{"id":1617,"date":"2023-02-22T08:00:00","date_gmt":"2023-02-22T14:00:00","guid":{"rendered":"https:\/\/packitforwarding.com\/?p=1617"},"modified":"2023-02-21T20:18:59","modified_gmt":"2023-02-22T02:18:59","slug":"captive-portal-palo-alto","status":"publish","type":"post","link":"https:\/\/packitforwarding.com\/index.php\/2023\/02\/22\/captive-portal-palo-alto\/","title":{"rendered":"Captive Portals and Not So Captive Portals"},"content":{"rendered":"\n<p>A few years ago as I was first cutting my teeth in the Palo Alto firewall world, I had a customer request something &#8220;unique&#8221; and I created a one-off solution. The request was to have a stand-alone portal that the end-users could go to and log in to gain additional access to resources. The reason for this was BYOD and other non-managed devices that wouldn&#8217;t show up in User-ID through the normal User-ID agent polling Windows. The traditional captive portal wasn&#8217;t a good fit either as the customer didn&#8217;t want to purchase a 3rd party signed TLS certificate. So I pulled out some PHP and created a very simple portal that did an LDAP authentication and then used Palo Alto&#8217;s XML-API to send a username and IP pair to the firewall. This worked well until recently when that server started to have issues after upgrading to PHP 8.1. <\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Opportunity!<\/h2>\n\n\n\n<p>I took the issues with the PHP application as a sign to do something better. By this point, I knew a lot more about the Palo Alto firewalls and decided it was time to try going through the captive portal documentation again and see what I could do. I set up a standard captive portal using the authentication policy. For the certificate, I used a certificate signed by the customer&#8217;s internal CA. I had an ulterior motive in getting the firewall set up as a SubCA so that we could implement SSL Decrypt. This all worked well, but it still didn&#8217;t give me the stand-alone portal that the customer&#8217;s users could just go to on their own&#8230; or did it?<\/p>\n\n\n\n<p>On a whim, I copied the URL that happened on the redirect and started playing with it. The default URL looks like this: <\/p>\n\n\n<div class=\"wp-block-syntaxhighlighter-code \"><pre class=\"brush: plain; auto-links: false; title: ; notranslate\" title=\"\">\nhttps:\/\/FQDN:6082\/php\/uid.php?vsys=1&amp;amp;rule=0&amp;amp;token=AUFxGTIly7YWSbOPd3WWSaUquwU=&amp;amp;url=https:\/\/example.com\n<\/pre><\/div>\n\n\n<p>So let&#8217;s take a look at this URL. The port isn&#8217;t &#8220;standard&#8221;, but everything else just looks like a PHP website that is passed a few values. Vsys is obviously there in case the Palo Alto firewall has multiple vsys operating. So by default, it will be 1 if there is only one vsys. The next parameter is rule. I&#8217;m fairly sure that this corresponds to the authentication rule and apparently is indexed starting at 0. The last two parameters are very much related to the redirection, so I thought why not just leave them off and see what happens? As it turns out it worked! Just passing the vsys and rule parameters created an entry in user-id.<\/p>\n\n\n\n<p>The next challenge was to get this to work without the BYOD devices needing to trust the internal CA. A <a href=\"https:\/\/www.reddit.com\/r\/paloaltonetworks\/comments\/m2xhra\/captive_portal_direct_access_or_redirect_to\/\" target=\"_blank\" rel=\"noreferrer noopener\">Reddit post<\/a> gave me the secret sauce.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>6080 &#8211; Captive portal with NTLM automatic login<\/li>\n\n\n\n<li>6081 &#8211; Captive portal with HTTP<\/li>\n\n\n\n<li>6082 &#8211; Captive portal with HTTPS<\/li>\n<\/ul>\n\n\n\n<p>Ok, I know using HTTP isn&#8217;t secure and that it means the password is going clear text, but sometimes we have to make concessions. The number of these devices is fairly limited and the traffic is all inside so the risk was accepted. I am still trying to get them to consider a better strategy that will include a 3rd party cert. (Can all of the firewall vendors please just support ACME on their gear so we can use Let&#8217;s Encrypt?) So the final URL that I&#8217;m using with the customer is https:\/\/FQDN:6081\/php\/uid.php?vsys=1&amp;rule=0. Not the most elegant URL, but it works and meets their needs.