Book Image

Securing Remote Access in Palo Alto Networks

By : Tom Piens aka Piens aka 'reaper'
Book Image

Securing Remote Access in Palo Alto Networks

By: Tom Piens aka Piens aka 'reaper'

Overview of this book

This book builds on the content found in Mastering Palo Alto Networks, focusing on the different methods of establishing remote connectivity, automating log actions, and protecting against phishing attacks through user credential detection. Complete with step-by-step instructions, practical examples, and troubleshooting tips, you will gain a solid understanding of how to configure and deploy Palo Alto Networks remote access products. As you advance, you will learn how to design, deploy, and troubleshoot large-scale end-to-end user VPNs. Later, you will explore new features and discover how to incorporate them into your environment. By the end of this Palo Alto Networks book, you will have mastered the skills needed to design and configure SASE-compliant remote connectivity and prevent credential theft with credential detection.
Table of Contents (11 chapters)
1
Section 1: Leveraging the Cloud and Enabling Remote Access
6
Section 2: Tools, Troubleshooting, and Best Practices

Using domain credential filter

Domain credential filter will check for a corporate username and the associated password: the firewall can check if the password entered on a website matches the actual password in a user's company account.

There are a few requirements to make this work: the Windows-based user-ID agent needs to be installed on an RODC and the user-ID credential service add-on needs to be added.

Important note

At this time, Windows Server 2012 or 2016 is recommended. 2019 is not yet supported.

The firewall also needs to be set up with traditional user-to-IP mapping, but this can be achieved by any of the user mapping methods. We already set up agentless User-IP mapping in a previous step, but an additional user-ID agent, Captive Portal or GlobalProtect, can be used instead or as well (a minimum of two agents is recommended for redundancy).

First, go into the support portal at https://support.paloaltonetworks.com and access Software Updates. Use the...