'reaper'

Overview of this book

This book builds on the content found in Mastering Palo Alto Networks, focusing on the different methods of establishing remote connectivity, automating log actions, and protecting against phishing attacks through user credential detection. Complete with step-by-step instructions, practical examples, and troubleshooting tips, you will gain a solid understanding of how to configure and deploy Palo Alto Networks remote access products. As you advance, you will learn how to design, deploy, and troubleshoot large-scale end-to-end user VPNs. Later, you will explore new features and discover how to incorporate them into your environment. By the end of this Palo Alto Networks book, you will have mastered the skills needed to design and configure SASE-compliant remote connectivity and prevent credential theft with credential detection.
Table of Contents (11 chapters)
1
Section 1: Leveraging the Cloud and Enabling Remote Access
6
Section 2: Tools, Troubleshooting, and Best Practices

Hardening the management interface

From a security perspective, it is best practice to ensure all your vulnerable and critical systems are always hardened. Thus, any unneeded services must be turned off, access should be restricted to only specific hosts, role-based access control (RBAC) principles should be upheld, and protocols should be restricted to the most secure version. The default configuration of the Palo Alto Networks appliances is actually relatively weak. This is intentional, to allow administrators to quickly deploy a firewall or panorama out of the box without too much hassle to get it running. Securing the appliance is left for after the initial deployment, but this stage is often overlooked. The following sections will provide you with knowledge you will need in order to harden your appliances.

FIPS-CC mode

FIPS-CC mode sets the system to comply with standards described in the Federal Information Processing Standard (FIPS) 140-2 and Common Criteria (CC). Enabling...