Reader small image

You're reading from  Mastering Palo Alto Networks - Second Edition

Product typeBook
Published inJun 2022
PublisherPackt
ISBN-139781803241418
Edition2nd Edition
Concepts
Right arrow
Author (1)
Tom Piens aka Piens aka 'reaper'
Tom Piens aka Piens aka 'reaper'
author image
Tom Piens aka Piens aka 'reaper'

Tom Piens is a seasoned cybersecurity professional with a distinguished career closely tied to Palo Alto Networks. With over two decades of experience in the field, Tom has played a pivotal role in shaping the digital defense landscape. His journey began as the first international (outside of the continental US) support engineer at Palo Alto Networks, where he rapidly ascended the ranks due to his remarkable aptitude for innovative solutions. Beyond his technical prowess, Tom's passion for knowledge transfer has made him a sought-after mentor. He's been instrumental in cultivating a dynamic learning environment within the Palo Alto Networks LIVE community, fostering a culture of continuous growth and excellence. His innate ability to simplify complex concepts has empowered his colleagues to stay at the forefront of cybersecurity trends.
Read more about Tom Piens aka Piens aka 'reaper'

Right arrow

Virtual Private Networks

In this chapter, we will learn about site-to-site VPNs and the challenges you may encounter when connecting to different vendors. We will learn how to set up a GlobalProtect user VPN and verify whether hosts connecting remotely are in a permissible state to enter the network or need to be quarantined.

In this chapter, we’re going to cover the following main topics:

  • Site-to-site VPNs
  • The GlobalProtect client and satellite VPNs

By the end of this chapter, you’ll be able to connect remote locations and remote users to a datacenter or central office in a secure way.

Technical requirements

In this chapter, we will be covering remote connections and protection from inbound connections. If you have a lab environment where you can simulate setting up VPN connections to other devices or produce incoming connections from a client, this will help greatly in visualizing what is being explained.

Setting up the VPN

There are several ways of connecting devices in a secure way.

Palo Alto Networks firewalls currently support the following protocols:

  • Generic Routing Encapsulation (GRE) is a fairly old protocol that is not very secure but can be useful if legacy devices need to be connected to the firewall to provide rudimentary security to the encapsulated packets.
  • Internet Protocol Security (IPSec) is the de facto tunneling protocol between remote sites and can be used for very strong encryption.
  • Secure Socket Layer (SSL), which is really Transport Layer Security (TLS), is used to connect endpoints over a network-friendly protocol.

To set up GRE tunnels, you can set up a connection in Networks | GRE Tunnels. All you need to configure is the following:

  • Name (this can be any description)
  • Source interface
  • Source IP is the IP associated with the source interface
  • Destination IP is the IP for the remote peer
  • Tunnel...

Summary

In this chapter, you learned how to set up site-to-site VPN tunnels and a client-to-site VPN with GlobalProtect. You can now not only provide connectivity but also scan the client machine for compliancy and know how to control the user experience.

In the next chapter, we will learn about creating custom applications and custom signatures for threat prevention, and how to apply zone protection and protect individual services using DoS protection profiles and policies.

If you’re preparing for the PCNSE, remember that the clientless VPN is a proxied connection and that applications must be created. You’ll need to understand the difference between the GlobalProtect Portal and Gateway, and know which features require an additional license (mobile clients, split tunnels for applications and domains, HIP checks, Clientless VPN, IPv6, and split DNS).

lock icon
The rest of the chapter is locked
You have been reading a chapter from
Mastering Palo Alto Networks - Second Edition
Published in: Jun 2022Publisher: PacktISBN-13: 9781803241418
Register for a free Packt account to unlock a world of extra content!
A free Packt account unlocks extra newsletters, articles, discounted offers, and much more. Start advancing your knowledge today.
undefined
Unlock this book and the full library FREE for 7 days
Get unlimited access to 7000+ expert-authored eBooks and videos courses covering every tech area you can think of
Renews at $15.99/month. Cancel anytime

Author (1)

author image
Tom Piens aka Piens aka 'reaper'

Tom Piens is a seasoned cybersecurity professional with a distinguished career closely tied to Palo Alto Networks. With over two decades of experience in the field, Tom has played a pivotal role in shaping the digital defense landscape. His journey began as the first international (outside of the continental US) support engineer at Palo Alto Networks, where he rapidly ascended the ranks due to his remarkable aptitude for innovative solutions. Beyond his technical prowess, Tom's passion for knowledge transfer has made him a sought-after mentor. He's been instrumental in cultivating a dynamic learning environment within the Palo Alto Networks LIVE community, fostering a culture of continuous growth and excellence. His innate ability to simplify complex concepts has empowered his colleagues to stay at the forefront of cybersecurity trends.
Read more about Tom Piens aka Piens aka 'reaper'