Does a security configuration benchmark/checklist exist for Palo Alto firewalls?

Reply
Highlighted
L2 Linker

Does a security configuration benchmark/checklist exist for Palo Alto firewalls?

There's a ton of fantastic best practices guides on this site in addition to the admin guides. I was wondering if a best practices security configuration benchmark or checklist exists for PA firewalls.

Something I can hand an IT auditor, similar to this:

http://goo.gl/JgmTTc


L7 Applicator

Re: Does a security configuration benchmark/checklist exist for Palo Alto firewalls?

Hello RyanF,

Since PAN firewall is having multiple options ( based on available licenses) for a deeper packet inspection, hence PAN does not have any recommended security settings. But, you may refer below mentioned documents for individual security features.

What are the Data Filtering Best Practices?

Amsterdam Oct 2014 - AppID best practices config example  >>>>> you may need help from your PAN SE to view this doc.

URL White List for SSL Sites Best Practices

How to Configure WildFire

Understanding DoS Protection

Hope this helps.

Thanks

L3 Networker

Re: Does a security configuration benchmark/checklist exist for Palo Alto firewalls?

Nessus has a very basic configuration check as well.

http://www.tenable.com/solutions/configuration-auditing

best practice is to use publically available hardening guides for other platforms.

NIST, DISA, NSA has several for other platforms that can be applied / referenced.

L1 Bithead

Re: Does a security configuration benchmark/checklist exist for Palo Alto firewalls?

Yes Palo Alto Configuration benchmark was recently released by SANS

http://www.sans.org/reading-room/whitepapers/auditing/palo-alto-firewall-security-configuration-benc...

YMMV, but it is very comprehensive.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!