<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PAN-OS 8.0 Blue team help (In a little over my head) in Advanced Threat Prevention Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/pan-os-8-0-blue-team-help-in-a-little-over-my-head/m-p/298910#M698</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;First, thank you for your service! I only allow SSH, HTTPS, and PING for my management interface. The PING is for my monitoring solution so that I know if there are any layer3/4 issues. Even though you might not use the cli that often, there are times when troubleshooting that it is essential, yes allow it.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Check out the rest of the article and you can limit to specific source IP's. Meaning if you have a static or a DHCP reservation, it will only allow you and drop the rest :).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps and feel free to ask as many questions as you like!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers!&lt;/P&gt;</description>
    <pubDate>Fri, 15 Nov 2019 22:13:48 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2019-11-15T22:13:48Z</dc:date>
    <item>
      <title>PAN-OS 8.0 Blue team help (In a little over my head)</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/pan-os-8-0-blue-team-help-in-a-little-over-my-head/m-p/298900#M697</link>
      <description>&lt;P&gt;I joined my schools cyber defense team last week, and subsequently volunteered to manage the firewall (Palo Alto VM version 8.0.0). I was supposed to have until the 23rd to learn as much as I could. However, due to scheduling conflicts we were moved to tomorrow. So, I need some help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Luckily it just so happened that on Veterans Day Palo Alto Networks opened up a massive learning lab for veterans (thank you!), and because I am a veteran I have been able to learn quite a bit. So I figure I will just follow the chapter on "best practices for securing administrative access" in the manual? Along with closing every port except 80 and 443 (which are required as part of the rules)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Should I disable SSH and PING? I don't have the time to learn the CLI commands and since I KNOW we will be getting attacked this just seems like a security risk.&lt;/LI&gt;&lt;LI&gt;The best practices says not to allow access over Telnet and HTTP. I don't plan on using Telnet, but does the firewall auto configure for HTTPS when you are signing in "locally?" Or will I need to create my own certificates?&lt;OL&gt;&lt;LI&gt;My only firewall experience is pfSense which I am very comfortable with, but pfSense this is not lol.&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Tomorrows event is a practice invitational (thank God). But the rules are the same as the actual competition that will take place in February. We cannot bring anything electronic into the room, only paperwork. However, if it is online and publicly available then we are free to use it (github etc)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sorry for the long post, but I think it warranted a bit of an explanation. Thank you for any help&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Nov 2019 21:21:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/pan-os-8-0-blue-team-help-in-a-little-over-my-head/m-p/298900#M697</guid>
      <dc:creator>Roydub83</dc:creator>
      <dc:date>2019-11-15T21:21:11Z</dc:date>
    </item>
    <item>
      <title>Re: PAN-OS 8.0 Blue team help (In a little over my head)</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/pan-os-8-0-blue-team-help-in-a-little-over-my-head/m-p/298910#M698</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;First, thank you for your service! I only allow SSH, HTTPS, and PING for my management interface. The PING is for my monitoring solution so that I know if there are any layer3/4 issues. Even though you might not use the cli that often, there are times when troubleshooting that it is essential, yes allow it.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Check out the rest of the article and you can limit to specific source IP's. Meaning if you have a static or a DHCP reservation, it will only allow you and drop the rest :).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps and feel free to ask as many questions as you like!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers!&lt;/P&gt;</description>
      <pubDate>Fri, 15 Nov 2019 22:13:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/pan-os-8-0-blue-team-help-in-a-little-over-my-head/m-p/298910#M698</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-11-15T22:13:48Z</dc:date>
    </item>
    <item>
      <title>Re: PAN-OS 8.0 Blue team help (In a little over my head)</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/pan-os-8-0-blue-team-help-in-a-little-over-my-head/m-p/298936#M700</link>
      <description>&lt;P&gt;Yes that helps very much.&lt;/P&gt;&lt;P&gt;I was assuming the SSH and PING settings were global and I get the idea of keeping them enabled. This is a pretty amazing firewall. We will see how two days worth of knowledge does lol.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you again for your help&lt;/P&gt;</description>
      <pubDate>Sat, 16 Nov 2019 04:05:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/pan-os-8-0-blue-team-help-in-a-little-over-my-head/m-p/298936#M700</guid>
      <dc:creator>Roydub83</dc:creator>
      <dc:date>2019-11-16T04:05:19Z</dc:date>
    </item>
  </channel>
</rss>

