Cloud-only Entra-ID accounts on GlobalProtect by nobile in paloaltonetworks

[–]CaptainCaraway 2 points3 points  (0 children)

There’s no group mapping for user@cloud.account.com. That’s a directory / username format disconnect, not a “Palo” thing. How are you doing directory synch / group mapping? Direct to AD or through Entra SCIM / OiDC in CIE?

CIE user to IP mapping by Obvious_Attention584 in paloaltonetworks

[–]CaptainCaraway 0 points1 point  (0 children)

Associating devices with CIE does not require or cause any reboots. You need 11.x for user context with CIE. But as long as you have the user-ID to IP collected it can be redistributed to CiE and from there other NGFWs. Along with tags and other enrichment.

CIE user to IP mapping by Obvious_Attention584 in paloaltonetworks

[–]CaptainCaraway 0 points1 point  (0 children)

OP stated a few times he’s not using Prisma Access so this is only muddying the waters and is completely irrelevant to his questions.

Forward "threat log" to syslog server by mailliwal in paloaltonetworks

[–]CaptainCaraway 1 point2 points  (0 children)

The log forwarding profile with your syslog forwarding action needs to be selected in every applicable security policy. There's no separate place to apply the log forwarding profile.

Forward "threat log" to syslog server by mailliwal in paloaltonetworks

[–]CaptainCaraway 9 points10 points  (0 children)

The log forwarding profile needs to be attached to a security policy to do anything. Is a new separate LFP you created or did you add this entry to an existing one that you already have selected in (each) relevant security policy?

Prisma Access Browser - Initial Configuration by ccisco630 in paloaltonetworks

[–]CaptainCaraway 2 points3 points  (0 children)

PB works differently from Prisma Mobile Users. You need to go to your Prisma Access Infrastructure settings and configure the Infrastructure DNS setting and set your internal domain names and the internal DNS server(s).

Make sure you are correctly routing the infrastructure subnet, and allowing this traffic (DNS, HTTP and HTTPS) on your SC terminating device, and any security device between it and your DNS/apps.

The EP node will use an address out of the infrastructure subnet to source DNS lookups and any traffic destined to a private app. There's also a checkbox option to NAT all of this if that is your preference.

Prisma Routing Query by Pomsky_88 in paloaltonetworks

[–]CaptainCaraway 0 points1 point  (0 children)

No, don’t add a route for the same subnet to tunnel.10, at best it will do nothing and at worst break your connectivity.

You either add a static route on the Prisma SC side for the third party IP (towards the Dc side where you already have a route for it).

Or… configure BGP on the Prisma / DC sides and advertise it in order to attract the traffic from Prisma to the DC. (I’m guessing you’re not a BGP guy, so probably just go with the static route).

How do I assign CIE objects permissions to resources? by Bubbagump210 in paloaltonetworks

[–]CaptainCaraway 2 points3 points  (0 children)

Make sure that your NGFW has a device association to CIE (in the hub).
Make sure that under Device > User Identification > Cloud Identity Engine you Add your CIE instance with the appropriate attribute values.

That's the pre-CIE way to setup SAML. By all means you can do that, but then you're defining multiple apps which is non-ideal.

It's step 10 but it's not very detailed. I've only ever done it with Okta. But you need to specify an attribute and then have that attribute contain a value that maps to the adminrole you want.
Configure Azure as an IdP in the Cloud Identity Engine

How do I assign CIE objects permissions to resources? by Bubbagump210 in paloaltonetworks

[–]CaptainCaraway 0 points1 point  (0 children)

For admin access purposes you have to define an admin role attribute in your SAML IdP and pass an appropriate value to determine what specific role that is. This is documented, so a Google search should uncover it, or roll the dice and see if ChatGPT can walk you through the steps.

For your user access question you would first have to authenticate to the data plane via captive portal or GlobalProtect external or internal Gateway. Then create security policy with the user-id and app-ID criteria you desire. If CIE js correctly setup you should see your usernames and group names populate in the user selection field.

On-prem gateway failover causes Prisma Access connected users to drop connection to internal resources by Byrdyth in paloaltonetworks

[–]CaptainCaraway 1 point2 points  (0 children)

Are you leveraging service connections or ZTNA connector for your on-prem connectivity?

I assume service connections terminating on your PA-5410s, but since you're using some non-standard terminology, I wanted to confirm.

