Book Image

Securing Remote Access in Palo Alto Networks

By : Tom Piens aka Piens aka 'reaper'
Book Image

Securing Remote Access in Palo Alto Networks

By: Tom Piens aka Piens aka 'reaper'

Overview of this book

This book builds on the content found in Mastering Palo Alto Networks, focusing on the different methods of establishing remote connectivity, automating log actions, and protecting against phishing attacks through user credential detection. Complete with step-by-step instructions, practical examples, and troubleshooting tips, you will gain a solid understanding of how to configure and deploy Palo Alto Networks remote access products. As you advance, you will learn how to design, deploy, and troubleshoot large-scale end-to-end user VPNs. Later, you will explore new features and discover how to incorporate them into your environment. By the end of this Palo Alto Networks book, you will have mastered the skills needed to design and configure SASE-compliant remote connectivity and prevent credential theft with credential detection.
Table of Contents (11 chapters)
1
Section 1: Leveraging the Cloud and Enabling Remote Access
6
Section 2: Tools, Troubleshooting, and Best Practices

Preparing the firewall for credential detection

To control which websites users are allowed to submit corporate credentials to, we first need to be able to detect which credentials should be checked. URL filtering can be leveraged to perform user credential checking to ensure company usernames (and passwords, if enabled) are only shared with trusted websites.

As you can see in Figure 6.1, you can access the configuration options via Objects > Security Profiles > URL Filtering > URL Filtering Profile > User Credential Detection.

There are three options available to perform credential detection:

  • Use IP User Mapping: Matches the submitted username to the user that is mapped to the source IP via IP user mapping.
  • Use Group Mapping: Matches the submitted username to any corporate username in its user-to-group mapping table, which is learned by enabling LDAP group mapping.
  • Use Domain Credential Filter: Verifies the submitted username and password match to...