Consigas - Palo Alto Networks Training Channel
Consigas - Palo Alto Networks Training Channel
  • Видео 18
  • Просмотров 215 916
Authenticating GlobalProtect and Prisma Access remote access users against Office365 Azure AD
Palo Alto Networks Training @ www.consigas.com - FireWall Best Practices | Want to learn more? Our Palo Alto Networks Courses teach you how to master the Next-Generation FireWall.
Update 29.06.2020 - Mitigate SAML Bypass Vulnerability without an upgrade (CVE-2020-2021) - This video explains how to securely set up SAML authentication end-to-end against Office 365 Azure AD. The critical element which explains how to set up certificate validation of the SAML Identity Provider starts at 29:35. With this configuration, there is no immediate need to upgrade the FireWall, although an upgrade should always be considered. It also fixes the commit error "Validate Identity Provider Certificate is che...
Просмотров: 14 744

Видео

Policy based Forwarding "PBF" - Palo Alto Networks FireWall Concepts Training Series
Просмотров 32 тыс.7 лет назад
Getting a network to fail-over between the two Internet lines or even load balance traffic between them can be real challenge. In this Palo Alto Networks Training Video, we will show you how it can be done using policy based forwarding "PBF". Security Best Practices Training for Palo Alto Networks - videos will be soon published on our webpage, sign up on bit.ly/2yakige and we will let you know...
Virtual Router - Palo Alto Networks FireWall Concepts Training Series
Просмотров 32 тыс.7 лет назад
Fully separating traffic is easy with the Next-Generation FireWall. While with other vendors you might need dedicated virtual systems, with Palo Alto Networks just adding another virtual router is enough. In this Palo Alto Networks Training Video, we will show you the concept including inter VR routing. Security Best Practices Training for Palo Alto Networks - videos will be soon published on o...
Layer 2 interfaces - Palo Alto Networks FireWall Concepts Training Series
Просмотров 25 тыс.7 лет назад
If you have some constrains in your network then using Layer-2 interfaces can be very powerful, but it can become very complex very quickly so its important to keep it simple. In this Palo Alto Networks Training Video, we will explain you the concept and some use cases. Security Best Practices Training for Palo Alto Networks - videos will be soon published on our webpage, sign up on bit.ly/2yak...
Tap interfaces - Palo Alto Networks FireWall Concepts Training Series
Просмотров 6 тыс.7 лет назад
Security Best Practices Training for Palo Alto Networks - videos will be soon published on our webpage, sign up on bit.ly/2yakige and we will let you know once they are available Security Best Practices Checklist for Palo Alto Networks Next-Generation FireWalls - download from our blog www.consigas.com/blog/security... Follow us on: ➜ LinkedIn bit.ly/consigaslinkedin ➜ Twitter Consi...
Virtual-Wire - Palo Alto Networks FireWall Concepts Training Series
Просмотров 14 тыс.7 лет назад
Deploying the Next-Generation FireWall using a Virtual-Wire is the fastest way to get it into the network and with this establish Full Visibility and control. In this Palo Alto Networks Training Video, we will explain you the concept and some use cases​. Security Best Practices Training for Palo Alto Networks - videos will be soon published on our webpage, sign up on bit.ly/2yakige and we will ...
Interface Management Profile - Palo Alto Networks FireWall Concepts Training Series
Просмотров 3,3 тыс.7 лет назад
Interface Management Profiles are an important element when setting up Layer-3 interfaces. In this Palo Alto Networks Training Video, we will show you what it is and how it works. Security Best Practices Training for Palo Alto Networks - videos will be soon published on our webpage, sign up on bit.ly/2yakige and we will let you know once they are available Security Best Practices Checklist for ...
Layer 3 sub-interfaces - Palo Alto Networks FireWall Concepts Training Series
Просмотров 12 тыс.7 лет назад
