<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Disable USB Port on Firewall in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/disable-usb-port-on-firewall/m-p/559008#M113382</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/187777"&gt;@DennyChanditya&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That is a great question!&amp;nbsp; You probably want to disable it for compliance reasons in which case my thoughts are no help.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt; and &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11943"&gt;@kiwi&lt;/a&gt;, Is it true that the USB port is used only for bootstrapping, and the NGFW only reads the USB "only when it is in factory default state or has all private data deleted"?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/firewall-administration/bootstrap-the-firewall/usb-flash-drive-support" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/firewall-administration/bootstrap-the-firewall/usb-flash-drive-support&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/firewall-administration/bootstrap-the-firewall/prepare-a-usb-flash-drive-for-bootstrapping-a-firewall" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/firewall-administration/bootstrap-the-firewall/prepare-a-usb-flash-drive-for-bootstrapping-a-firewall&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If so, then the USB port cannot be accessed after the NGFW has booted?&amp;nbsp; I like that from a security perspective.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
    <pubDate>Thu, 21 Sep 2023 13:08:52 GMT</pubDate>
    <dc:creator>TomYoung</dc:creator>
    <dc:date>2023-09-21T13:08:52Z</dc:date>
    <item>
      <title>Disable USB Port on Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/disable-usb-port-on-firewall/m-p/558924#M113366</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can we disable physical USB port on the Firewall?&lt;/P&gt;
&lt;P&gt;I didn't find how to disable this usb interface on the firewall. or is there any documentation&amp;nbsp; how to disable this?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Denny&lt;/P&gt;</description>
      <pubDate>Thu, 21 Sep 2023 06:19:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/disable-usb-port-on-firewall/m-p/558924#M113366</guid>
      <dc:creator>DennyChanditya</dc:creator>
      <dc:date>2023-09-21T06:19:56Z</dc:date>
    </item>
    <item>
      <title>Re: Disable USB Port on Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/disable-usb-port-on-firewall/m-p/558996#M113376</link>
      <description>&lt;P&gt;I'm not entirely sure, but enabling FIPS-CC mode would be your most likely candidate. it does disable the console port for anything but output&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/certifications/enable-fips-and-common-criteria-support/change-the-operational-mode-to-fips-cc-mode" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/certifications/enable-fips-and-common-criteria-support/change-the-operational-mode-to-fips-cc-mode&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/certifications/fips-cc-security-functions" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/certifications/fips-cc-security-functions&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Sep 2023 11:49:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/disable-usb-port-on-firewall/m-p/558996#M113376</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2023-09-21T11:49:12Z</dc:date>
    </item>
    <item>
      <title>Re: Disable USB Port on Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/disable-usb-port-on-firewall/m-p/558998#M113378</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/187777"&gt;@DennyChanditya&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The option to disable USB is currently not available. There is an existing feature request with ID:11893. &lt;BR /&gt;Please reach out to your local SE to add your vote to this FR.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://live.paloaltonetworks.com/t5/blogs/how-to-use-palo-alto-networks-new-feature-request/ba-p/409590" target="_blank"&gt;https://live.paloaltonetworks.com/t5/blogs/how-to-use-palo-alto-networks-new-feature-request/ba-p/409590&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://live.paloaltonetworks.com/t5/blogs/how-to-add-a-new-feature/ba-p/272149" target="_blank"&gt;https://live.paloaltonetworks.com/t5/blogs/how-to-add-a-new-feature/ba-p/272149&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Kind regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-Kim.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Sep 2023 11:53:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/disable-usb-port-on-firewall/m-p/558998#M113378</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2023-09-21T11:53:31Z</dc:date>
    </item>
    <item>
      <title>Re: Disable USB Port on Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/disable-usb-port-on-firewall/m-p/559008#M113382</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/187777"&gt;@DennyChanditya&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That is a great question!&amp;nbsp; You probably want to disable it for compliance reasons in which case my thoughts are no help.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt; and &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11943"&gt;@kiwi&lt;/a&gt;, Is it true that the USB port is used only for bootstrapping, and the NGFW only reads the USB "only when it is in factory default state or has all private data deleted"?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/firewall-administration/bootstrap-the-firewall/usb-flash-drive-support" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/firewall-administration/bootstrap-the-firewall/usb-flash-drive-support&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/firewall-administration/bootstrap-the-firewall/prepare-a-usb-flash-drive-for-bootstrapping-a-firewall" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/firewall-administration/bootstrap-the-firewall/prepare-a-usb-flash-drive-for-bootstrapping-a-firewall&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If so, then the USB port cannot be accessed after the NGFW has booted?&amp;nbsp; I like that from a security perspective.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Thu, 21 Sep 2023 13:08:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/disable-usb-port-on-firewall/m-p/559008#M113382</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-09-21T13:08:52Z</dc:date>
    </item>
    <item>
      <title>Re: Disable USB Port on Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/disable-usb-port-on-firewall/m-p/559057#M113390</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;If this is for compliance, I would suggest using compensating physical controls, like locked cabinet doors, restricted access to room, etc. On a side note, its a great way to charge your phone if at the data center for a long time :).&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Thu, 21 Sep 2023 20:01:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/disable-usb-port-on-firewall/m-p/559057#M113390</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2023-09-21T20:01:57Z</dc:date>
    </item>
  </channel>
</rss>

