Pages

Showing posts with label panorama. Show all posts
Showing posts with label panorama. Show all posts

Sunday, November 3, 2019

Administrator rules for your PANW firewalls (work in progress)

Will you let your kids play with your gun? I hope not.
With your firewall, I think you should do the same.

Letting the firewall managed by people who don't know exactly what they are doing, and the risks implied because of the applied configuration can be catastrophic in case of breach : it is like having a lock on your door, but leaving the door opened; do not get surprised if something bad happens then.

Sunday, October 13, 2019

Password recovery on PAN-OS firewall

If you forgot your domain account you used to log on your favorite PAN-OS systems, you simply have to reset it from the domain controller (or the equivalent).

But how to recover the local account password?

To do so, there are multiple ways to recover it.

1 - High Availability
In the case the firewall is in HA with another firewall, if you can access the peer firewall, you can create a new local account, and then sync the config.

2- Panorama
In case the firewall is added to Panorama, it is possible to connect from Panorama then select the firewall to display the firewall.
You can also add a new account on a template, and push the template to the firewall.

3- Maintenance mode
It is possible to restore a previous configuration (you need to need the password on the previous configuration).
You can also export the configuration, edit the configuration then load it with a new password.
Finally, you can factory reset (last resort solution)

Finally, I advise you to set a read-only account with a password which can expire : if you have lost the superuser password, and you don't want to factory reset the firewall, the TAC will be able to do something using this read-only account.
And while you cannot configure the firewall, you still can see the logs and reports.