Setting up a new physical interface can be cumbersome because you first have to get them cabled up and then you even need to be lucky enough to have an interface left. In this Palo Alto Networks Training Video, we will show you how to add a nearly unlimited amount of interfaces without cabling using Layer-3 sub-interfaces. Security Best Practices Training for Palo Alto Networks - videos will be...
Layer 3 interfaces - Palo Alto Networks FireWall Concepts Training Series
Просмотров 6 тыс.7 лет назад
Layer 3 should be your preferred deployment method for the Palo Alto Networks Next-Generation FireWalls. In this Palo Alto Networks Training Video, we explain you the concept, short and simple.​ Security Best Practices Training for Palo Alto Networks - videos will be soon published on our webpage, sign up on bit.ly/2yakige and we will let you know once they are available Security Best Practices...
Service Route - Palo Alto Networks FireWall Concepts Training Series
Просмотров 6 тыс.7 лет назад
Why using the Service Route on the Palo Alto Networks Next-Generation FireWall or you might even ask What is it? In this Palo Alto Networks Training Video, we will explain you the concept and our best practices. Security Best Practices Training for Palo Alto Networks - videos will be soon published on our webpage, sign up on bit.ly/2yakige and we will let you know once they are available Securi...
Configuration Management - Palo Alto Networks FireWall Concepts Training Series
Просмотров 4,1 тыс.7 лет назад
The Palo Alto Networks Next-Generation FireWall has some powerful functions to manage its configuration but at the same time it can be very confusing if you are used to other FireWall vendors. In this Palo Alto Networks Training Video, we will explain you the concept of Configuration Management so you can make full use of it. Security Best Practices Training for Palo Alto Networks - videos will...
How to protect the Datacenter - Palo Alto Networks FireWall Concepts Training Series
Просмотров 6 тыс.7 лет назад
In this Palo Alto Networks Training Video, we will show the Threat Prevention Techniques of the Palo Alto Networks Next-Generation FireWall that will protect the datacenter. Security Best Practices Training for Palo Alto Networks - videos will be soon published on our webpage, sign up on bit.ly/2yakige and we will let you know once they are available Security Best Practices Checklist for Palo A...
How to protect end-users - Palo Alto Networks FireWall Concepts Training Series
Просмотров 7 тыс.7 лет назад
In this Palo Alto Networks Training Video, we will show the Threat Prevention Techniques of the Palo Alto Networks Next-Generation FireWall that will protect end-user devices. Security Best Practices Training for Palo Alto Networks - videos will be soon published on our webpage, sign up on bit.ly/2yakige and we will let you know once they are available Security Best Practices Checklist for Palo...
How a device gets compromised - Palo Alto Networks FireWall Concepts Training Series
Просмотров 1,7 тыс.7 лет назад
In this Palo Alto Networks Training Video, we will give you an overview on the Threat Landscape and show a step by step use case on how easy it is to infiltrate an enterprise network. Security Best Practices Training for Palo Alto Networks - videos will be soon published on our webpage, sign up on bit.ly/2yakige and we will let you know once they are available Security Best Practices Checklist ...
Core Features - Palo Alto Networks FireWall Concepts Training Series
Просмотров 15 тыс.7 лет назад
In this Palo Alto Networks Training Video, we will show you the core features of the Next-Generation FireWall that make the difference. Security Best Practices Training for Palo Alto Networks - videos will be soon published on our webpage, sign up on bit.ly/2yakige and we will let you know once they are available Security Best Practices Checklist for Palo Alto Networks Next-Generation FireWalls...
Palo Alto Networks Best Practices - Migration Tool
Просмотров 18 тыс.8 лет назад
Palo Alto Networks Best Practices - Migration Tool
Palo Alto Networks Best Practices - FireWall Migration Strategy
Просмотров 9 тыс.8 лет назад
Palo Alto Networks Best Practices - FireWall Migration Strategy
Palo Alto Networks Training
Просмотров 3 тыс.10 лет назад
Palo Alto Networks Training

