<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article Secure Day-One Configuration Not for the Faint of Heart in General Articles</title>
    <link>https://live.paloaltonetworks.com/t5/general-articles/secure-day-one-configuration-not-for-the-faint-of-heart/ta-p/435501</link>
    <description>&lt;DIV class="lia-message-template-content-zone"&gt;
&lt;P style="font-weight: 400;"&gt;&lt;EM&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Day-One-Configuration-blog_OtakarKlier_LIVEcommunity.jpg" style="width: 960px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/37046iC621CD2FB9D8C1BC/image-size/large?v=v2&amp;amp;px=999" role="button" title="Day-One-Configuration-blog_OtakarKlier_LIVEcommunity.jpg" alt="Day-One-Configuration-blog_OtakarKlier_LIVEcommunity.jpg" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;&lt;EM&gt;&lt;STRONG&gt;This content was developed, written, and contributed by&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580" target="_self"&gt;&lt;FONT color="#FF6600"&gt;@OtakarKlier&lt;/FONT&gt;&lt;/A&gt;, one of LIVEcommunity's Cyber Elite experts.&amp;nbsp;&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;This configuration is something I came up with that is in-line with best practices and day-one settings. I felt should be part of any new implementation for proper security; it combines best practices from not only the day-one config, but also a start to Zero Trust.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;For manual config of management interface via CLI:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;You must change the default password, you must set one and remember it! (The template will change it, so you'll need to change it a second time after importing and applying the template.)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;At the CLI:&lt;/STRONG&gt;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;configure
set deviceconfig system ip-address &amp;lt;IP address&amp;gt; netmask &amp;lt;subnet mask&amp;gt; default-gateway &amp;lt;gateway&amp;gt;
set deviceconfig system dns-setting servers primary &amp;lt;IP of internal DNS server if no internal DNS server use 208.67.220.220 &amp;gt;
set deviceconfig system ntp-servers primary-ntp-server ntp-server-address &amp;lt;IP of NTP server or use us.pool.ntp.org&amp;gt;
commit&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;NTP and DNS are required for the device to obtain its licensing and updates.&lt;/P&gt;
&lt;P&gt;Connect to the GUI and download all licenses as well as Dynamic updates.&lt;BR /&gt;Upgrade code to version 10.0.6 (that is what the template was built on)&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Import the XML config (see attachment)&lt;BR /&gt;Template password is Paloaltorocks1! (please change it)&lt;BR /&gt;Load the snapshot (see attachments)&lt;BR /&gt;&lt;STRONG&gt;PanOS1006Base.xml&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MGMT interface is configured for DHCP in the template&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;assign IP to eth 1/1 and NAT &lt;BR /&gt;assing IP to internal eth 1/2&lt;BR /&gt;Verify default outbound route&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Set/Disable the following if not used:&lt;/P&gt;
&lt;P&gt;SIEM=1.0.0.0&lt;BR /&gt;email server profile 1.0.0.1&lt;BR /&gt;Netflow 10.0.0.2&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Put the MGMT interface into the Management zone and make sure it has the proper IP, subnet mask and gateway along with DNS and NTP.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;STRONG&gt;Additional information can be found via the&amp;nbsp;&lt;A style="font-family: inherit; background-color: #ffffff;" href="https://docs.paloaltonetworks.com/best-practices/10-1/data-center-best-practices/data-center-best-practices-checklist.html" target="_blank" rel="noopener"&gt;Data Center Security Policy Best Practices Checklist&lt;/A&gt;.&lt;/STRONG&gt;&lt;SPAN style="font-family: inherit;"&gt;&amp;nbsp;&lt;/SPAN&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #1f497d; font-family: Calibri, sans-serif; font-size: 14.6667px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff; text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial; display: inline !important; float: none;"&gt;The part below is to mitigate some scan findings for weak ciphers: &lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;configure
delete deviceconfig system ssh

set deviceconfig system ssh ciphers mgmt aes256-ctr
set deviceconfig system ssh ciphers mgmt aes256-gcm

set deviceconfig system ssh regenerate-hostkeys mgmt key-type RSA key-length 3072
set deviceconfig system ssh session-rekey mgmt interval 3600

set deviceconfig system ssh mac mgmt hmac-sha2-256
commit
exit
set ssh service-restart mgmt&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;Thanks for reading—and a big thanks to Cyber Elite expert&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580" target="_self"&gt;&lt;FONT color="#FF6600"&gt;@OtakarKlier&lt;/FONT&gt;&lt;/A&gt;&amp;nbsp;for sharing his expertise.&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;</description>
    <pubDate>Fri, 15 Oct 2021 23:04:12 GMT</pubDate>
    <dc:creator>kiwi</dc:creator>
    <dc:date>2021-10-15T23:04:12Z</dc:date>
    <item>
      <title>Secure Day-One Configuration Not for the Faint of Heart</title>
      <link>https://live.paloaltonetworks.com/t5/general-articles/secure-day-one-configuration-not-for-the-faint-of-heart/ta-p/435501</link>
      <description>&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;This configuration is in-line with best practices and day-one settings for proper security, and combines Palo Alto Networks best practices with a Zero Trust start.&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Fri, 15 Oct 2021 23:04:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-articles/secure-day-one-configuration-not-for-the-faint-of-heart/ta-p/435501</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2021-10-15T23:04:12Z</dc:date>
    </item>
  </channel>
</rss>

