Securing Remote Access in Palo Alto Networks: Practical techniques to enable and protect remote users, improve your security posture, and troubleshoot next-generation firewalls
Book information
Description
Explore everything you need to know to set up secure remote access, harden your firewall deployment, and protect against phishing Key FeaturesLearn the ins and outs of log forwarding and troubleshooting issuesSet up GlobalProtect satellite connections, configure site-to-site VPNs, and troubleshoot LSVPN issuesGain an in-depth understanding of user credential detection to prevent data leaks Book Description This book builds on the content found in Mastering Palo Alto Networks, focusing on the different methods of establishing remote connectivity, automating log actions, and protecting against phishing attacks through user credential detection. Complete with step-by-step instructions, practical examples, and troubleshooting tips, you will gain a solid understanding of how to configure and deploy Palo Alto Networks remote access products. As you advance, you will learn how to design, deploy, and troubleshoot large-scale end-to-end user VPNs. Later, you will explore new features and discover how to incorporate them into your environment. By the end of this Palo Alto Networks book, you will have mastered the skills needed to design and configure SASE-compliant remote connectivity and prevent credential theft with credential detection. What you will learnUnderstand how log forwarding is configured on the firewallFocus on effectively enabling remote accessExplore alternative ways for connecting users and remote networksProtect against phishing with credential detectionUnderstand how to troubleshoot complex issues confidentlyStrengthen the security posture of your firewallsWho this book is for This book is for anyone who wants to learn more about remote access for users and remote locations by using GlobalProtect and Prisma access and by deploying Large Scale VPN. Basic knowledge of Palo Alto Networks, network protocols, and network design will be helpful, which is why reading Mastering Palo Alto Networks is recommended first to help you make the most of this book. Table of ContentsCentralizing logsConfiguring Advanced GlobalProtect FeaturesSetting up site-to-site VPNs and Large Scale VPNsConfiguring Prisma AccessEnabling features to improve your security postureAnti Phishing with User Credential DetectionPractical troubleshooting and Best Practice Tools Securing Remote Access in Palo Alto Networks Contributors About the author About the reviewer Preface Who this book is for What this book covers To get the most out of this book Code in Action Download the colour images Conventions used Get in touch Reviews Section 1: Leveraging the Cloud and Enabling Remote Access Chapter 1: Centralizing Logs Technical requirements Understanding log forwarding profiles and best practices Allocating log storage Adding disk space to a VM firewall Learning about Panorama and log collectors Forwarding logs to syslog, SMTP, and other options SNMP trap server profile Syslog server profile Email server profile HTTP server profile Netflow Profile Configuring system log forwarding on the firewall Exploring log forwarding profiles Dynamic tagging Assigning log forwarding actions Troubleshooting logs and log forwarding Debugging log-receiver Reading system resources Using tcpdump Troubleshooting forwarding to a log collector Summary Chapter 2: Configuring Advanced GlobalProtect Features Technical requirements Learning about advanced configuration features Integrating SAML into authentication methods Setting up a VPN connection before the user has logged on Leveraging quarantine to isolate agents Practical troubleshooting for GlobalProtect issues Summary Chapter 3: Setting up Site-to-Site VPNs and Large-Scale VPNs Technical requirements Configuring a site-to-site VPN connection Static site-to-site tunnels Dynamic site-to-site tunnels Setting up the LSVPN Summary Chapter 4: Configuring Prisma Access Technical requirements Configuring Prisma Access Configuring the service infrastructure Configuring the service connection Configuring directory sync Configuring mobile users Configuring remote networks Configuring the remote firewalls Configuring Cortex Data Lake Summary Section 2: Tools, Troubleshooting, and Best Practices Chapter 5: Enabling Features to Improve Your Security Posture Technical requirements Hardening the management interface FIPS-CC mode Replacing the default certificates Setting minimum password complexity Configuring administrator roles Restricting access to the management interface Setting the master key EDLs MineMeld Summary Chapter 6: Anti-Phishing with User Credential Detection Technical requirements Preparing the firewall for credential detection Configuring SSL/TLS decryption Enabling IP user mapping Using IP user mapping for credential detection Enabling group mapping Troubleshooting user-ID Using group mapping for credential detection Using domain credential filter Troubleshoot domain credential filter Summary Chapter 7: Practical Troubleshooting and Best Practices Tools Technical requirements Troubleshooting User-ID Users are not being mapped Users are mapped briefly Inconsistent domain in username Command-line interface (CLI) cheat sheet Troubleshooting NAT Loss of connectivity – proxy-ARP misconfiguration Troubleshooting destination NAT issues Troubleshooting source NAT BPA tool Summary Why subscribe? Other Books You May Enjoy Packt is searching for authors like you Leave a review - let other readers know what you think
Similar books
Mastering Palo Alto Networks
2020 · EPUB
Securing Remote Access in Palo Alto Networks
2021 · EPUB
MySQL® Notes for Professionals book
2018 · PDF
MrExcel 2022: Boosting Excel
2022 · PDF
MrExcel 2022: Boosting Excel
2022 · PDF
Session C11: Ancient Cultural Landscapes in South Europe – their Ecological Setting and Evolution, Session C22: Gardeners from South America, Session S04: Agro-Pastoralism and Early Metallurgy Sessions, Session WS29: The Idea of Enclosure in Recent Iberian Prehistory, Session C88: Rhytmes et causalites des dynamiques de l'anthropisation en Europe entre 6500 ET 500 BC: Hypotheses socio-culturelles et/ou climatiques: Proceedings of the XV UISPP World Congress (Lisbon 4-9 September 2006) / Actes du XV Congrès Mondial (Lisbonne 4-9 Septembre 2006) Vol.36
2010 · PDF
THE BRITISH ARMY IN INDIA: ITS PRESERVATION BY AN APPROPRIATE CLOTHING, HOUSING, LOCATING, RECREATIVE EMPLOYMENT, AND HOPEFUL ENCOURAGEMENT OF THE TROOPS. with AN APPENDIX ON INDIA : THE CLIMATE OP ITS HILLS ; THE DEVELOPMENT OF ITS RESODRCBS, INDUSTRY, AND ARTS ; THE ADMINISTRATION OF JUSTICE ; THE BLACK ACT ; THE PROGRESS OF CHRISTIANITY ; THE TRAFFIC IN OPIUM ; THE VALUE OF INDIA ; PERMANENT CAUSES OF DISAFFECTION, AND OF THE RECENT REBELLION ; THE TRADITIONARY POLICY; MISGOVERNMENT BY NATIVE RULERS ; ANNEXATIONS OF THEIR TERRITORY, ETC.
1858 · PDF
Idries Shah 27 Books Collection : A Perfumed Scorpion, A Veiled Gazelle, Caravan of Dreams, Darkest England, Destination Mecca, Evenings with Idries Shah, Knowing How to Know, Learning How to Learn, Letters and Lectures of Idries Shah, Neglected aspects of Sufi study, Observations, Oriental Magic, Reflections, Seeker after Truth, Special Illumination, Special Problems in the study of Sufi ideas, Sufi thought and action, Tales of the Dervishes, The Dermis Probe, The Elephant in the Dark, The Englishman Handbook, Idries Shah Antology, The Magic Monastery, The natives are restless, wisdom of the Idiots PDF.
2022 · PDF