<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: External access question in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/external-access-question/m-p/216548#M62726</link>
    <description>&lt;P&gt;Thanks Otakar and Robin,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's reassuring to hear your positive feedback on this design. I will also create the zone...first time zone for me, but I should be able to follow the design of a similar zone already in place.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
    <pubDate>Mon, 04 Jun 2018 20:12:20 GMT</pubDate>
    <dc:creator>tsheldon</dc:creator>
    <dc:date>2018-06-04T20:12:20Z</dc:date>
    <item>
      <title>External access question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/external-access-question/m-p/216205#M62641</link>
      <description>&lt;P&gt;Hi, I am a network admin and sometimes SQL admin. I have been asked to allow a consultant to build a database reporting server on our network. He will VPN into our network through a Palo Alto firewall and use RDP to access a single non-domain server called "Reports." A firewall rule will control this access. On the Reports server, the consultant will log in with a non-admin account, but have db-owner rights to SQL Server. He will use SQL Server to connect with two other SQL Servers on the network with read-only permissions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anyone see any holes in this scheme? I want to make sure the consultant can't do anything else on the internal network except build a database on Reports and query/collect data on the two other SQL servers. I&lt;SPAN&gt; don't have much control over the security configuration of the consultants computer. Should I go so far as to isolate the Reports server on a Palo Alto controlled subnet?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Any suggestions are appreciated.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 31 May 2018 22:50:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/external-access-question/m-p/216205#M62641</guid>
      <dc:creator>tsheldon</dc:creator>
      <dc:date>2018-05-31T22:50:56Z</dc:date>
    </item>
    <item>
      <title>Re: External access question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/external-access-question/m-p/216214#M62642</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Sounds like a good plan. I would even try to microsegment that server into its own zone. You could even get crazier and have them have their own VPN profile, but that is overkill.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 01 Jun 2018 00:36:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/external-access-question/m-p/216214#M62642</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-06-01T00:36:35Z</dc:date>
    </item>
    <item>
      <title>Re: External access question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/external-access-question/m-p/216236#M62648</link>
      <description>&lt;P&gt;I would put the reports server in it's own ZONE (or your DMZ at a push) and only allow the required traffic from that ZONE to the SQL server on the production network.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;</description>
      <pubDate>Fri, 01 Jun 2018 09:22:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/external-access-question/m-p/216236#M62648</guid>
      <dc:creator>RobinClayton</dc:creator>
      <dc:date>2018-06-01T09:22:42Z</dc:date>
    </item>
    <item>
      <title>Re: External access question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/external-access-question/m-p/216548#M62726</link>
      <description>&lt;P&gt;Thanks Otakar and Robin,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's reassuring to hear your positive feedback on this design. I will also create the zone...first time zone for me, but I should be able to follow the design of a similar zone already in place.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jun 2018 20:12:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/external-access-question/m-p/216548#M62726</guid>
      <dc:creator>tsheldon</dc:creator>
      <dc:date>2018-06-04T20:12:20Z</dc:date>
    </item>
  </channel>
</rss>