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Final Thoughts<\/h2>\n\n\n\n<p>So I learned a lot of things during this process. The bottom line is that we&#8217;ve come to rely on getting users to IP mappings out of Active Directory and we need to rapidly come up with new methodologies as cloud-first becomes the mantra. At the time of this writing, there is no methodology from Palo Alto to get these mappings from either Azure AD (or Intune) or the Google Suite consoles. Identity is King, but we need to get it with as little friction with the end-user as possible.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A few years ago as I was first cutting my teeth in the Palo Alto firewall world, I had a customer request something &#8220;unique&#8221; and I created a one-off solution. The request was to have a stand-alone portal that the end-users could go to and log in to gain additional access to resources. The reason [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":1619,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"Sometimes it takes a few years and a new problem to come up with a better solution for an old problem. #paloalto #identity","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[88,189],"tags":[191],"class_list":["post-1617","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog","category-palo-alto","tag-palo-alto"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Captive Portals and Not So Captive Portals -<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/packitforwarding.com\/index.php\/2023\/02\/22\/captive-portal-palo-alto\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Captive Portals and Not So Captive Portals -\" \/>\n<meta property=\"og:description\" content=\"A few years ago as I was first cutting my teeth in the Palo Alto firewall world, I had a customer request something &#8220;unique&#8221; and I created a one-off solution. The request was to have a stand-alone portal that the end-users could go to and log in to gain additional access to resources. The reason [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/packitforwarding.com\/index.php\/2023\/02\/22\/captive-portal-palo-alto\/\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/packitforwarding\" \/>\n<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/packitforwarding\" \/>\n<meta property=\"article:published_time\" content=\"2023-02-22T14:00:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/i0.wp.com\/packitforwarding.com\/wp-content\/uploads\/2023\/02\/pexels-photo-12652839.jpeg?fit=1880%2C1255&ssl=1\" \/>\n\t<meta property=\"og:image:width\" content=\"1880\" \/>\n\t<meta property=\"og:image:height\" content=\"1255\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Ben Story\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@https:\/\/www.twitter.com\/ntwrk80\" \/>\n<meta name=\"twitter:site\" content=\"@ntwrk80\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Ben Story\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/packitforwarding.com\\\/index.php\\\/2023\\\/02\\\/22\\\/captive-portal-palo-alto\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/packitforwarding.com\\\/index.php\\\/2023\\\/02\\\/22\\\/captive-portal-palo-alto\\\/\"},\"author\":{\"name\":\"Ben Story\",\"@id\":\"https:\\\/\\\/packitforwarding.com\\\/#\\\/schema\\\/person\\\/441c2562293c45fbcf483f246430e6c8\"},\"headline\":\"Captive Portals and Not So Captive Portals\",\"datePublished\":\"2023-02-22T14:00:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/packitforwarding.com\\\/index.php\\\/2023\\\/02\\\/22\\\/captive-portal-palo-alto\\\/\"},\"wordCount\":662,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/packitforwarding.com\\\/#\\\/schema\\\/person\\\/441c2562293c45fbcf483f246430e6c8\"},\"image\":{\"@id\":\"https:\\\/\\\/packitforwarding.com\\\/index.php\\\/2023\\\/02\\\/22\\\/captive-portal-palo-alto\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/i0.wp.com\\\/packitforwarding.com\\\/wp-content\\\/uploads\\\/2023\\\/02\\\/pexels-photo-12652839.jpeg?fit=1880%2C1255&ssl=1\",\"keywords\":[\"Palo Alto\"],\"articleSection\":[\"Blog\",\"Palo Alto\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/packitforwarding.com\\\/index.php\\\/2023\\\/02\\\/22\\\/captive-portal-palo-alto\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/packitforwarding.com\\\/index.php\\\/2023\\\/02\\\/22\\\/captive-portal-palo-alto\\\/\",\"url\":\"https:\\\/\\\/packitforwarding.com\\\/index.php\\\/2023\\\/02\\\/22\\\/captive-portal-palo-alto\\\/\",\"name\":\"Captive Portals and Not So Captive Portals -\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/packitforwarding.