<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: how to configure/Restrict Prisma Management Access in Prisma Access Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/how-to-configure-restrict-prisma-management-access/m-p/559240#M588</link>
    <description>&lt;P&gt;Hi Ariq,&lt;BR /&gt;Are you still seeing those logs, I believe some of the logs you see in traffic logs are the gcp /aws ip running health check kinda stuff, just want to be sure you are not referring to those logs when you implemented GEO-Block Do you still see those logs?&lt;/P&gt;</description>
    <pubDate>Sun, 24 Sep 2023 07:15:12 GMT</pubDate>
    <dc:creator>znazir</dc:creator>
    <dc:date>2023-09-24T07:15:12Z</dc:date>
    <item>
      <title>how to configure/Restrict Prisma Management Access</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/how-to-configure-restrict-prisma-management-access/m-p/557252#M565</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;We are deploying Prisma Access. Deployment is on progress. From the security logs we can see that we are hitting some brute force attacks. We are using Cloud managed Prisma Access. Not the Panaroma managed.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How do we configure the Management Access Policy? I want to whitelist our selective IP addresses.&amp;nbsp;Ho do we do this in Prisma ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Note: I have tried this Document but I cant find Trusted IP feature in my portal.&amp;nbsp;&lt;BR /&gt;&lt;A href="https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin/manage-prisma-cloud-alerts/trusted-ip-addresses-on-prisma-cloud" target="_blank"&gt;Trusted IP Addresses on Prisma Cloud (paloaltonetworks.com)&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Sep 2023 00:45:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/how-to-configure-restrict-prisma-management-access/m-p/557252#M565</guid>
      <dc:creator>Ariq_Aziz</dc:creator>
      <dc:date>2023-09-11T00:45:16Z</dc:date>
    </item>
    <item>
      <title>Re: how to configure/Restrict Prisma Management Access</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/how-to-configure-restrict-prisma-management-access/m-p/557332#M566</link>
      <description>&lt;P&gt;yeah that article is for prisma cloud so won't apply to prisma access&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am wondering: you say you're seeing brute force in the traffic log, but you are using prisma access cloud managed, which lives on the palo alto HUB portal (which you can't see in your security logs because this portal is maintained by Palo Alto and not your tenant) can you clarify what you're seeing exactly?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;are you seeing brute force attacks against your (GP) Portal/gateways maybe?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the attacks, are they coming from a certain country you would be able to block off? you could use an embargo rule to block everyone from there connecting to you :&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-advanced-deployments/block-incoming-connections-from-specific-countries" target="_blank"&gt;https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-advanced-deployments/block-incoming-connections-from-specific-countries&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;next, are you using LDAP for authentication? you could switch to SAML which also offloads the authentication to your IdP, and can apply conditional access etc&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Make sure to add an any any deny rule at the end of your security policy, and only create security rules for the access needed (always use zones, be as specific as possible).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;hope this helps, feel free to post additional information if my reply was not helpful&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Sep 2023 10:51:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/how-to-configure-restrict-prisma-management-access/m-p/557332#M566</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2023-09-11T10:51:06Z</dc:date>
    </item>
    <item>
      <title>Re: how to configure/Restrict Prisma Management Access</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/how-to-configure-restrict-prisma-management-access/m-p/557427#M567</link>
      <description>&lt;P&gt;Hi Reaper&lt;/P&gt;
&lt;P&gt;Yes, Sorry my post was not clear in words. Yes, I was getting Brute Force in my Global Protect Portal as we are using Prisma Access. I have created Geo Block policy as you recommended.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have SAML ,MFA. However , GEO Block Policy the best First layer of defense. And We created&amp;nbsp; deny any any at the bottom before the default rules. Thanks for adding up those.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I often mixed up Prisma cloud and Prisma access !! Thanks again for pointing that out. Ha Ha.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Sep 2023 22:53:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/how-to-configure-restrict-prisma-management-access/m-p/557427#M567</guid>
      <dc:creator>Ariq_Aziz</dc:creator>
      <dc:date>2023-09-11T22:53:43Z</dc:date>
    </item>
    <item>
      <title>Re: how to configure/Restrict Prisma Management Access</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/how-to-configure-restrict-prisma-management-access/m-p/559240#M588</link>
      <description>&lt;P&gt;Hi Ariq,&lt;BR /&gt;Are you still seeing those logs, I believe some of the logs you see in traffic logs are the gcp /aws ip running health check kinda stuff, just want to be sure you are not referring to those logs when you implemented GEO-Block Do you still see those logs?&lt;/P&gt;</description>
      <pubDate>Sun, 24 Sep 2023 07:15:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/how-to-configure-restrict-prisma-management-access/m-p/559240#M588</guid>
      <dc:creator>znazir</dc:creator>
      <dc:date>2023-09-24T07:15:12Z</dc:date>
    </item>
  </channel>
</rss>

