Initial setup of Palo Alto Networks Next Generation Firewall

Ok, we just unboxed our PA-500 NG Firewall and we want to deploy it in our network for variety of purposes. Before we deploy it, there are several steps that should be taken care of, such as assigning IP parameters, registering with Paloalto Networks and so on. We will deal with deployment scenarios later as well as some standard use cases. For now, we just want to do initial tasks.

The model we will be working with is PA-500 which has eight ethernet ports for data plane and one ethernet port for management plane. In order to configure the box, we need to connect our laptop to the management port and assign our laptop with the IP address from the 192.168.1.2-192.168.1.254 range, because the default management IP address of PA is 192.168.1.1:

31-Jul-2014 9-22-06 AM

We will receive a certificate warning, which is ok, because this certificate is self-signed and as such is not trusted by our browser:

31-Jul-2014 9-24-04 AM

Then we log in with the default credentials of admin/admin:

31-Jul-2014 9-24-37 AM

We will be notified that we should change our credentials, which we will do in a later step:

31-Jul-2014 9-25-42 AM

After we successfully log in, we will see our management interface with basic informations:

31-Jul-2014 9-26-45 AM

We click Device->Administrators->admin, type old password and two times new password, then click OK:

31-Jul-2014 9-28-23 AM

Now we navigate to Device->Setup option, and under “General Settings” we click small settings icon. We then change some basic parameters:

31-Jul-2014 9-29-51 AM

31-Jul-2014 9-32-07 AM

We do the same for “Management Interface Settings”:

31-Jul-2014 9-34-08 AM

In the dialog that opens, we type in the new IP parameters that fit our network: IP address, Netmask and Default Gateway. In here we can also specify which management protocols are allowed to the box and from which addresses. If we don’t specify anything in the “Permitted IP Addresses” then any IP address will be able to connect. If we specify 10.0.0.0/24, for example, then only PCs from that range will be able to connect. Please note that on the picture the default gateway is same as the management IP address. This is wrong, but I was unable to correct the picture for reasons not important now 🙂 This should be valid default router IP address, for example 10.0.0.1:

31-Jul-2014 9-38-17 AM

Now we can make our changes permanent as part of startup configuration by clicking “Commit”:

31-Jul-2014 9-41-06 AM

31-Jul-2014 9-43-07 AM

Now we will be disconnected from the box because our IP address is 192.168.1.2 and the IP address of PA has changed. We could now change our IP address to be from the same segment as PA, and then reconnect to the box. We want to be nice to the box and shut it down gracefully, instead of just pulling out the cable. This is done by clicking Device->Operations->Shutdown Device:

31-Jul-2014 9-51-14 AM

31-Jul-2014 9-51-58 AM

There is a catch now: we don’t know when the box is down, because it will not power off by itself. So we can connect our serial sable to the console port with our terminal software and wait for the final shutdown message:

31-Jul-2014 9-53-52 AM

No we can pull out the cable and mount our PA box into datacenter. We now need to obtain our licenses from the PAN site and upgrade the software and various signatures. Before we can do that, we need to specify the DNS servers, so the box can reach out to the PAN site. This is done via Device->Services:

31-Jul-2014 10-45-45 AM

Then we specify our private DNS servers or public ones, depending on our network and security policies:

31-Jul-2014 10-46-50 AM

We are now ready for obtaining licenses and updating the box. We log in to our support page, support.paloaltonetworks.com and click Assets and then Register New Device. The dialog pops up requiring some basic information about the box. The most important one is the serial number which we obtain from our PA partner. After submitting the form, we are presented with features we are able to use:

11-Aug-2014 10-43-36 AM

After completing this task, we are returned back to main page where we can check out our license status, such as expiration date or if this license is evaluation (marked with a red capital T).  Now we go back to our box, and under Device->Licenses->Retrieve license keys from license server:

11-Aug-2014 10-49-13 AM

Finally, we may upgrade our software to the latest version. To check our version, as well as available versions we go under Device->Software:

11-Aug-2014 10-59-14 AM

Here we can see a bunch of stuff. Marked with red color is our current version with the option of re-install in the case of some sort of problem. Green squared are version downloaded to the box, but not active. We can activate any of them by clicking Install. Finally, blue squared are the most current version. We can download this or any other available version to the box and install it. This is exactly what we are going to do:

11-Aug-2014 11-03-52 AM

A time for coffee 🙂

11-Aug-2014 11-59-34 AM

After clicking OK, we may install the downloaded version:

11-Aug-2014 12-00-51 PM

11-Aug-2014 12-04-23 PM

After the installation is completed, we need to reboot our box:

11-Aug-2014 1-28-28 PM

After a reboot, we make sure that the device signatures and databases are current and we are ready to go. We can do that by clicking: Device->Dynamic Updates. Depending on our license, we can see different categories, when was the last update when will be next one and so on. We can wait for the next update cycle (01:02 in this case) or trigger the upgrade process manually:

11-Aug-2014 2-05-38 PM

 

We may change these settings by clicking at the schedule link. Also we should note the option of downloading only or downloading and installing updates:

11-Aug-2014 2-51-18 PM

 

Of course, we should not forget submitting our configuration.

Now we are ready for our first scenario. Next time…

 

 

Advertisements
This entry was posted in Firewall, Paloalto, Security and tagged , , . Bookmark the permalink.

55 Responses to Initial setup of Palo Alto Networks Next Generation Firewall

  1. Pingback: [NEW PCNSE7 PDF]Download PCNSE7 Dumps VCE from Braindump2go[11-20] | Offer Free Online Latest Braindump2go Microsoft Exam Dumps

  2. Pingback: [NEW PCNSE7 PDF]Download PCNSE7 Exam Questions and Answers from Braindump2go[11-20] | All Latest Braindump2go Certificate Exams Dumps

  3. Pingback: [NEW PCNSE7 PDF]Braindump2go Free PCNSE7 VCE Files Free Download[11-20] | Free Latest Braindump2go IT Exam Dumps

  4. Pingback: [NEW PCNSE7 PDF]Free Downloading for Braindump2go PCNSE7 Dumps PDF[11-20] | Free Braindump2go Latest Microsoft Exam Dumps

  5. Pingback: [NEW PCNSE7 PDF]Free Downloading PCNSE7 Dumps in Braindump2go[11-20] | | Free Download Latest Braindump2go Microsoft Exam Dumps

  6. Pingback: [NEW PCNSE7 PDF]Free Downloading PCNSE7 Dumps in Braindump2go[11-20] | Braindump2go Updated Real Microsoft MCTS Exam Questions & MCTS Dumps

  7. Pingback: [NEW PCNSE7 PDF]Free Downloading PCNSE7 Dumps in Braindump2go[11-20] – Free Download Braindump2go MCSA Exam Questions & Dumps with PDF&VCE

  8. Pingback: [NEW PCNSE7 PDF]Braindump2go Offers PCNSE7 New Questions for PCNSE7 Exam Candidates[11-20] | Collection of Latest Microsoft Exam Questions and Hot Exam Dumps

  9. Pingback: [NEW PCNSE7 PDF]Braindump2go PCNSE7 Exam Questions 131q[11-20] | Updated Real Microsoft MCSE Exam Questions & MCSE Dumps

  10. Pingback: [NEW PCNSE7 PDF]Braindump2go Free PCNSE7 PDF Dumps 131q[11-20] | Braindump2go Hot IT Certification Exam Questions

  11. Pingback: [NEW PCNSE7 PDF]Braindump2go 131Q PCNSE7 PDF Free Download[11-20] – Free Download Braindump2go Oracle OCA, OCP, OCM,Microsoft Exam Questions & Dumps with PDF&VCE

  12. Pingback: [NEW PCNSE7 PDF]Free Braindump2go PCNSE7 Exam Dumps 131Q Download[11-20] | Free Latest Braindump2go Exam Dumps

  13. Pingback: [NEW PCNSE7 PDF]Free Braindump2go PCNSE7 Exam Questions Download 131Q[11-20]Free Download Braindump2go VMware VCP510 & VCP550 Exam Dumps | Free Download Braindump2go VMware VCP510 & VCP550 Exam Dumps

