- 35
- 291 993
NETSums
Germany
เข้าร่วมเมื่อ 16 ก.ย. 2022
Welcome! This channel is focused on creating tutorials and walkthroughs for Network Professionals. I hope I will be able to help you configure and manage your Palo Alto Firewalls and boost your networking career!
- ABOUT -
Ricardo has been a network professional for over 20 years. For the last 7 years he has been daily working with the Palo Alto Firewalls. He comes originally from Brazil, and has been living in Germany since 2004.
- ABOUT -
Ricardo has been a network professional for over 20 years. For the last 7 years he has been daily working with the Palo Alto Firewalls. He comes originally from Brazil, and has been living in Germany since 2004.
Palo Alto GlobalProtect - Must-Know Portal Settings & Tips [2024]
In this video I walk you through the most useful GlobalProtect settings and how they impact your VPN users. I'll show you exactly what remote users experience after these settings are adjusted.
In this video we focus on the settings found in the GlobalProtect Portal configuration, specifically within the App tab of the Agent.
🌐 Useful Links
- GlobalProtect with Pre-Logon: th-cam.com/video/k2Y2L8wiMdI/w-d-xo.html
- GlobalProtect Tutorial for Beginners: th-cam.com/video/jonUROUSn-U/w-d-xo.html
- NETSums Resources: netsums.com/resources
👍 Like, Share, and Subscribe for More:
If you find this tutorial helpful, don't forget to give it a thumbs up, share it with your colleagues, and subscribe to our channel for more in-depth tutorials on network security and technology best practices.
🔗 Connect with Us:
If you have questions, suggestions, or any kind of feedback, please don't hesitate to comment below! We will reply as soon as possible.
#PaloAlto #NetworkSecurity #Tutorial #itsecurity #IdentityManagement #paloaltofirewall #paloaltonetworks #firewall #globalprotect
Timeline
00:00 Must-Know GP Portal Settings & Tips
1:12 Connect Method
3:54 Allow user to disconnect GP
13:48 Allow user to uninstall GP
15:25 Allow user to upgrade GP
21:17 Allow user to extend GP session
22:33 Use default browser for SAML
23:44 Client certificate store lookup
24:11 Allow user to change portal address
24:38 Pre-logon tunnel rename timeout
25:18 GP connection MTU
25:39 Display SSL fallback notification
27:29 Enable advanced internal host detection
In this video we focus on the settings found in the GlobalProtect Portal configuration, specifically within the App tab of the Agent.
🌐 Useful Links
- GlobalProtect with Pre-Logon: th-cam.com/video/k2Y2L8wiMdI/w-d-xo.html
- GlobalProtect Tutorial for Beginners: th-cam.com/video/jonUROUSn-U/w-d-xo.html
- NETSums Resources: netsums.com/resources
👍 Like, Share, and Subscribe for More:
If you find this tutorial helpful, don't forget to give it a thumbs up, share it with your colleagues, and subscribe to our channel for more in-depth tutorials on network security and technology best practices.
🔗 Connect with Us:
If you have questions, suggestions, or any kind of feedback, please don't hesitate to comment below! We will reply as soon as possible.
#PaloAlto #NetworkSecurity #Tutorial #itsecurity #IdentityManagement #paloaltofirewall #paloaltonetworks #firewall #globalprotect
Timeline
00:00 Must-Know GP Portal Settings & Tips
1:12 Connect Method
3:54 Allow user to disconnect GP
13:48 Allow user to uninstall GP
15:25 Allow user to upgrade GP
21:17 Allow user to extend GP session
22:33 Use default browser for SAML
23:44 Client certificate store lookup
24:11 Allow user to change portal address
24:38 Pre-logon tunnel rename timeout
25:18 GP connection MTU
25:39 Display SSL fallback notification
27:29 Enable advanced internal host detection
มุมมอง: 2 284
วีดีโอ
Reset Palo Alto Firewall to Factory Default [2024]
มุมมอง 1.4K6 หลายเดือนก่อน
In this video you'll learn how to reset a Palo Alto Firewall to factory default. In order to access the CLI, we will be connecting to the firewall using SSH. 🌐 Useful Links - Palo Alto Training (preparation for PCNSA): netsums.com/training - NETSums Resources: netsums.com/resources 👍 Like, Share, and Subscribe for More: If you find this tutorial helpful, don't forget to give it a thumbs up, sha...
