- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
08-28-2024 07:01 PM
I am seeing that we have different Palo Alto provided Security Profiles that we can map to the security policy. What would best strategy to test it first in lower environments before rolling onto prod ?
We just want to make sure it should not create any problems to existing traffic.
Right now, we are not using for each security policy. But we want to use.
any kind of help would be greatly appreciated.
ty
09-02-2024 04:20 AM
Hi @Khanna075 ,
When I do a migration from a another vendor firewall to Palo Alto, I used to test the security profiles 1st. Here was my process:
To be honest, it has been a while since I have done that. I found very little false positives as I did many migrations. There were some. Today, I enable all the security profiles; have the customer perform their test plan; and troubleshoot the false positives the night of the cut-over or the next day.
It is important to run a BPA on the new NGFW before the cutover because the BPA recommends additional security profile settings that the Day 1 Configuration does not have.
Thanks,
Tom
08-29-2024 09:37 AM
Can someone please suggest me any inputs on this ?
09-01-2024 09:22 PM
Hello @Khanna075
thanks for posting question.
We had a similar situation in the past. We used AD group of IT / Security Department as a source user to limit the policies with strict security profile for testing before rolling this out to rest of the policies. Alternatively you can use source IP address (Source subnet if this is possible in your case) to limit policies with strict security profile.
Kind Regards
Pavel
09-02-2024 04:20 AM
Hi @Khanna075 ,
When I do a migration from a another vendor firewall to Palo Alto, I used to test the security profiles 1st. Here was my process:
To be honest, it has been a while since I have done that. I found very little false positives as I did many migrations. There were some. Today, I enable all the security profiles; have the customer perform their test plan; and troubleshoot the false positives the night of the cut-over or the next day.
It is important to run a BPA on the new NGFW before the cutover because the BPA recommends additional security profile settings that the Day 1 Configuration does not have.
Thanks,
Tom
09-05-2024 04:34 AM
Thanks Pavel for your inputs.
It is helpful to plan my requirement.
09-05-2024 04:35 AM
Thank you much Tom for taking out time and sharing your inputs. This actually covers everything that I need to consider my planning.
Really appreciate the help!
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!