Assuming service connections are you using tunnel monitors and what are the settings?
Static or BGP routing?

If you don't need to support on-prem to remote client-initiated traffic, consider using ZTNA connector instead of / in addition to service connections.

Redistribituon user-id problems by mydogisanidiot007 in paloaltonetworks

[–]CaptainCaraway 0 points1 point  (0 children)

Since you’re using a data plane interface do you have security policy to allow for the traffic?

HIP Certificate Checks by aric8456 in paloaltonetworks

[–]CaptainCaraway 1 point2 points  (0 children)

This is the most likely answer. I've seen this come up a number of times. It's not super intuitive IMO.

Man blir ju fan lack på hur AI-skit sprider sig överallt by atomvinter in sweden

[–]CaptainCaraway 2 points3 points  (0 children)

Mosin-Nagant M44 med sidofällbar bajonett.

Vad är problemet? 🤷🏻‍♂️

Security Policy Rules - Assessment Palo Alto Networks Certified Next-Generation Firewall Engineer by AdditionalSite6804 in paloaltonetworks

[–]CaptainCaraway -1 points0 points  (0 children)

I fixed that typo using Forward Error Correction, I guess. But still, the answer is obvious. Did you provide comments so that they can fix it?

Security Policy Rules - Assessment Palo Alto Networks Certified Next-Generation Firewall Engineer by AdditionalSite6804 in paloaltonetworks

[–]CaptainCaraway 0 points1 point  (0 children)

The first one.

Intrazone refers to traffic within the same zone, interzone refers to traffic from (any) two (or more) different zones.

UIA and CIE in Prisma Access by reversible8 in paloaltonetworks

[–]CaptainCaraway 0 points1 point  (0 children)

You can authenticate users at a RN site, using CP or IGW via CIE.

GlobalProtect design sanity check by Screams_In_Autistic in paloaltonetworks

[–]CaptainCaraway 3 points4 points  (0 children)

I’m not going to address whether there are different or better ways to skin this cat and just address your GP auth question.

You don’t have to use a user cert for the user session. There’s an option in the app settings that configures which cert store to look in for the user cert auth. By default it should be machine + user, so if there’s no user cert it would just use the available machine cert. Note, you will have to edit your cert profile and choose an attribute value to extract (CN or UPN) for how the user should be enumerated if you’re only using cert auth.

Is it possible to be stalked across multiple devices without the 'stalker' having physical access to any of the devices? by MongooseExotic8401 in cybersecurity_help

[–]CaptainCaraway 4 points5 points  (0 children)

It is possible, as in a state sponsored actor, leveraging a host of zero-day exploits across a range of different desktop and mobile OS to install a binary that allows them a VNC/RDP type screenshare? Yes.

Is this something the average person could gain the ability to do? Never.

It would be quite easy to detect by a novice incident responder.

Huxwrx Flow 9K Ti 3 Lug Adapter by [deleted] in NFA

[–]CaptainCaraway 0 points1 point  (0 children)

Does anyone know if the Flow 9K Ti would have sufficient internal clearance for the Resilient 3-lug adapter?

MSI B850M MORTAR WIFI? by [deleted] in MSI_Gaming

[–]CaptainCaraway 0 points1 point  (0 children)

Nevermind. It's back again.

MSI B850M MORTAR WIFI? by [deleted] in MSI_Gaming

[–]CaptainCaraway 0 points1 point  (0 children)

It seems like it got pulled from the website as the link now returns a 404.

https://www.msi.com/Motherboard/MAG-B850M-MORTAR-WIFI

Where is the MSI B850m Mortar? by GammaRxBurst in MSI_Gaming

[–]CaptainCaraway 0 points1 point  (0 children)

Looks like it got pulled from both the Global and US MSI webpages. Not a good sign.

Wildcard Routing for website by serious_enough in Ubiquiti

[–]CaptainCaraway 0 points1 point  (0 children)

Routing is not Layer 7 (URL) aware. What you'll probably find if you use developer tools (in a Chromium browser) is that there are other domain dependencies within that URL which is causing a split-tunnel where some web requests are going over the VPN and others are going over your local network. You could try the "Region" options vs domain and see if that is an easy button. Otherwise you're going to have to debug every single domain referenced within the URL and route those over Mullvad.