Palo Alto Policy-based Site to Site VPN with NAT [2024]
มุมมอง 3K7 หลายเดือนก่อน
In this video we'll configure together a Policy-Based Site to Site VPN with Network Address Translation (NAT) on the Palo Alto Networks firewalls. As a disclaimer, I personally prefer configuring route-based instead of policy-based VPN, if I have the choice. Sometimes, though, it's just technically not possible, there are times that your partner's device on the other side of the tunnel doesn't ...
Palo Alto - Temporarily Block Attackers [2024]
มุมมอง 2.8K8 หลายเดือนก่อน
🔒 In this video I'll show you one neat configuration on the Palo Alto Firewall to stop or slow down internet attackers, in order to keep your public servers safe. This is a rather straightforward configuration to setup, but for some reason, I haven't seen it being implemented very often! 🛡 We will use Panorama to push the configuration to our perimeter firewall. For this configuration, you'll n...
Palo Alto SSL Inbound Inspection with Let's Encrypt Certificate [2024]
มุมมอง 2.4K9 หลายเดือนก่อน
🚀 Welcome to this video where we dive deep into the world of Palo Alto SSL Inbound Inspection using Let's Encrypt certificates! 🚀 In this tutorial, we'll guide you through the step-by-step process of setting up SSL Inbound Inspection on Palo Alto Networks firewall with the added security and convenience of Let's Encrypt certificates. 🛡️🔐 SSL/TLS Inbound Inspection typically operates from the I...
GlobalProtect Internal Gateway with SAML/OKTA [2024]
มุมมอง 3.8K10 หลายเดือนก่อน
🚀 Welcome to our comprehensive TH-cam tutorial on setting up Palo Alto Internal Gateway with SAML authentication and seamless integration with Okta! In this step-by-step guide, we'll walk you through the entire process, from configuring Palo Alto to establishing a secure Single Sign-On (SSO) experience using Okta's powerful identity management platform. 🔒 Secure Access with Palo Alto Internal G...
GlobalProtect Gateway Selection (Multi-Gateway Configuration) [2024]
มุมมอง 3.3K10 หลายเดือนก่อน
In this video I'll show you how to configure multiple external GlobalProtect Gateways and also go over the parameters that the GlobalProtect App (Client) takes into consideration when selecting the best gateway. 💻 Palo Alto Online Training 🔥 Join our exclusive online training: "Mastering Palo Alto Firewalls: Comprehensive Training in Operation and Management." 🚀 Prepare confidently for the PCNS...
Palo Alto GlobalProtect Clientless VPN [2024]
มุมมอง 5K11 หลายเดือนก่อน
In this video I'm going to show how to configure the feature Clientless VPN of the Palo Alto Firewall. 💻 Palo Alto Online Training 🔥 Join our exclusive online training: "Mastering Palo Alto Firewalls: Comprehensive Training in Operation and Management." 🚀 Prepare confidently for the PCNSA exam with expert guidance and hands-on exercises. Reserve your spot now and benefit from Early Bird discoun...
Step-by-Step Palo Alto Windows User-ID Agent Setup Guide [2024]
มุมมอง 16Kปีที่แล้ว
🔒 Unlock the Power of Palo Alto: Configuring Windows User-ID Agent Tutorial! 🔒 In this tutorial, we'll walk you through the entire setup process, demystifying the complexities and ensuring you harness the full potential of this robust security solution. 💡 🔧 Key Highlights: ✅ Seamless Integration: Learn how to seamlessly integrate the Windows User-ID Agent into your Palo Alto infrastructure, ens...
Adding a Palo Alto Firewall to Panorama
มุมมอง 9Kปีที่แล้ว
In this video I'll show you how to add a new Palo Alto Firewall to your Panorama. 💻 Palo Alto Online Training 🔥 Join our exclusive online training: "Mastering Palo Alto Firewalls: Comprehensive Training in Operation and Management." 🚀 Prepare confidently for the PCNSA exam with expert guidance and hands-on exercises. Reserve your spot now and benefit from Early Bird discounts and bonusses! 💻 Le...
