Showing posts with label Firewall. Show all posts
Showing posts with label Firewall. Show all posts

FIREWALL #HOW TO DOWNLOAD GLOBAL PROTECT CLIENT ON PALO ALTO PORTAL

In case you need to download global Protect client, other than on public Firewall IP here it is relative procedure that you should follow:

  1. Customer Support Portal
  2. Login with valid support account
  3. Updates --> Software Updates --> Global Protect Agent for Windows64 --> GlobalProtect64-6.x.y.z.msi

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PNlXCAW

Firewall - License Expired and Palo Alto behavior

In case your Palo Alto licenses suddenly expires Palo Alto will face below behavior.

What Happens When Licenses Expire?

What Happens When Licenses Expire? #2

Consider that, in case Firewall/VM will be rebooted only 1200 sessions, at the same time, will be available

Firewall - Complete list URL Filtering Categories #PALO ALTO

Palo Alto has URL filtering feature possibility.

About complete list URL Filtering Categories here it is official web link:

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cm5hCAC

In case you would like to test web site link and find relative categorization here it is another useful link:

https://urlfiltering.paloaltonetworks.com/

Firewall #Palo Alto and dynamic/blacklist IP

Palo Alto permit to read proper .txt file exposed through https/http website (usually IIS) to import IP list to that must blacklisted

I am taking note about official article:

https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/policy/use-an-external-dynamic-list-in-policy/configure-the-firewall-to-access-an-external-dynamic-list

CISCO - Show the Complete Configuration without Breaks/Pauses on Cisco Router/Switches, ASA Firewall and WLC

On Cisco Network devices you could have necessity to show running configuration withouth breaks/pauses:

switches/router:

show terminal | in Length

terminal length 0

show run

show run brief 

WLC

config paging disable

show run-config" to display the config.

Cisco ASA

Pager (saved)

terminal pager (telnet session not saved)

The default is 24 lines; 0 means no page limit.

1. Type "pager 0" in priviledged mode to set your terminal to display without any breaks.

2. Type "show run-config" to display the config.

3. Type "pager 20" in priviledged mode to set your terminal to display with breaks every 20 lines.


full article:

https://community.cisco.com/t5/networking-knowledge-base/show-the-complete-configuration-without-breaks-pauses-on-cisco/ta-p/3115114

Firewall - How to backup configuration #PALO ALTO

Here it is official article that well explain on how to backup Palo Alto configuration.

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000POICCA4&lang=en_US%E2%80%A9

Below you can find relative explicative screenshot.



Firewall - What happens when licenses Expires #PALO ALTO

I am taking note about what happen when Palo Alto licenses expires.

These are weblinks that well explain all details:

https://docs.paloaltonetworks.com/vm-series/9-1/vm-series-deployment/license-the-vm-series-firewall/what-happens-when-licenses-expire

https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/subscriptions/what-happens-when-licenses-expire

Be Aware that if you get unexpected Firewall/VM reboot only 1200 internet sessions are supported. (and this is a big problem in case license renew process is not yet completed)

Indeed here are located Palo Articles that explains how to proceed with license renewal process

Action Required:

To complete the credit renewal process, you will need to follow the instruction in the following document https://docs.paloaltonetworks.com/vm-series/10-2/vm-series-deployment/license-the-vm-series-firewall/software-ngfw/renew-your-software-ngfw-credit-license

Tech Docs:


Hacker/Security - UPnP security concerns

About UPnP there are several security concerns that people majority are not aware.

Here it is an article that well explain concepts and security problems that you might face:

Security - Radius Server

 Here it is a basic article related to Radius protocol, I am taking note, on blog, for future purposes and, in case, it would be useful for seomeone


https://techgenix.com/radius-protocol-authentication-management-guide/

Antivirus - Sophos Message Relay/Cache Manager #FIREWALL PORTS

Sophos Central endpoints has possibility, to update themselves, or send messages status, to a LAN server (that operate as Sophos Update Cache and Message Relay)

Alternatively Endpoints updates, themselves, to internet.

Here they are ports that are necessary to be opened (to permit previously behaviors)

https://support.sophos.com/support/s/article/KB-000035367?language=en_US

Server - Microsoft DTC & Firewall rules

Here it is official Microsoft article that explain on how correctly configure Distributed Transaction Coordinator (DTC) working properly through firewall (and relatives ports to be opened):

https://support.microsoft.com/en-us/topic/c3ccb2af-a9f8-180e-8e11-8565f6c654a2#:~:text=All%20ports%20must%20be%20in,of%2015%20to%2020%20ports


Cisco - Disable AnyConnect SSL VPN portal website

During these days I was wondering if it is possible to disable the Cisco ASA VPN page and continue to use SSL vpn with the client. These question was rasing due to security concerns about, a.e., AD user locking out. 

Using ASDM you need to follow below steps. 

Configuration > Connection Profiles > Check the box "Shut down portal login page"

This features seems to be confirmed in this very exhaustive article too:

https://www.linkedin.com/pulse/shutting-down-webvpn-portal-ftd-flexconfig-matt-albrecht

[original articles]

https://community.spiceworks.com/topic/2114883-disable-anyconnect-ssl-vpn-portal-website

https://www.cisco.com/c/en/us/td/docs/security/asa/asa94/config-guides/asdm74/vpn/asdm-74-vpn-config/webvpn-customizing.html

https://community.cisco.com/t5/vpn/disabling-clientless-browser-based-vpn/td-p/3065988