  14. Pingback: [NEW PCNSE7 PDF]Free Braindump2go PCNSE7 Questions Instant Download 131Q[11-20] | Free IT Exam VCE And PDF Dumps

  15. Pingback: [NEW PCNSE7 PDF]Free Braindump2go PCNSE7 Dumps VCE Download 131Q[11-20] | Braindump2go IT Exam Questions Free Download

  16. Pingback: [NEW PCNSE7 PDF]Free Braindump2go PCNSE7 PDF Dumps Download 131Q[11-20] | Braindump2go Exam Dumps VCE&PDF - ExamCollection

  17. Pingback: [NEW PCNSE7 PDF]PCNSE7 Palo Alto Networks Exam Dumps Free Download from Braindump2go[11-20] | Latest Braindump2go VCE And PDF Dumps Free Download

  18. Pingback: [NEW PCNSE7 PDF]PCNSE7 Palo Alto Networks Exam Questions from Braindump2go Free Download[11-20] | Braindump2go Free IT Certification Exams and Tests Collection

  19. Pingback: [NEW PCNSE7 PDF]Free Braindump2go 131Q PCNSE7 Dumps Free Download[11-20] | Braindump2go Free PDF&VCE Dumps Download - ExamCollection

  20. Pingback: [NEW PCNSE7 PDF]Free Braindump2go Latest PCNSE7 Exam Questions 131Q Free Download[11-20] | Braindump2go New PDF and VCE Dumps - 100% Exam Questions

  21. Pingback: [NEW PCNSE7 PDF]Free Braindump2go Latest PCNSE7 VCE 131Q Guarantee 100% Pass[11-20] | Braindump2go Exam Dumps with PDF and VCE(New Version!)

  22. Pingback: [NEW PCNSE7 PDF]Free Braindump2go Latest PCNSE7 PDF 131Q 100% Pass Guaranteed[11-20] | Free Braindump2go Exam Dumps Camp | Free PDF and VCE

  23. Pingback: [NEW PCNSE7 PDF]Free Braindump2go Free PCNSE7 Dumps VCE 131Q Download[11-20] | Braindump2go Free Exams VCE and PDF

  24. Pingback: [March 2018] Lead2pass 2018 100% Real PCNSE7 Exam Questions 226q | Lead2pass Offers New Updated IT Exam Dumps Permanently

  25. Pingback: [March 2018] Lead2pass Free Palo Alto Networks PCNSE7 Braindumps VCE Updated 226q | VCE And PDF Dumps Of Lead2pass

  26. Pingback: [March 2018] PCNSE7 New Questions Free Download In Lead2pass 226q | Lead2pass New Updated IT Exam Questions

  27. Pingback: [March 2018] Lead2pass Dumps For Exam PCNSE7 With New Updated Exam Questions 226q | Lead2pass New Updated IT Exam Questions

  28. Pingback: [March 2018] Easily Pass PCNSE7 Exam By Training Lead2pass New Palo Alto Networks VCE Dumps 226q | 100% New Updated IT Exam Questions

  29. Pingback: [March 2018] Easily Pass PCNSE7 Exam With Lead2pass New Palo Alto Networks PCNSE7 Brain Dumps 226q | New Updated Lead2pass Exam Collection

  30. Pingback: [March 2018] Easily Pass Palo Alto Networks PCNSE7 Exam With Lead2pass Latest Palo Alto Networks PCNSE7 Brain Dumps 226q | Free IT Exam Questions Collection From Lead2pass

  31. Pingback: [March 2018] Lead2pass Exam Collection PCNSE7 Dumps And PCNSE7 New Questions 226q | Lead2pass All Latest Exam Questions

  32. Pingback: [March 2018] Free Download PCNSE7 Exam Dumps VCE From Lead2pass 226q | Latest Lead2pass Exam Dumps

  33. Pingback: [March 2018] Free Download Of Lead2pass PCNSE7 Real Exam Questions 226q | 100% Pass with Lead2pass Exam Questions

  34. Pingback: [March 2018] Free Lead2pass PCNSE7 PDF Download 100% Pass Exam PCNSE7 226q | Free Sharing Lead2pass Exam Collection

