Best Practice Assessment Release Notes

Announcements

ATTENTION Customers, All Partners and Employees: The Customer Support Portal (CSP) will be undergoing maintenance and unavailable on Saturday, November 7, 2020, from 11 am to 11 pm PST. Please read our blog for more information.

      Adoption capability with License details New feature   Details: When a license is expired or inactive its respective features do not work at their best. For instance if URL filtering license is expired then URL filtering capability, Credential Phishing protection capability gets outdated and may not provide effective security coverage. With this addition now we can see a notification if license is expired so that we can identify if the adoption is effective or not.   DNS Security Service New feature   Details: When the DNS security license is active we ensure the DNS security service is configured according to best practice. In the DNS Signature tab in Anti-spyware profile we can select the DNS securit service EDL and set to action = sinnkhole and single packet capture to pass the best practice.   License validation based on enabled features New feature   Details: When using certain features that need license to be active and if license gets expired this new check will indicate the necessity of license to run the feature at optimal and as expected. Ex: If Anti-spyware is enabled on firewall policies but the license is not active or expired then the check would provide an indication to enable the license to ensure the feature works as intended.   Updated BPA Mapping Definitions Table  Bug   Details: Updated the BPA Mapping definition table under BPA component with new checks and its respective columns pertaining to security controls such a Capability Summary, CIS Critical Security controls.   Updated Wildfire file sizes for Pdf and MSoffice file types Bug   Details: Wildfire file size values for types Pdf and Msoffice was not accurate and had been rounded. These values were updated as per the recommendation.
View full article
‎09-18-2020 11:33 AM
1,143 Views
0 Replies
v3.17.0 - Released on 8/13/2019   New Features   Log Forwarding URL Settings Details: When you create Log Forwarding profiles, forward URL logs to Panorama or another logging system, such as a syslog, SNMP, email, or HTTP server, so you can ensure URL activity logs are retained for a certain duration for compliance reasons, identifying URL activity that was not expected, and any web traffic pattern of compromised systems.     Log Forwarding Authentication Settings Details: When you create Log Forwarding profiles, forward Authentication logs to Panorama or another external logging space, such as a syslog, SNMP, email, or HTTP server, so you can ensure any resources accessed through authentication is recorded and saved for compliance, identifying and correcting authentication policies if extra resources are provided than needed and if any future incident handling.     Security Policy Inbound Malicious IP Feed Details: Before you allow and block traffic by application, it is advisable to block traffic from IP addresses that Palo Alto Networks and trusted third-party sources have proven to be malicious. The rule will ensure that your network is always protected against the IP addresses from the Palo Alto Networks malicious IP address feeds and other feeds, which are compiled and dynamically updated based on the latest threat intelligence.     Security Policy Outbound Malicious IP Address Feed Details: Before you allow and block traffic by application, it is advisable to block traffic from IP addresses that Palo Alto Networks and trusted third-party sources have proven to be malicious. The security rule will ensure that your network is always protected against the IP addresses from the Palo Alto Networks malicious IP address feeds and other feeds, which are compiled and dynamically updated based on the latest threat intelligence. Ensure the security rule is logging at session end and log forwarding profile is applied to track activity.     Security Policy Inbound High Risk IP Address Feed Details: Before you allow and block traffic by application, it is advisable to block traffic from IP addresses that Palo Alto Networks and trusted third-party sources have proven to be High risk in nature. The security rule will ensure that your network is always protected against the IP addresses from the Palo Alto Networks malicious IP address feeds and other feeds, which are compiled and dynamically updated based on the latest threat intelligence. Ensure the security rule is logging at session end and log forwarding profile is applied to track activity.     Security Policy Outbound High Risk IP Address Feed Details: Before you allow and block traffic by application, it is advisable to block traffic from IP addresses that Palo Alto Networks and trusted third-party sources have proven to be high risk in nature. The security rule will ensure that your network is always protected against the IP addresses from the Palo Alto Networks malicious IP address feeds and other feeds, which are compiled and dynamically updated based on the latest threat intelligence. Ensure the security rule is logging at session end and log forwarding profile is applied to track activity.     HA Content Versions Details: This check ensures both the pairs in High Availability (HA) setup are the latest content versions. The content versions checked are Apps and Threat, Antivirus, and URL database. Both pairs in HA will work at optimal levels if the content versions are the same between the devices. The firewall will take same action on traffic if the devices have same content version, so the expected behavior is same across.     Enhancements Added Industry Average trending for ZPP, Log forwarding, and Credential Phishing prevention Added "Rules using Profile" and "Rules using Profile Pct" for Log-forwarding profile, Decryption profile, and DoS protection profiles Added logic to resolve Panorama template variables Improved logic for check #222 – Content-Based Critical System Logs Bug Fixes Fixed a display issue in the HTML report for Application Tags Fixed a calculation bug with the "Rules using Profile Pct" values v3.17.1 (Hotfix) - Released on 8/16/2019 Fixed a parsing issue with Decryption Policies and DoS Protection Policies
View full article
‎09-18-2020 11:33 AM
1,187 Views
0 Replies
  BPA Release Notes v4.0   This is a major feature release. Below are the highlights of the release,   Complete UI styleguide redesign aligning with other company products. Front end tech stack has been upgraded for improved performance and scalability. Created almost 200 short videos for each Best Practice Check that is embedded within the BPA HTML report. Developed a new splash page to enable users to learn about any new capabilities within the product. Created a usability improvement by linking different sections with in the BPA report to take customers from the summary graphs to individual checks - this guides the customer focus to the priority improvement areas. The spreadsheet has been updated to not only show the failed checks but also including the passed checks with added column for BPA Verdict. On a Panorama run BPA report, we now can show a Heatmap adoption for selected Device group in relation to their device group hierarchy so that total context is clear and evident.