Комментарии

  • @akshaytirlotkar8916
    @akshaytirlotkar8916 2 года назад

    this was very insightful, helped a lot in understanding the wildfire and other security features

  • @haleviet2986
    @haleviet2986 2 года назад

    Thank you for excellent explanation video.

  • @Fmaster007
    @Fmaster007 2 года назад

    Great videos but would be greater if you can do videos on configuration on the topic. Just a thought

  • @AfonsoAlvesrefletireagir
    @AfonsoAlvesrefletireagir 2 года назад

    Great

  • @krystalrey7544
    @krystalrey7544 3 года назад

    Emergency Information

  • @scottporter4524
    @scottporter4524 3 года назад

    ^92.^68.^7.^0

  • @abdimohamed1554
    @abdimohamed1554 3 года назад

    Amazing refresher 🔥🔥🔥

  • @davec544
    @davec544 3 года назад

    Excellent video and was perfect for what I needed to get it working for my company. Thank You!!! However, I've been asked to come up with redundancy for VPN and to utilize both ISPs we have. I hope you can help guide me. if you or anyone seeing this don't mind helping? The issue I'm unsure about is at 29:50 when you take us through creating the certificate and auth profile to enable the validate IDP cert. I created the certificate to import into Azure AD using the URL of our portal/Gateway for GlobalProtect. By adding a second ISP, I assume I'll need to register a new URL to use via Azure AD Single sign-on (in addition to the original one via the configuration)? But since I created the IDP certificate using the URL for ISP1, what is the best route to be able to get it configured to work with ISP1 and ISP2? Will I be required to use DNS Failover in the cloud (using the original URL with both ISP IPs configured)? Forgive my ignorance but GlobalProtect and SAML via Microsoft is new territory for me. If you or anyone could help, it would be greatly appreciated! Thanks, Again!!

  • @lokeshg3065
    @lokeshg3065 3 года назад

    AWESOME EXPANATION

  • @darshanmc4750
    @darshanmc4750 3 года назад

    How to find out that a GP user in prelogon stage unable to proceed to connect further due to authentication issue caused by azure AD/SAML authentication? How to verify that in case when we get the troubleshooting logs

  • @joaoayres831
    @joaoayres831 3 года назад

    Perfect

  • @MohamedGamal-ti9dj
    @MohamedGamal-ti9dj 3 года назад

    Awesome Video

  • @agharajubin7027
    @agharajubin7027 3 года назад

    Thank you for doing this. Great explanation!

  • @HughJass-313
    @HughJass-313 3 года назад

    this was VERY helpful

  • @parveenjha9298
    @parveenjha9298 3 года назад

    very good explanation ,

  • @MarkROlsen86
    @MarkROlsen86 3 года назад

    Your Channel is one of the best in RUclips about Palo Alto. I really encourage you to continue to do your videos.

  • @amoljangle6443
    @amoljangle6443 4 года назад

    Very informative and useful video..Plz make such more videos.

  • @Hamish-en2vi
    @Hamish-en2vi 4 года назад

    I can't find the right words to describe your job. It was fantastic.

  • @sshivaniverma6742
    @sshivaniverma6742 4 года назад

    A small doubt, why didn't we use directly L3 interface here instead of using L2?

    • @ihsanfavy9265
      @ihsanfavy9265 Год назад

      again and again, implementation L2 as your condition environment, and why this video explain L2 because the scenario is able to explain L2, yo need watch full this video because your answer is righ there

  • @vivekprajapati7911
    @vivekprajapati7911 4 года назад

    yes pls It's is very helpful vedio,please make a vedio on packet flow of paloalto

  • @vivekprajapati7911
    @vivekprajapati7911 4 года назад

    great knowledge sir i want more ...videos in depth...

  • @bmwduran
    @bmwduran 4 года назад

    Does TAP interface on PAN deduplicates traffic? For example if there are multiple copies of same traffic reaching at the TAP port?

  • @stevenfox3214
    @stevenfox3214 4 года назад

    Thank you sir for a fantastic walk through. You saved my butt a bunch of time.

  • @henrydsouza1386
    @henrydsouza1386 4 года назад

    Can you add the script here ? share pls

    • @oomlive
      @oomlive 4 года назад

      www.consigas.com/best-practices/authenticating-globalprotect-and-prisma-access-remote-access-users-against-office365-azure-ad

  • @hangvichet26
    @hangvichet26 4 года назад

    Possible if i want to do vpn site to site on subinterface?

  • @Mac-ew1gv
    @Mac-ew1gv 4 года назад

    Thank you for taking the time out to make this video.

  • @Bormanb23
    @Bormanb23 4 года назад

    Can you just use route path monitoring and PBR, I don't see why we need a separate VR for each ISP plus a third for the LAN, it seems overly complicated but I may be wrong

  • @Hayzin
    @Hayzin 4 года назад

    Hi guys! I am facing a problem in the GlobalProtect Login page. When I try to login into GlobalProtect I can not have access to the login page, instead my Windows Login is automatic used to access the VPN. There is a configuration to show the login page every time I have to login? I have the same problem reported in this link: live.paloaltonetworks.com/t5/general-topics/globalprotect-no-longer-prompting-for-account/td-p/309392

  • @elrodjenkins
    @elrodjenkins 4 года назад

    FYI, you can add wildcards. Just edit the metadata. We have done this for Prisma Access successfully.

  • @AshfaqAhmad
    @AshfaqAhmad 4 года назад

    That's a very nice explanation of Vsys.

