What's Popular

Meh, Whatever is Featured

Linking Active Directory to Palo Alto

 ###First you need to create a server profile under the LDAP section. DEVICE>Server Profiles>LDAP then click on the Add down at the bo...

Showing posts with label Firewall. Show all posts
Showing posts with label Firewall. Show all posts

Friday, October 7, 2022

Open Port on Linux Firewalld

 1. First you need to add the rule:

a. user@test>firewalld-cmd --add-port=YOUR_PORT_#/udp-or-tcp --permanent


2. Restart the firewall:

a. user@test>firewall-cmd --reload


3. Check the firewall list:

a. user@test>firewall-cmd --list-all

Thursday, November 1, 2018

Linux Firewall Tips

•    Disable the firewall:
    o    >systemctl disable firewalld
•    Install the iptables-service:
    o    >yum install iptables-services
•    Enable iptables
    o    >systemctl enable iptables
    o    Now you can save iptables:
            >service iptables save
•    To stop the firewall:
    o    >systemctl stop firewalld
•    Check status of the firewall:
    o    >systemctl status firewalld
•    To start the firewall:
    o    >systemctl firewall start
•    To enable the firewall:
    o    >systemctl enable firewall

Friday, October 26, 2018

Cisco ASA 5515 VPN Tips

•    This shows the sessions currently on the system
    o    #show vpn-sessiondb
•    If you have static/standing connections on the system, you can use this command to force logoff all the sessions.
    o    #vpn-sessiondb logoff all
•    Show specific sessions running on the system:
    o    #show run telnet
    o    #show run http
    o    #show run ssh
•    Show user accounts listed on the ASA system
    o    #show run user
•    Show the SSH information configured in the system
    o    #show running-config ssh

Thursday, October 25, 2018

Adding Users to ASA for VPN Access

1.    Open the Cisco ASDM client.
2.    From the ASDM Home screen, click on the “Configuration” tab up in the top left corner.



3.    From here, click on “Remote Access VPN” tab.


4.    From this tab, navigate to “AAA/Local Users>Local Users”.

5.    Click on the “Add” button on the right side of the ASDM.


6.    For Engineers, you can give “Full Access(ASDM, SSH, Telnet, Console)” and then assign privilege levels accordingly. For basic user VPN access, click on the “No ASDM, SSH, Telnet or Console access” circle.

7.    Once you have the profile done, click on the VPN Policy tab. This tab will allow you to give them the VPN access policy. Once in the VPN Policy tab, uncheck the checkbox next to “Group Policy, Inherit”, and then select “VPN-Test” on the drop down. This is all you need to do here for the profile.

8.    You can now see your newly created profile in the “Local Users” section in the ASA. Now you just need to click “Apply”. This sends the commands to the ASA that creates this profile and settings.

 9.    A good rule of thumb I noticed is to navigate to a different tab on the left to ensure the Apply greys out. This will ensure it has been saved and is in the ASA configs.

Thursday, October 4, 2018

Palo Alto Graceful Shutdown

Via GUI:

•    Click on Device tab > Setup link > Operations tab
•    Click on shutdown device under device operations on the right hand side
•    Click Yes on the confirmation pop-up
•    Wait a few minutes for the process to complete.

Via CLI

•    Issue the command: “request shutdown system”
    o    >request shutdown system
    o    Warning: executing this command will leave the system in a shutdown state. Power must be removed and reapplied for the system to restart. Do you want to continue? (y or n) y
•    Wait until “System Halted” is displayed on the console.