Todd's Blog

Todd's Tips for System Adminstrators

  • TechDays
  • Speaking Engagements
  • Contact Me
  • About Me

Connect

  • LinkedIn

Powered by Genesis

Real Time Block Lists with Palo Alto Firewalls

posted on June 17, 2016

If you use a Palo Alto firewall, a new feature since PanOS 5.0 is the real time block lists. I’ve had a few people ask me how to set them up so here is the instructions.

To know what the max number of IPs that your firewall can handle in the RBL, run the following command from the CLI.

show system state | match cfg.general.max-address

This will give you the maximum number of IPs you can have in the list.

Next in the gui on your Palo Alto device, head to objects and then in the left, go to Dynamic Block Lists.

PaloAlto-RealTime-Block-Lists-1

Here is the list of block lists that I’ve configured. To create a new one, click on the add button and give the list a name and a web source for the list. Decide how often you want it to update.

PaloAlto-RealTime-Block-Lists-2

Finally you need to create a deny rule blocking these sites inbound.

PaloAlto-Deny-Policy

Commit the changes and you are off to the races. I often will leave logging on for a bit to see what is being blocked, but eventually, I turn it off because I don’t really care what traffic I am dropping.

Here is a list of sites I pull in. It appears some of these might be managed by a Palo Alto engineer, but I am not certain about this.

  • DSheild Top 20 – https://panwdbl.appspot.com/lists/dshieldbl.txt
  • https://www.team-cymru.org/Services/Bogons/fullbogons-ipv4.txt
  • SpamHaus – https://panwdbl.appspot.com/lists/shdrop.txt (Spam list)
  • Zues Tracker – https://panwdbl.appspot.com/lists/zeustrackerbadips.txt
  • Malware Domain List – https://panwdbl.appspot.com/lists/mdl.txt
  • Openblock List – http://panwdbl.appspot.com/lists/openbl.txt

 

 

 

Filed Under: Technology Tagged With: Firewall, Palo Alto, Security

OWSUG Meeting – Windows 7 Security Tidbits & Understanding and Preventing Insider Threat

posted on May 12, 2009

This looks like an excellent event to attend. I strongly recommend this one to anyone who can make it out to the event.

 


OWSUG

June 3rd 2009 User Group Meeting

Topic: Windows 7 Security Tidbits & Understanding and Preventing Insider Threat

Description:

Windows 7 Security Tidbits – Windows 7 is coming and the boss is asking you about all those new security features. Perhaps you’ve heard some buzz about AppLocker? What’s this about DirectAccess connecting securely to your corporate network without a VPN?  What’s up with BitlLocker To Go? In this fun and interactive session, Kai Axford, a Microsoft Senior Security Strategist with Microsoft’s Trustworthy Computing team, will demonstrate some of the new security features in Microsoft’s newest desktop operating system. Bring your questions and get the scoop on these upcoming Microsoft security technologies!

Understanding and Preventing Insider Threat – Many analysts have stated that the Number One issue facing corporate customers today is the threat of targeted corporate espionage coming from within the organization. Join Kai Axford, a security strategist from the Microsoft Trustworthy Computing team for an entertaining and engaging session, as he shares real stories from the trenches about the risk this threat presents for both you and your customers. He’ll demo the means by which these attacks occur and discuss the mindset of the attackers. Don’t miss the chance to see how this is done!

Speaker:

Kai Axford (CISSP, MCSE-Security) is a Senior Security Strategist in Microsoft’s Trustworthy Computing Group.

A ten-year Microsoft veteran, Kai is responsible for discussing and recommending security solutions for both private and public sector organizations. In addition, he conducts Chief Security Officer councils worldwide, taking executive feedback and affecting change within Microsoft’s security products and processes.

Kai started with Microsoft in 1999 as a Server Support Engineer and then moved on to become an IT Pro Evangelist, focusing on his peers through the Microsoft TechNet Events program. Kai has delivered more than 300 security presentations on a variety of topics, including digital forensics, security management, incident response, and computer espionage. He is a frequent speaker at security conferences, executive meetings, and business seminars around the world.

