Skip to end of metadata
Go to start of metadata

You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 2 Current »

About the Device

 The Palo Alto Networks firewall allows you to specify security policies based on accurate identification of each application seeking access to your network.

Device Information

 Entity

Particulars

Vendor Name

 Palo Alto

Product Name

 PA Series Firewall

Type of Device

 Hosted

Collection Method

Log Type

 Ingestion label

Preferred Logging Protocol

Log collection method

Palo Alto Networks Firewall

PAN_FIREWALL

 Syslog(CSV)

 CyberHub

Port Requirements

Source

Destination

Port

Palo Alto Networks Firewall

CyberHub

601 (TCP)

Device Configuration

 The Palo Alto NG Firewall generates logs in syslog format and fetches report in xml from wildfire cloud. To configure the device to forward syslog events to collector and fetch xml reports from wildfire cloud, perform the below-mentioned steps.

  1. For syslog configuration on Palo Alto Device, log in to Palo Alto device with the credentials.

  2. Under the Device tab, click Server Profiles > Syslog to open the Syslog Settings page.

  3. Add a new Syslog server by doing the following, in order:

  4. Click Add to open the New Syslog Server Profile window.Specify the following information.

    1. Name – Enter a name for the collector computer, and then click Add.

    2. Server – Enter the IP address of the collector computer.

    3. Transport - Select TCP as the method of communication with the syslog server.

    4. Port – 601. Default port for TCP

    5. Format – Select the format as “BSD”.

    6. Facility – Select "LOG_USER" from the drop-down list.

  5. Click OK to save the changes.

  6.  Define a Log Forwarding Profile on Palo Alto Device to send Traffic, Threat and Wildfire logs to the collector through Syslog.

    1. In the Palo Alto Device Console, Under the Objects tab, click Log Forwarding to open the Logging Profiles page.

    2. Add a new profile. To do this, click Add to open the New Log ForwardingProfile page and specify the following information:

    3. Name – Enter a profile name.

    4. Traffic Settings: Syslog Setting – For Syslog, select the syslog server profile added in step 1  under Syslog column.

    5. Threat Settings: Syslog Setting – For each severity level, select the syslog server profile added in step 1 under Syslog column.

    6. WildFire Setting: Syslog Setting – For each verdict, select the syslog server profile added in step 1 under Syslog column.

  7. Click OK to submit the new profile.

Integration Parameters

Parameters required from customer for Integration.

Property

Default Value

Description

IP Address

Palo Alto Firewall interface IP address

Hostname or IP address of the device which forwards logs to the CyberHub.

  • No labels