security policies

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

security policies

hello , i need to extract security policies from palo alto appliance  

Model (PA-460)  

 

is there a way to schedule the report or grant read only access to audit function ?

1 REPLY 1

Community Team Member

Hi @mostafa.abdelhakem ,

 

To accomplish this on a PA-460, you have two distinct approaches depending on whether you want a push method (scheduling automated email reports) or a pull method (granting direct, read-only access to an external auditor).

 

Because "Security Policies" are part of the firewall's XML configuration file rather than dynamic traffic data, standard PDF custom reports won't show the exact rule geometry. However, for auditing Palo Alto policies you can configure notifications for configuration changes under Device > Log Settings > Configurations.

 

As for granting Read-Only Access to an Auditor,  you can create a customized Admin Role Profile:

  1. Navigate to Device > Admin Role and click Add.

  2. Name the profile something clear (e.g., Auditor-Read-Only).

  3. Under the Web UI tab, set the rules for the tabs you want them to see.

Then you can create the actual auditor account.  Go to Device > Administrators and click create a role based admin using the profile you just created earlier. 

 

Hope this helps,

LIVEcommunity team member, CISSP
Cheers,
Kiwi
Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.
  • 39 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!