He is finishing an MBA in Information Assurance and is a member of ISSA, INFRAGARD, ASIS, and the North Texas Electronic Crimes Task Force. He was the recipient of the 2006 “Rising Star” award from the Information Security Executive council. Kai is interested in security management and hopes to become a Chief Security Officer one day.

Prior to Microsoft, Kai served as a leader in several real-world operations with the U.S. Army’s elite 75th Ranger Regiment. Originally from Wisconsin, Kai is a huge NFL Green Bay Packers fan.  He is based in Dallas, Texas with his lovely wife, a new baby boy, and a (very wet) yellow Labrador.

Location:
Microsoft Canada Co.
100 Queen Street Suite 500
Ottawa, Ontario
K1P 1J9

Agenda:

5:00 p.m.  Event registration
5:30 p.m.  Q & A
8:00 p.m.  Door Prizes

Notes:

· Pizza and Pop will be served, Please RSVP to help us order enough of both.

· Please note that no one will be admitted after 5:55 p.m.!

RSVP: http://www.clicktoattend.com/?id=138491

Links

OWSUG.ca Web Site          http://owsug.ca/

OWSUG.ca Mailing list     http://lists.owsug.ca

OWSUG.ca Blog                  http://owsug.ca/blogs/MainFeed.aspx

OWSUG.ca Forums            http://owsug.ca/forums/default.aspx

Filed Under: User Groups Tagged With: OWSUG, Security, Windows 7

Windows 7 – The Lineup is Released

posted on February 3, 2009

Microsoft announced their Windows 7 lineup today. The plan for Windows 7 is to promote 2 main versions in North America, Professional and Home Premium, but the other versions will be there as well.

The versions being offered are as follows and the points listed are my interpretation of the what I read in the article.

  • Starter – Only available to OEM’s.
  • Home Basic – Not available in North America
  • Home Premium – The version for home users
  • Professional – Mainstream version for business customers
  • Enterprise – For customers who opt to purchase Software Assurance, has bitlocker and other security features
  • Ultimate – For those customers who want every feature available

According to the article, there is supposed to be a natural progression from version to version, as opposed to having some features in some versions and not others at the same level like we saw in Vista. (The example given was Media Centre being available in Vista Home Premium but not Vista Business).

It will be interesting to see what the differences between versions on Windows 7 will be. From the press release, it looks like Bitlocker will only be available to customers who buy Ultimate or purchase Software Assurance and utilize the Enterprise edition of Windows 7. That’s a shame because I think the value of Bitlocker should be available to home users along with businesses. Home users have a need to protect their data just like a company, but I guess I can’t have everything in one version.

The complete plan is located at http://www.microsoft.com/presspass/features/2009/feb09/02-03Win7SKU-QA.mspx

 

Technorati Tags: Windows 7

Filed Under: Technology Tagged With: BitLocker, Enterprise, Home Basic, Home Premium, Professional, Security, Starter, Ultimate, Versions, Windows 7

  • 1
  • 2
  • 3
  • 4
  • Next Page »

Recent Posts

  • Office 365 – Creating Custom SKUs
  • Setting a Default Printer in Windows 10
  • Deploying Windows to the Correct Drive in Configuration Manager
  • Surface Pro 4, Surface Dock and DVI Problems
  • Enabling UEV in Windows 10 1607

Recent Comments

  • Moore Details on Setting up a Delayed Charge in Quickbooks Online
  • MCP Exam Training on Using PowerShell to Get a List of Groups from Active Directory
  • Kac on Setting up an Office 2010 KMS Host Server
  • prabumedia.com | Pilih lisensi MAK atau MKS untuk aktifasi produk Microsoft ? on Setting up a KMS Server
  • prabumedia.com | Pilih lisensi MAK atau MKS untuk aktifasi produk Microsoft ? on Setting up an Office 2010 KMS Host Server

Archives

Categories

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org