Skip to content

How to measure configuration quality?

Organizations may invest in best-of-breed solutions, but if these are poorly configured, they won’t reap the benefits. I’ve seen many instances like this in both public and private entities. Sometimes configuration errors are obvious—such as widely open firewall rules or a network access control system that assigns the same VLAN to all hosts (yes, I’ve seen it!). These mistakes are easy to identify and address. But what about systems with numerous features and capabilities?

Some vendors offer tools to assess configuration quality. Palo Alto Networks, for example, provides the Best Practice Assessment Report (BPA), which evaluates firewall configuration quality.

Best Practice Assessment (BPA)

To generate a BPA report, you first need to export a Tech Support file from the firewall.

Initially, these reports were generated through the Support Portal; however, they’re now available through the AIOps application (even in the free version).

More information on accessing the BPA report can be found here: Palo Alto Networks BPA Documentation

What Does the BPA Report Provide? Security Profiles: By default, security profiles aren’t configured according to best practices. The BPA report highlights how these profiles are applied to security policies and whether they align with best practices

From the summary screen, you can drill down into specific security policies to identify where profiles are missing.

Other checks are about security, identity, network and services

Security policies should be specific. For instance, in some cases, the “any” setting is allowed under applications, policy descriptions are missing, and session start logging is configured (which should be enabled only for troubleshooting).

Some configurations may enable log forwarding but overlook critical log types, such as WildFire logs—important from a security perspective.

Features like the automatic commit lock are recommended to prevent accidental configuration changes by other admins.

These are just a few examples; there are many more checks that the BPA performs.

With the paid version of AIOps, configurations that don’t align with best practices can even be restricted. In Panorama, it’s possible to prevent the configuration of new policies that aren’t compliant.

More on Panorama’s BPA plugin can be found here: BPA Plugin for Panorama

In Summary, a deployed system is only as effective as its configuration. Palo Alto’s NGFWs are highly capable devices, packed with a lot of features. By using the BPA, you can assess the quality of your firewall configuration, make necessary changes, and ultimately reduce your attack surface.

Join the conversation

Your email address will not be published. Required fields are marked *