About the Device
The Palo Alto Networks firewall allows you to specify security policies based on accurate identification of each application seeking access to your network.
Device Information
Entity | Particulars |
---|---|
Vendor Name | Palo Alto |
Product Name | PA Series Firewall |
Type of Device | Hosted |
Collection Method
Log Type | Ingestion label | Preferred Logging Protocol | Log collection method |
---|---|---|---|
Palo Alto Networks Firewall | PAN_FIREWALL | Syslog(CSV) | CyberHub |
Port Requirements
Source | Destination | Port |
---|---|---|
Palo Alto Networks Firewall | CyberHub | 601 (TCP) |
Device Configuration
The Palo Alto NG Firewall generates logs in syslog format and fetches report in xml from wildfire cloud. To configure the device to forward syslog events to collector and fetch xml reports from wildfire cloud, perform the below-mentioned steps.
For syslog configuration on Palo Alto Device, log in to Palo Alto device with the credentials.
Under the Device tab, click Server Profiles > Syslog to open the Syslog Settings page.
Add a new Syslog server by doing the following, in order:
Click Add to open the New Syslog Server Profile window.Specify the following information.
Name – Enter a name for the collector computer, and then click Add.
Server – Enter the IP address of the collector computer.
Transport - Select TCP as the method of communication with the syslog server.
Port – 601. Default port for TCP
Format – Select the format as “BSD”.
Facility – Select "LOG_USER" from the drop-down list.
Click OK to save the changes.
Define a Log Forwarding Profile on Palo Alto Device to send Traffic, Threat and Wildfire logs to the collector through Syslog.
In the Palo Alto Device Console, Under the Objects tab, click Log Forwarding to open the Logging Profiles page.
Add a new profile. To do this, click Add to open the New Log ForwardingProfile page and specify the following information:
Name – Enter a profile name.
Traffic Settings: Syslog Setting – For Syslog, select the syslog server profile added in step 1 under Syslog column.
Threat Settings: Syslog Setting – For each severity level, select the syslog server profile added in step 1 under Syslog column.
WildFire Setting: Syslog Setting – For each verdict, select the syslog server profile added in step 1 under Syslog column.
Click OK to submit the new profile.
Integration Parameters
Parameters required from customer for Integration.
Property | Default Value | Description |
---|---|---|
IP Address | Palo Alto Firewall interface IP address | Hostname or IP address of the device which forwards logs to the CyberHub. |