View full article
‎09-14-2020 12:29 PM
257 Views
0 Replies
  BPA Release Notes v3.36   Bugs Fixed an issue on BP check "PanOS Release Date" PanOS Release date in certain conditions was not being accurately getting the right value and inaccurately reporting the analysis.   Fixed an issue on BP check "Local Admins" Local Admins BP check will validate minimum password complexity check but it was failing for this check. The criteria needed to be updated.   Fixed an issue on BP check "Authentication Profile" Local admin count was not being calculated as expected and the Authentication Profile BP check was failing. This has been corrected and we have added new field for Local Admin user count.    
View full article
‎07-01-2020 03:51 PM
401 Views
0 Replies
  BPA Release Notes v3.35   Bugs Fixed 'Inbound Malicious IP Address' BP Check with Hierarchy An issue was identified that was not taking into account for a security rule configured in the hierarchical device groups and failing.  
View full article
‎07-01-2020 03:21 PM
342 Views
0 Replies
  BPA Release Notes v3.34   Bugs   Intrazone Rule with Action Deny We have fixed this best practice check now. If the Intrazone rule is set with Action=Deny then that security rule is excluded from this check analysis.      
View full article
‎06-03-2020 04:39 PM
431 Views
0 Replies
  BPA Release Notes v3.33   New Features   Improvements on 'Mapping Definitions' section  We have added, a - 'Passing Occurence' column - Now we can know how many number of times a single BP check has been parsed in a configuration and check how many times it has passed out of total occurrences seen in the configuration. b - On mouse over the '?' button we can identify the details on how the calculation is made for Passing %, Previous Passing % and Passing Occurence c - Total - How the total value is derived and its calculation on the filtered results.   Passing Occurence and details on calculation for Passing % and Total values      HTTP/2 Protocol inspection We have added a new check to ensure if customer expecting HTTP/2 protocol traffic then they have the right configuration in place to permit this traffic through the firewall.   'Security Profile Verdict' New filter in 'Rule Detail' Tab Now we can have the ability to filter security rules which have security profiles with pass or fail BP check verdicts. We can export the list of rules to fix them or scope the work.   Security Profile Verdict - Filter in BPA   Bugs   Fixed some text typos in BPA informational section  
View full article
‎06-03-2020 04:33 PM
388 Views
0 Replies
  BPA Release Notes v3.32   Bugs Quic App Deny rule BP check This BP check was failing in a scenario when it was supposed to pass. Needed an update ordering of pre-rulebase, post-rulebase to resolve the issue.   User ID timeout BP check update This BP check was failing due to overwriting of data. This has been fixed and correct configuration value is parsed and BP check verdict is created.   BPA report generation issue There was an encoding issue that needed to be updated that fixed the issue and user could generate the BPA report.  
View full article
‎05-05-2020 08:45 AM
491 Views
0 Replies
Read about the recent BPA Release Notes in v3.31. See what improvements have been made and what bugs have been resolved.
View full article
‎04-08-2020 10:54 AM
631 Views
0 Replies
Read the BPA Release Notes v3.30 and see what's new. Find out if there were any new features or bugs that were addressed in the release notes.
View full article
‎04-06-2020 03:02 PM
587 Views
0 Replies
Review the new BPA Release Notes for v3.27. See how the new features and bug fixes can help you with checking your system for vulnerabilities. 
View full article
‎04-03-2020 03:37 PM
592 Views
0 Replies
Review the improvements and bug fixes for the BPA. See how the fixed BP Mode Summary Graph can help you.
View full article
‎04-03-2020 02:58 PM
620 Views
0 Replies
   BPA Release Notes v3.29   Improvements   Update to NIST Security Controls We have renamed 'Control Category Summary' graph to 'NIST Security Controls' in the BPA Summary report, PDF Executive reports and other places as needed.   Bugs   BPA report bundle generation through API Fixed an error where a large file could not be processed to generate the BPA report bundle through BPA API.    