Palo Alto URL Filtering and URL Categories
มุมมอง 6Kปีที่แล้ว
In this video we'll show you how to configure the URL Filtering feature of the Palo Alto Firewall. URL filtering technology protects users from web-based threats by providing granular control over user access and interaction with content on the Internet. We're going to block access to the URL category social-networking, but make an exception for some URLs in this group. Furthermore, we're going...
Palo Alto GlobalProtect VPN Configuration [2024 IMPROVED!!!]
มุมมอง 25Kปีที่แล้ว
In this tutorial you're going to learn how to configure remote access VPN on the Palo Alto Firewall. Palo Alto has its own VPN client, called GlobalProtect. In the video I will show you how to authenticate a remote user using Microsoft Active Directory. This video is an improved version of an older GlobalProtect tutorial I made in the beginning of 2023 (th-cam.com/video/Dj-rjuX9I_E/w-d-xo.html)...
Palo Alto NAT Configuration [2024]
มุมมอง 1.5Kปีที่แล้ว
In this video I'll help you to configure Network Address Translation (NAT) on your Palo Alto Firewall. #paloaltofirewall #firewall #networking Please subscribe to the channel if you found this video useful. It does help us a lot. Thank you! Link to FREE CLI Cheat Sheet and other resources netsums.com/resources
Panorama GROUP MAPPING - How to show AD groups in Panorama policies
มุมมอง 3.2Kปีที่แล้ว
In this video I will show you how to automatically synchronize your Active Directory groups to Palo Alto Panorama Policies. Whenever you create new policies, such as security rules, you will be able to select the AD groups in the field Source User instead of having to type or paste their Distinguished Names. #paloaltonetworks #paloaltofirewall #firewall #panorama Link to FREE CLI Cheat Sheet an...
Config Backup from Palo Alto using Linux [in 10 minutes]
มุมมอง 1.4Kปีที่แล้ว
In this video I'm going to show you how backup the configuration from your Palo Alto Firewall to a Linux server. For that we're going to use a Python tool called pan-python, that will connect to the firewall and download its configuration. Pan-python is a multi-tool set for Palo Alto Network PAN-OS, Panorama, WildFire and Autofocus.
Azure Authentication for Panorama Admins WITH GROUP MAPPING!!!
มุมมอง 4Kปีที่แล้ว
Azure Authentication for Panorama Admins WITH GROUP MAPPING!!!
Palo Alto Firewall - Static Routes [2024]
มุมมอง 1.1Kปีที่แล้ว
Palo Alto Firewall - Static Routes [2024]
Palo Alto GlobalProtect with multiple AD groups [2024]
มุมมอง 6Kปีที่แล้ว
Palo Alto GlobalProtect with multiple AD groups [2024]
Palo Alto Panorama Template Variables [2024]
มุมมอง 887ปีที่แล้ว
Palo Alto Panorama Template Variables [2024]
Palo Alto Firewall - Packet Capture [2024]
มุมมอง 6Kปีที่แล้ว
Palo Alto Firewall - Packet Capture [2024]
Palo Alto SSL Forward Proxy (Outbound SSL Decryption) [2024]
มุมมอง 7Kปีที่แล้ว
Palo Alto SSL Forward Proxy (Outbound SSL Decryption) [2024]
Palo Alto Feeds - Built-in External Dynamic Lists (EDL) [2024]
มุมมอง 2.6Kปีที่แล้ว
Palo Alto Feeds - Built-in External Dynamic Lists (EDL) [2024]
Palo Alto VPN - Site to Site step by step configuration [2024]
มุมมอง 16Kปีที่แล้ว
Palo Alto VPN - Site to Site step by step configuration [2024]
When to use Pre and Post Security Rules in Panorama
มุมมอง 7Kปีที่แล้ว
When to use Pre and Post Security Rules in Panorama
Palo Alto Login - Two Factor Authentication [2024]
มุมมอง 17Kปีที่แล้ว
Palo Alto Login - Two Factor Authentication [2024]
Palo Alto GlobalProtect with Pre-Logon [2024]
มุมมอง 17Kปีที่แล้ว
Palo Alto GlobalProtect with Pre-Logon [2024]
Palo Alto GlobalProtect SAML Single Sign-On with Azure [in 8 minutes]
มุมมอง 23K2 ปีที่แล้ว
Palo Alto GlobalProtect SAML Single Sign-On with Azure [in 8 minutes]
Palo Alto GlobalProtect VPN Configuration Step by Step [2024]
มุมมอง 72K2 ปีที่แล้ว
Palo Alto GlobalProtect VPN Configuration Step by Step [2024]
Palo Alto Firewall - Traffic Log [2023]
มุมมอง 10K2 ปีที่แล้ว
Palo Alto Firewall - Traffic Log [2023]
There are no new uploaded videos these days How are you? I have one more request Please make a video on how to configure and set up Paloalto multicast
I have a virtual machine on Azure running Windows 10, where I installed the Palo Alto GlobalProtect VPN client. However, when I try to connect, I get the following error: "Matching client configuration not found." Interestingly, the VPN client works fine when I connect using another device, like my laptop.