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/packitforwarding.com\\\/index.php\\\/2023\\\/02\\\/22\\\/captive-portal-palo-alto\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/packitforwarding.com\\\/index.php\\\/2023\\\/02\\\/22\\\/captive-portal-palo-alto\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/i0.wp.com\\\/packitforwarding.com\\\/wp-content\\\/uploads\\\/2023\\\/02\\\/pexels-photo-12652839.jpeg?fit=1880%2C1255&ssl=1\",\"datePublished\":\"2023-02-22T14:00:00+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/packitforwarding.com\\\/index.php\\\/2023\\\/02\\\/22\\\/captive-portal-palo-alto\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/packitforwarding.com\\\/index.php\\\/2023\\\/02\\\/22\\\/captive-portal-palo-alto\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/packitforwarding.com\\\/index.php\\\/2023\\\/02\\\/22\\\/captive-portal-palo-alto\\\/#primaryimage\",\"url\":\"https:\\\/\\\/i0.wp.com\\\/packitforwarding.com\\\/wp-content\\\/uploads\\\/2023\\\/02\\\/pexels-photo-12652839.jpeg?fit=1880%2C1255&ssl=1\",\"contentUrl\":\"https:\\\/\\\/i0.wp.com\\\/packitforwarding.com\\\/wp-content\\\/uploads\\\/2023\\\/02\\\/pexels-photo-12652839.jpeg?fit=1880%2C1255&ssl=1\",\"width\":1880,\"height\":1255,\"caption\":\"Photo by imustbedead on Pexels.com\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/packitforwarding.com\\\/index.php\\\/2023\\\/02\\\/22\\\/captive-portal-palo-alto\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/packitforwarding.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Captive Portals and Not So Captive Portals\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/packitforwarding.com\\\/#website\",\"url\":\"https:\\\/\\\/packitforwarding.com\\\/\",\"name\":\"\",\"description\":\"Paying it forward to the next generation of IT.\",\"publisher\":{\"@id\":\"https:\\\/\\\/packitforwarding.com\\\/#\\\/schema\\\/person\\\/441c2562293c45fbcf483f246430e6c8\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/packitforwarding.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":[\"Person\",\"Organization\"],\"@id\":\"https:\\\/\\\/packitforwarding.com\\\/#\\\/schema\\\/person\\\/441c2562293c45fbcf483f246430e6c8\",\"name\":\"Ben Story\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/i0.wp.com\\\/packitforwarding.com\\\/wp-content\\\/uploads\\\/2026\\\/02\\\/cropped-PIF_Logo-Color-Horizontal-Rounded-1.png?fit=489%2C250&ssl=1\",\"url\":\"https:\\\/\\\/i0.wp.com\\\/packitforwarding.com\\\/wp-content\\\/uploads\\\/2026\\\/02\\\/cropped-PIF_Logo-Color-Horizontal-Rounded-1.png?fit=489%2C250&ssl=1\",\"contentUrl\":\"https:\\\/\\\/i0.wp.com\\\/packitforwarding.com\\\/wp-content\\\/uploads\\\/2026\\\/02\\\/cropped-PIF_Logo-Color-Horizontal-Rounded-1.png?fit=489%2C250&ssl=1\",\"width\":489,\"height\":250,\"caption\":\"Ben Story\"},\"logo\":{\"@id\":\"https:\\\/\\\/i0.wp.com\\\/packitforwarding.com\\\/wp-content\\\/uploads\\\/2026\\\/02\\\/cropped-PIF_Logo-Color-Horizontal-Rounded-1.png?fit=489%2C250&ssl=1\"},\"description\":\"In the course of my career, I have had the pleasure of working in multiple verticals including Education, Logistics and Healthcare. Although I started as a systems administrator (aka server jockey), I am now firmly in the network engineering arena. Currently I am working for a multi-state hospital system.\",\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/packitforwarding\",\"https:\\\/\\\/www.linkedin.com\\\/in\\\/benstory\",\"https:\\\/\\\/x.com\\\/https:\\\/\\\/www.twitter.com\\\/ntwrk80\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Captive Portals and Not So Captive Portals -","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/packitforwarding.com\/index.php\/2023\/02\/22\/captive-portal-palo-alto\/","og_locale":"en_US","og_type":"article","og_title":"Captive Portals and Not So Captive Portals -","og_description":"A few years ago as I was first cutting my teeth in the Palo Alto firewall world, I had a customer request something &#8220;unique&#8221; and I created a one-off solution. The request was to have a stand-alone portal that the end-users could go to and log in to gain additional access to