Skip to content

paloaltonetworks

Strata Cloud Manager

Panorama is a well-known tool for managing Palo Alto Networks firewalls and providing central log storage. It has been available for as long as the NGFW firewalls themselves. I work with it frequently. Like any product, it is not perfect. I have encountered several specific drawbacks. Panorama management logic is based on Device Groups for… Read More »Strata Cloud Manager

DNS Tunneling again…

Some time ago, I did some tests related to DNS tunneling identification. What was wrong with that scenario was that the test was not based on a real-life setup. DNS tunneling happened only inside the infrastructure (LAN environment), without any connection to the Internet or external DNS servers. Such a scenario can influence how vendors… Read More »DNS Tunneling again…

PAN-OS 12 – What’s New

Every vendor keeps evolving their products, and from time to time they release a “new revolutionary version.” Marketing always claims it’s a game changer in the industry 🙂 Palo Alto Networks just released PAN-OS 12.1.x (after 12.0.x). Marketing says it’s innovative software with quantum protection and other fancy words. Let’s skip the hype and look… Read More »PAN-OS 12 – What’s New

PANW best practices from Day 0

In my blog, I’ve often mentioned that Palo Alto Networks (PANW) firewalls are feature-rich, offering a wide range of configurations across multiple areas. There are many steps involved in setting up a firewall according to best practices. Unfortunately, I often see subpar configuration quality. In a previous blog post, I discussed how to measure the… Read More »PANW best practices from Day 0

How to measure configuration quality?

Organizations may invest in best-of-breed solutions, but if these are poorly configured, they won’t reap the benefits. I’ve seen many instances like this in both public and private entities. Sometimes configuration errors are obvious—such as widely open firewall rules or a network access control system that assigns the same VLAN to all hosts (yes, I’ve… Read More »How to measure configuration quality?

How to choose the right firewall model?

How do you choose the right firewall model for your environment? The first and obvious  factor to consider is performance. We need to account for the features that will be used in our firewall (IPsec tunnels, security features, SSL decryption). Based on the expected throughput and using vendor datasheets, we can estimate which model is… Read More »How to choose the right firewall model?

CRWD fuck up, how to prevent it

We all know what happened last Friday (19.07.2023). “Crowdstrikers” had a terrible day. What are my thoughts about that situation? Of course, it is obvious that some team at CRWD missed something, and the testing phase wasn’t good enough. Mistakes happen, and this one had a really big impact. I don’t want to blame the… Read More »CRWD fuck up, how to prevent it