View full article
‎03-11-2020 11:30 AM
638 Views
0 Replies
Read about the new features in this BPA release notes v3.26, which includes: Filter option added in BPA for Pass/Fail checks.
View full article
‎01-29-2020 02:13 PM
789 Views
0 Replies
1 Like
Read about the new features, updates, and bug fixes in the BPA Release Notes v3.25.
View full article
‎01-28-2020 01:56 PM
716 Views
0 Replies
Review BPA Release Notes v3.24 to learn about the new features, improvements, and current bug fixes that will help improve the BPA tool experience. 
View full article
‎01-06-2020 02:03 PM
760 Views
0 Replies
Review the BPA release notes for V3.23. Learn how we added managed devices count on the Panorama report and a forwarding decryption check. We also explain some of the bugs that were fixed.
View full article
‎01-06-2020 01:48 PM
798 Views
0 Replies
Review BPA Release Notes for V3.21. Learn about the updates to bug fixes such as updated file blocking profile check, updated Intrazone rule check, and an Xpath evaluation error update.
View full article
‎12-26-2019 09:00 AM
874 Views
0 Replies
View the BPA Release Notes for V3.22. Learn about the added new URL category Grayware part of blocked categories and a check for DNS Security License. We also corrected a bug about parsing accurately.
View full article
‎12-17-2019 11:39 AM
837 Views
0 Replies
  New Features   Number of Managed Devices on Panorama Now we can start tracking how many firewalls are being managed by the Panorama. At times, our adoption percentage values may change due to addition/removal of firewalls, and having the ability to know a change in the managed devices helps explain the change in adoption values.   BPA tracking columns for firewalls managed by Panorama.   New link added in CIS Critical Security Controls The second link that is added helps map CIS Critical Security Controls to other security controls and frameworks.   CIS Critical Security Controls 7.0 Summary with a highlighted section for a link to frameworks and standards information.   Class Summary Documentation Added the Class Summary reference to Control Category   Class Summary reference in Control Category   Bug Fixes Wildfire Profile File Types: Fixed a bug on Wildfire profile if customer defined specific file types then validate if all the relevant file types are defined to ensure all zero-day file types are inspected in sandbox.   Failed Attempts: Fixed a bug where Admin user login failed attempt was passing when the value was set at 0. Failed attempt for admin users should be a fixed value in the range 1 - 5   Idle Timeout: Fixed a bug where Admin user Idle timeout was passing when the value was set at 0. Idle timeout for admin users should be a fixed value in the range 1 - 10   Included Networks: Fixed a bug for Included Networks check where it needed an update on the error message and that is updated now.   Interface Management Profile: Fixed a bug where the protocols enabled for Interface management profile are correctly parsed on a Template configuration.   Mapping Definitions Control Category: Fixes a calculation error for Risk Assessment control category under Mapping Definitions  
View full article
‎10-28-2019 04:04 PM
1,075 Views
0 Replies
v3.19.0 - Released on 9/9/2019   In addition to the enhancements and bug fixes included in this release, the team is hard at work on a major update of the HTML report to be more consistent with the company’s product style guide. Stay tuned for more!   Enhancements Updated check #207 – Credential Theft feature now ensures that business credentials compromising URL categories are set to “Block”   Update logic for WildFire file size checks on PAN-OS < 8.1 to provide a note if the file sizes exceed the recommended value   Added logic to rename "Captive Portal Policy" to "Authentication Policy" if PAN-OS 8.0+   Bug Fixes Updated formula for Zone Protection Profile Adoption calculation to use all enabled rules Fixed a bug with the Rules using Profile % calculations v3.19.1 (Hotfix) - Released on 9/13/2019 Fixed a display issue where Interface Mgmt Network Profiles were missing from the HTML report v3.19.2 (Hotfix) - Released on 9/19/2019 Fixed a bug related to parsing template variables
View full article
‎09-19-2019 10:57 AM
1,116 Views
0 Replies
v3.18.0 - Released on 8/26/2019 At face value, this release squashes several bugs from our backlog. Behind the scenes, however, we are refactoring the codebase to support a larger re-write of the HTML report. More to follow in future releases!   Bug Fixes Fixed GRE Tunnel Keep Alive default values Fixed location of BPA check #71 – GP Portal Agent Config – App Configurations: Enforce GlobalProtect Connection for Network Access in the HTML report
View full article
‎09-03-2019 10:33 AM
1,105 Views
0 Replies
Go here to see the release notes from the June 24, 2019 release. 
View full article
‎07-29-2019 09:12 AM
1,248 Views
0 Replies
Observe the BPA Release Notes for v3.15 released on July 16, 2019. This reveals updates, fixed bugs, and enhancements made to the Best Practice Assessment.
View full article
‎07-29-2019 08:19 AM
1,519 Views
0 Replies
CSP maintenance