  35. Pingback: [March 2018] Free Share Of Lead2pass PCNSE7 VCE And PDF Dumps 226q | 100% Free Lead2pass Exam Dumps Download

  36. Pingback: [March 2018] Free Version Lead2pass Palo Alto Networks PCNSE7 PDF Dumps With Exam Questions Download 226q | 100% Valid Exam Dumps on Lead2pass

  37. Pingback: [March 2018] Lead2pass Latest Palo Alto Networks PCNSE7 Exam Questions Free Downloading 226q | 100% Pass IT Exam By Training Lead2pass New VCE And PDF Dumps

  38. Pingback: [March 2018] Lead2pass Palo Alto Networks PCNSE7 Exam Dumps Free Download 226q | New Lead2pass VCE And PDF Free Instant Download

  39. Pingback: [March 2018] Lead2pass PCNSE7 Exam Questions Guarantee PCNSE7 Certification Exam 100% Success 226q | New Lead2pass PDF And VCE Ensure IT Exam Pass 100%

  40. Pingback: [March 2018] Lead2pass 2018 100% Real PCNSE7 Exam Questions 226q | Lead2pass New Updated IT Exam Questions

  41. Pingback: [March 2018] Lead2pass Palo Alto Networks PCNSE7 VCE And PDF Instant Download 226q | New Lead2pass Practice Test Free Download

  42. Pingback: [March 2018] Lead2pass Offers Free PCNSE7 Dumps Files for Free Downloading By PCNSE7 Exam Expert 226q | Free Download Lead2pass VCE And PDF Dumps

  43. Pingback: [March 2018] Lead2pass Provides Free PCNSE7 Exam Dumps PDF 226q | Lead2pass 100% Valid Exam Questions PDF Free Download

  44. Pingback: [March 2018] Lead2pass PCNSE7 Exam Questions Free Download 226q | Lead2pass Dumps

  45. Pingback: [March 2018] Latest PCNSE7 Dumps PDF Free Download In Lead2pass 226q | Latest Dumps PDF Free Download In Lead2pass

  46. Pingback: [March 2018] New Lead2pass Palo Alto Networks PCNSE7 New Questions Free Download 226q | Quickly Pass Test With Lead2pass New Brain Dumps

  47. Pingback: [March 2018] PCNSE7 Exam Dump Free Updation Availabe In Lead2pass 226q | Offering New Exam PDF And Exam VCE Dumps For Free Downloading

  48. Pingback: [March 2018] Lead2pass New Released Palo Alto Networks PCNSE7 Exam Questions From Palo Alto Networks Exam Center 226q | Updated Study Materials From Lead2pass Free Downloading

  49. Pingback: [March 2018] Official PCNSE7 Exam Preparation Download From Lead2pass 226q | Exam Dumps Free Download In Lead2pass 100% Real Questions

  50. Pingback: [March 2018] Lead2pass PCNSE7 New Questions For Passing The PCNSE7 Certification Exam 226q | Free Lead2pass Dumps VCE

  51. Pingback: [March 2018] Pass PCNSE7 Exam By Training Lead2pass New VCE And PDF Dumps 226q | Best Lead2pass PDF Dumps With New Update Exam Questions

  52. Pingback: [March 2018] Ensure Pass PCNSE7 Exam With Lead2pass New PCNSE7 Brain Dumps 226q | Lead2pass Dumps For Exam With New Updated Exam Questions

  53. Pingback: [March 2018] Try Lead2pass Latest Palo Alto Networks PCNSE7 Dumps To Pass The Exam Successfully 226q | Exam PDF Free Instant Download From Lead2pass

  54. Pingback: [March 2018] Latest Lead2pass PCNSE7 Exam Free PCNSE7 Dumps Download 226q | New Lead2pass Dumps PDF Version Released For Free Downloading

  55. Pingback: [March 2018] PCNSE7 Latest Dumps Free Download From Lead2pass 226q | Ensure Pass IT Exam By Training Lead2pass New VCE And PDF Dumps

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out /  Change )

Google+ photo

You are commenting using your Google+ account. Log Out /  Change )

Twitter picture

You are commenting using your Twitter account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )

w

Connecting to %s