Hide Public IPs

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Hide Public IPs

Not applicable

I've been getting a lot of traffic from 'unfriendly' countries trying to gain access to a service we provide via one of our NAT'ed public ip address. I know for a fact they have no business connecting to that service. Is there a setting on the Palo Alto to hide my Public ip addresses? In that same vain, can I also hide what ports/protocols I have open to the outside world?

Thank you

1 REPLY 1

L6 Presenter

You can set a security rule before your current allow rule which will blacklist certain ranges.

In PA you can set range by country (this list is basically maxmind's GeoIP and some other sources if im not mistaken and updated through app-id database I think) so you can somewhat "ban" a whole country or region. And in case you dont want to see these blocks in your logs this blacklist rule can be set to not log a thing.

A better method is to make your allow rule as narrow as possible.

The design could be:

1) Blacklist rules (as wide as possible and mostly to ban for global access no matter which service they wish to connect to).

2) Allow rules (as narrow as possible).

3) Default deny + log (stuff that isnt allowed elsewhere should be logged if you are interrested in those logs).

The tricky part is that the "attacker" will of course, depending on protocol, see that they are being blocked because PA currently doesnt allow you to set HOW the blacklist should block the client (which method is being used depends on which protocol the client requested and is set by PA themselfs).

It seems that many PA-users have already sent this as a feature request to their Sales Engineers (so it would be great if you could do this aswell) so you as a PA-admin could decide how the block should be performed (just drop or deny where the deny will send a packet back to the client with either tcp-rst or icmp net/host unreachable or icmp administratively prohibited).

In your case I would prefer to just drop the traffic (the attacker will not get an answer at all not even that the port is closed).

  • 2292 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!