Book Image

Securing Remote Access in Palo Alto Networks

By : Tom Piens aka Piens aka 'reaper'
Book Image

Securing Remote Access in Palo Alto Networks

By: Tom Piens aka Piens aka 'reaper'

Overview of this book

This book builds on the content found in Mastering Palo Alto Networks, focusing on the different methods of establishing remote connectivity, automating log actions, and protecting against phishing attacks through user credential detection. Complete with step-by-step instructions, practical examples, and troubleshooting tips, you will gain a solid understanding of how to configure and deploy Palo Alto Networks remote access products. As you advance, you will learn how to design, deploy, and troubleshoot large-scale end-to-end user VPNs. Later, you will explore new features and discover how to incorporate them into your environment. By the end of this Palo Alto Networks book, you will have mastered the skills needed to design and configure SASE-compliant remote connectivity and prevent credential theft with credential detection.
Table of Contents (11 chapters)
1
Section 1: Leveraging the Cloud and Enabling Remote Access
6
Section 2: Tools, Troubleshooting, and Best Practices

BPA tool

The BPA tool is a free tool made available to all customers and partners of Palo Alto Networks and can be run directly from the support portal at https://support.paloaltonetworks.com.

The BPA tool can ingest a tech support file (TSF), which contains the device configuration and device metrics, and perform an analysis against a database of best practices. The output can be used to further button down the configuration.

First, we will need to generate and collect a TSF. Go to Device > Support and click Generate Tech Support File, as illustrated in the following screenshot:

Figure 7.21 – Generating a TSF

Note

While the TSF is being generated, the web interface will be greyed out and can't be used by the admin that initiated the operation. Commit jobs, including automated content updates, are paused until the file is generated.

The file can also be exported via secure copy (scp) or Trivial File Transfer Protocol (tftp) via...