  • @bx1803
    @bx1803 4 года назад

    Please make more videos !!!! I love your videos!

  • @yudidjohan4160
    @yudidjohan4160 4 года назад

    Great explanation. Thanks!

  • @guille01argentina
    @guille01argentina 4 года назад

    better explained here than in PA EDU110, thanks!! just one question, can you treat the traffic going throw?

  • @Arkansmith
    @Arkansmith 5 лет назад

    Appreciate the video. Helped a lot.

  • @jaradsamraj6157
    @jaradsamraj6157 5 лет назад

    Course Cost is very expensive. any offers ?

  • @prashantrajbhandari6412
    @prashantrajbhandari6412 5 лет назад

    can this be achieved with two ISP and two PA firewall in Active/Active configuration?

  • @zemerick1
    @zemerick1 5 лет назад

    How do you handle the VLANs if the switch is the default gateway for you clients instead of the PA?

    • @supruzer
      @supruzer 5 лет назад

      Hey Zak, you would create SVIs on the switch. Not sure if that's the answer you are looking for.

  • @h4gg497
    @h4gg497 5 лет назад

    I wouldn't really say this is the a particularly good use case for PBF. You could have just enabled ECMP on the VR then tweaked the ECMP load-balancing algorithms. Also it's asymmetric routing not "asynchronous". Why bother with different VRs for each ISP, just use a single egress interface (in a port-channel).

    • @salmannasheet3584
      @salmannasheet3584 4 года назад

      Would ECMP help with static default routes ? can we have 2 default route( in same VR) with same AD/Metric ? , if not ECMP won't work?

  • @w1jumpmaster
    @w1jumpmaster 5 лет назад

    So if the Production and Pre-Production are in the same IP subnet, the Managements are different, If I tried to connect to something across the IVRL, then it would be the same IP ? If you are going to have IVRL, then you need different subnets all the way around

    • @kevindall5268
      @kevindall5268 4 года назад

      Steve Holloway - No. The management subnets are only connected at the VR. The production L3 interface is not known by the PreProd VR and will therefore only route to the interface for the production environment because that is what the production VR knows that subnet to live. Does that make sense?

  • @tripleceas
    @tripleceas 5 лет назад

    You lost me at rooter.

  • @Treiyou
    @Treiyou 5 лет назад

    This did not clear it up for me, when would you not be able to use a layer 3 firewall?

    • @chuckbaker9196
      @chuckbaker9196 5 лет назад

      A use case I have found once is to plug in a secondary or tertiary internet connection using a virtual wire to let it traverse the firewall and not change the IP space the ISP provided to us. It allowed us to still monitor and controller where people can go without allowing it to touch our corporate network. It was used to emulate in our business a user at home and kept the testing/connection, as I said, from touching any of our corporate networks. this would be a one off type deployment model.

  • @SwitchTechJob
    @SwitchTechJob 5 лет назад

    Hi sir, can you please share in theory about the PA . i Need to check it out

  • @overtheedge107
    @overtheedge107 5 лет назад

    Thanks for short and simple explanation!

  • @peternorton7665
    @peternorton7665 5 лет назад

    What a bad idea!

  • @sureshsinha8124
    @sureshsinha8124 5 лет назад

    Excellent.Thank you

  • @shakeelm5339
    @shakeelm5339 5 лет назад

    YOU NEED TO LEARN HOW TO WRITE "1" - YOU WRITE "1" AS INVERTED "V" - AND YOU CALL YOURSELF AS "NETWORK EXPERT"

  • @sagibar-or6337
    @sagibar-or6337 6 лет назад

    Very clear and informative, but I am missing linkage to Palo Alto Config UI. The PA UI has "VLANs" menu item, vs "vlans" tab in the interface menu. This does not corresponds to L2 vs L3 vlan.

  • @maltekaule9330
    @maltekaule9330 6 лет назад

    Awesome explanation, easy to understand!

  • @voittb4954
    @voittb4954 6 лет назад

    Very good content, it's clear and well explained. However it would have been nice to include GUI view and quick config exemple.

  • @oneilmatlock8321
    @oneilmatlock8321 6 лет назад

    For Production and Pre-Production L3 interfaces, could they be the same IP address? Want to keep server VMs the same IP address and default gateway when moving in and out of the two environments.

    • @kevindall5268
      @kevindall5268 4 года назад

      Oneil Matlock Yes. IP address assigned to the interface can be the same IP. The interface itself will have to be different. Does that make sense?