Great and thanks
Hello Teacher when i will do login show this error "Failed to get client configuration"
Hi. It could mean that your client is not matching any of your agents in the portal or gateway configuration (check your user groups), or any of your authentication profiles (check there also the AD groups you're using).
Sorry I asking something, in my company right now has PoC about Prisma Access via Panorama. But We get some issues because Service Connection is always Error. After I checked, the Tunnel is down. So whats the type of tunnel should I use for thats case?
So the only different between route based firewall and policy based firewall is you add a Proxy ID ?
There are some technical differences (in policy based, usually several SAs are negotiated, and in route based only one), but regarding the Palo Alto configuration, yes, that's the only difference.
Nice vidio
Thank you, I'm glad you liked it.
I have something similar but i'm sending the Access Domain and Admin Roles via the SAML assertion, but I can't get this to work without manually creating a Administrator account for each User. Thoughts?
Thank you great content! If you use the default management interface for communications then no need for rules to allow communications between windows user ID agent server and Palo firewall right?
Thank you for your feedback. That's correct, if you use the management interface, you only need to activate User ID in the management profile. But if the traffic leaving the management interface goes through a firewall (as in my case), this firewall obviously needs to allow the communication.
Can you please make a video for Global Protect HIP
I have actually been thinking about it for a while. But thank you for your suggestion! 😊
Can you please make a video for configuring Azure SAML group mapping with Palo Alto GlobalProtect , to allocate separate vpn pool and destination access based on these groups
I have had the right address when I meet you here. Many thanks
You're welcome, thank you also for the comment!
Would be useful to have link for all pre-requisites etc.
You're right. I'll take a look at it soon. Thank you!
FYI: For those who is trying to install in Ubuntu 24.04, it's not yet possible to do it, because there are no packages for this version (as of 22.11.2024)
Hi, thank you for the update! :-)
Question Richaro, I have version 10.1.6-h8, can I update to version 11.1.5-h1 or I have to update with in-line version like 10.1.6-h9 for example? Per security bulletin (CVE-2024-9474), they recommened PA440 to be on version 10.1.14-h6 or later. Some says that 11.1.5-h1 may not be compatibled or support on PA440 and PA220 or it's better to wait for 10.1.6-h9 to release.
Hi. You can go directly to 11.1., no problem. I have PA-440 running 11.2, I have no problem with it. The PA-220 became very slow from version 9 to 10 to administer (commits take forever). I would keep that in mind before going to 11.1.
Great work !!
Thank you!
you are a savior!
I'm glad we could help! :-)
Do we need a license for registering the virtual firewalls? is there a grace period? I'm looking for a way to use firewalls and Panorama for a home lab. I appreciate it if you could make a video about it.
When you buy a license for a virtual firewall with credits, you should also be able to check a box for a free Panorama license. This shouldn't cost any additional credits.
@@netsums So, does it mean I don't need a separate license for Panorama?
I'm not 100% sure, but I think you need a license, which is free whenever you buy a Palo Alto VM Firewall.
@@netsums Thank you
Hmmm, interesting. But: why we config in split and in policy We can config one GP Clinet for users and allow access into Policy. And in Monitor we can't see another Server, because we add into SPLIT tunnel just one IP.
it is a great Video with clear explain! Thank you please more Video with Another Topics!
Thank you, I'm glad you liked it. :-)
I just found you on Internet. This video is amazing!. Your didactic is superb!
