Does a security configuration benchmark/checklist exist for Palo Alto firewalls?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Does a security configuration benchmark/checklist exist for Palo Alto firewalls?

L2 Linker

There's a ton of fantastic best practices guides on this site in addition to the admin guides. I was wondering if a best practices security configuration benchmark or checklist exists for PA firewalls.

Something I can hand an IT auditor, similar to this:

http://goo.gl/JgmTTc


3 REPLIES 3

L7 Applicator

Hello RyanF,

Since PAN firewall is having multiple options ( based on available licenses) for a deeper packet inspection, hence PAN does not have any recommended security settings. But, you may refer below mentioned documents for individual security features.

What are the Data Filtering Best Practices?

Amsterdam Oct 2014 - AppID best practices config example  >>>>> you may need help from your PAN SE to view this doc.

URL White List for SSL Sites Best Practices

How to Configure WildFire

Understanding DoS Protection

Hope this helps.

Thanks

L3 Networker

Nessus has a very basic configuration check as well.

http://www.tenable.com/solutions/configuration-auditing

best practice is to use publically available hardening guides for other platforms.

NIST, DISA, NSA has several for other platforms that can be applied / referenced.

L1 Bithead

Yes Palo Alto Configuration benchmark was recently released by SANS

http://www.sans.org/reading-room/whitepapers/auditing/palo-alto-firewall-security-configuration-benc...

YMMV, but it is very comprehensive.

  • 4305 Views
  • 3 replies
  • 1 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!