Palo Alto Networks Firewall Debug and Troubleshoot Lab Guide ®
PAN-OS 8.0 EDU-311 Courseware Version A
®
Palo Alto Networks Te!nial E"uation
Palo Alto Networks, Inc. https://www.paloaltonetworks.com
©2007-2017, Palo Alto Networks, Inc. Palo Alto Networks and PAN-OS are registered trademarks of Palo Alto Networks, Inc. All oter marks mentioned erein ma! "e trademarks of teir res#ecti$e com#anies.
©2017, Palo Alto Networks, Inc.
Page 2
Table of Contents %a"le of &ontents.............................................................................................................................' %!#ogra#ical &on$entions.............................................................................................................( )ow to *se %is +a" ide............................................................................................................ +a" ide O"/ecti$es......................................................................................................................7 +a" 1 Scenario Administrati$e %ro"lesooting............................................................................ Scenario........................................................................................................................................ +a" Notes..................................................................................................................................... +a" 1 Soltion Administrati$e %ro"lesooting..........................................................................10 Im#ort te &onfigration iles...................................................................................................10 +oad te &onfigration iles.....................................................................................................12 3iew 3iew te &onfigration from te &+I and te 4e"*I................................................... 4e"*I.............................................................. ............1' .1' ater 5asic S!stem Information..............................................................................................16 ater Ad$anced Information....................................................................................................16 +a" 2 Scenario irewall %ro"lesooting....................................................................................1 Scenario etails.........................................................................................................................1 +a" 2 Soltion irewall %ro"lesooting.....................................................................................1 %ro"lesoot Administrati$e Access..................................................... Access.......................................................................................... ..................................... 1 As 8stdent9 Admin, &reate a New :; Secrit! ;one..........................................................1< %ro"lesoot *ser Atentication Isses...................................................................................20 Perform a !namic *#date........................................................................................................20 +a" ' Scenario +a!er ' %ro"lesooting.....................................................................................2' +a" etails.................................................................................................................................2' %nnel &onfigration Information.............................................................................................26 =ternet 1>' Interface S#ecification.......................................................................................26 :; Secrit! ;one S#ecification.........................................................................................26 I?= atewa! S#ecification....................................................................................................26 I?= &r!#to Profile S#ecification...........................................................................................2(
©2017, Palo Alto Networks, Inc.
Page 3
IPsec &r!#to Profile S#ecification.........................................................................................2( IPsec %nnel &onfigration S#ecification..............................................................................2( %est %nnel &onnecti$it!...........................................................................................................2 +a" ' Soltion +a!er ' %ro"lesooting......................................................................................27 %ro"lesoot +oss of &onnecti$it! to te Internet....................................................................27 %ro"lesoot )%%P>)%%P Access to 4e"sites......................................................... ................ 27 In$estigate te Acti$it! and @ele$ance of +egac! Policies.......................................................2 %ro"lesoot &onnecti$it! to a S#ecific Address......................................................................2 %ro"lesoot 3PN %nnel &onfigration..................................................................................2 +a" 6 Scenario SS+ ecr!#tion Polic! %ro"lesooting.............................................................'0 +a" etails.................................................................................................................................'0 +a" 6 Soltion SS+ ecr!#tion Polic! %ro"lesooting.............................................................'1 SS+ 4e"sites Are Not ecr!#ted..............................................................................................'1 +a" ( Scenario Polic! and Performance %ro"lesooting...........................................................'' +a" etails.................................................................................................................................'' +a" ( Soltion Polic! and Performance %ro"lesooting............................................................'( %ro"lesoot an Ina"ilit! to Access Allowed :edia Ser$ices................................................... '( ailre to 5lock Infected iles...................................................................................................' %ro"lesoot a Pro"lem wit *ser-I.......................................................................................' 4! Some 4e" Pages Are %iming Ot.....................................................................................' &reate and @e$iew a 3ideo Stream Packet &a#tre..................................................................'7
©2017, Palo Alto Networks, Inc.
Page 4
Typographical Conventions %is gide ses te following t!#ogra#ical con$entions for s#ecial terms and instrctions. Convention
Meaning
Example
5olding
Names of selecta"le items in te we" interface
&lick Secrit! to o#en te Secrit! @le Page
Courier font
%et tat !o enter and coding eam#les
=nter te following command a:\setup
%e show arp all command !ields tis ot#t username@hostname> show arp