Ricardo! Eu sabia que seu sotaque em Ingles era do Brasil! Muito bom canal! Estou comecando com Palo-Alto e seus videos ajudarao muito. Abracos aqui do Canada em 2024!
Hahaha. Pois é, o sotaque me entrega. :-) grande abraço, fico feliz que os vídeos podem te ajudar!
Do you have instruction for GlobalProtect pre-logon with SSO using SMAL from Azure? thanks a lot for sharing
Just followed the steps and it works like a charm on my VM series FW. Thanks
Cool! I'm glad we could help. :-)
many thanks for showing the "merge" feature of wireshark which I haven't known before. Excellent!
Vos vidéos sont excellentes, faciles à comprendre et la production est très bonne. Félicitations!
Merci ! 😊
Very good and thank you.
Thank you also for the comment
Good, thank you.
Do you have a guide or flowchart to setup rules and policies? We're about to redo all our rule and policies and its somewhat of a daunting task. Thanks sir for your great channel!
Hi. Do you please know, why login shows this one message? Error Displaying SAML error response page
I would guess your URLs at the IdP are not set correctly. Please check them once again.
In pre-check once you download the software, you are also supposed to check/perform dynamic updates to the latest. Then go for install the software
Excellent guide for deploying Prelogon. I am testing this in our environment but noticing after reboot the prelogon doesnt connect..Only If user logs out I can see prelogon logs in the firewall. Can you please advise what I am missing?
congrats and it's well deserved, love your content. wish you all the support, all the way back from Senegal !
Thank you so much!
That's a perfect video! I really hope I can do it so well like you.
Thank you for the comment, I'm glad you liked the video. 😊
Hi - thank you for the script! Can we export text based results of the operational commands instead of xml or json ?
Thank you for the comment. I don't think it's possible to export it in different formats
Your videos are awesome Ricardo! Keep up the great work my friend. Is there anyway that we can give back to you for all of your hard work of putting out these informative and educational videos?
Hi, thank you for your comment and being open to help, it means a lot! :-) Sorry for taking so long to reply. We're planning on making available what we call a "GlobalProtect easy configurator", which will provide the users an initial but functioning GlobalProtect configuration, after filling out a couple form fields (instead of the full blown Palo Alto firewall configuration, which can be overwhelming). If you would like to be a beta tester, please send me a message over netsums.com. Thank you again!
please create video to configure laptop in auto pilot mode
very nice video , no one can explain in such way
Thank you so much 😀
thank you very much this is very helpful for beginners
Thank you for the comment, I'm glad it was helpful!
Hello is this necessarily authorized to use ssl descryption in the network if yes what are the advantages and disadvantages.thx
I'm not sure I understand your question. In some countries there are some connections that are not allowed to be decrypted. Each company has its own policies. The advantage of SSL decryption is that the firewall gains more visibility on the traffic.
Thank you for the very informative videos but if you can put the commands with more description would be very helpful. i.e. panxapi.py -t 'pavm' -h 'pa-3200-01' -l admin[:password] -k >> ~/.panrc pavm- Do we have to create the file before this command? pa-3200-01- is this the hostname of the Palo Alto firewall? Can I put the host IP address instead?
Very nice job.
Thank you!
Allow Transparently wont upgrade your global protect app if there is more then one version in between. Like 6.3.0 to 6.3.1. It will notify you about upgrade procedure, but never start upgrading.
You are amazing. Funny to think nobody in this world has provided updated videos on how to do things with Palo Alto.
Thank you for the comment, I'm glad you like the videos!
I got it to workonce but it would never reprompt the user with MFA. I did configure the logout SAML URL but still no luck. The user logged in without using MFA.
Create some video on dynamic group
Fantastic tutorial and video, it outperforms the PAN docs pages ❤
I have a question: Does this apply to macOS for transferring the certificate file? Another question: Do we need to configure something when using TLS 1.2? I am having issues connecting to GlobalProtect with the error: "The network connection is unreachable or the gateway is unreachable. Thanks everyone for your next help.
Jones Sharon Davis Daniel Young George
Good Video...
Great video!! Keep going I have multiple firewalls managed by panorama, where should I apply SAML? on firewalls or panorama or both?
Hi, thank you for the comment and sorry for the late reply. If you want to apply SAML for firewalls or Panorama, why not apply for both? :-)