resources. The reason [&hellip;]","og_url":"https:\/\/packitforwarding.com\/index.php\/2023\/02\/22\/captive-portal-palo-alto\/","article_publisher":"https:\/\/www.facebook.com\/packitforwarding","article_author":"https:\/\/www.facebook.com\/packitforwarding","article_published_time":"2023-02-22T14:00:00+00:00","og_image":[{"width":1880,"height":1255,"url":"https:\/\/i0.wp.com\/packitforwarding.com\/wp-content\/uploads\/2023\/02\/pexels-photo-12652839.jpeg?fit=1880%2C1255&ssl=1","type":"image\/jpeg"}],"author":"Ben Story","twitter_card":"summary_large_image","twitter_creator":"@https:\/\/www.twitter.com\/ntwrk80","twitter_site":"@ntwrk80","twitter_misc":{"Written by":"Ben Story","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/packitforwarding.com\/index.php\/2023\/02\/22\/captive-portal-palo-alto\/#article","isPartOf":{"@id":"https:\/\/packitforwarding.com\/index.php\/2023\/02\/22\/captive-portal-palo-alto\/"},"author":{"name":"Ben Story","@id":"https:\/\/packitforwarding.com\/#\/schema\/person\/441c2562293c45fbcf483f246430e6c8"},"headline":"Captive Portals and Not So Captive Portals","datePublished":"2023-02-22T14:00:00+00:00","mainEntityOfPage":{"@id":"https:\/\/packitforwarding.com\/index.php\/2023\/02\/22\/captive-portal-palo-alto\/"},"wordCount":662,"commentCount":0,"publisher":{"@id":"https:\/\/packitforwarding.com\/#\/schema\/person\/441c2562293c45fbcf483f246430e6c8"},"image":{"@id":"https:\/\/packitforwarding.com\/index.php\/2023\/02\/22\/captive-portal-palo-alto\/#primaryimage"},"thumbnailUrl":"https:\/\/i0.wp.com\/packitforwarding.com\/wp-content\/uploads\/2023\/02\/pexels-photo-12652839.jpeg?fit=1880%2C1255&ssl=1","keywords":["Palo Alto"],"articleSection":["Blog","Palo Alto"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/packitforwarding.com\/index.php\/2023\/02\/22\/captive-portal-palo-alto\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/packitforwarding.com\/index.php\/2023\/02\/22\/captive-portal-palo-alto\/","url":"https:\/\/packitforwarding.com\/index.php\/2023\/02\/22\/captive-portal-palo-alto\/","name":"Captive Portals and Not So Captive Portals -","isPartOf":{"@id":"https:\/\/packitforwarding.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/packitforwarding.com\/index.php\/2023\/02\/22\/captive-portal-palo-alto\/#primaryimage"},"image":{"@id":"https:\/\/packitforwarding.com\/index.php\/2023\/02\/22\/captive-portal-palo-alto\/#primaryimage"},"thumbnailUrl":"https:\/\/i0.wp.com\/packitforwarding.com\/wp-content\/uploads\/2023\/02\/pexels-photo-12652839.jpeg?fit=1880%2C1255&ssl=1","datePublished":"2023-02-22T14:00:00+00:00","breadcrumb":{"@id":"https:\/\/packitforwarding.com\/index.php\/2023\/02\/22\/captive-portal-palo-alto\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/packitforwarding.com\/index.php\/2023\/02\/22\/captive-portal-palo-alto\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/packitforwarding.com\/index.php\/2023\/02\/22\/captive-portal-palo-alto\/#primaryimage","url":"https:\/\/i0.wp.com\/packitforwarding.com\/wp-content\/uploads\/2023\/02\/pexels-photo-12652839.jpeg?fit=1880%2C1255&ssl=1","contentUrl":"https:\/\/i0.wp.com\/packitforwarding.com\/wp-content\/uploads\/2023\/02\/pexels-photo-12652839.jpeg?fit=1880%2C1255&ssl=1","width":1880,"height":1255,"caption":"Photo by imustbedead on Pexels.com"},{"@type":"BreadcrumbList","@id":"https:\/\/packitforwarding.com\/index.php\/2023\/02\/22\/captive-portal-palo-alto\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/packitforwarding.com\/"},{"@type":"ListItem","position":2,"name":"Captive Portals and Not So Captive Portals"}]},{"@type":"WebSite","@id":"https:\/\/packitforwarding.com\/#website","url":"https:\/\/packitforwarding.com\/","name":"","description":"Paying it forward to the next generation of IT.","publisher":{"@id":"https:\/\/packitforwarding.com\/#\/schema\/person\/441c2562293c45fbcf483f246430e6c8"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/packitforwarding.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":["Person","Organization"],"@id":"https:\/\/packitforwarding.com\/#\/schema\/person\/441c2562293c45fbcf483f246430e6c8","name":"Ben Story","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/i0.wp.com\/packitforwarding.com\/wp-content\/uploads\/2026\/02\/cropped-PIF_Logo-Color-Horizontal-Rounded-1.png?fit=489%2C250&ssl=1","url":"https:\/\/i0.wp.com\/packitforwarding.com\/wp-content\/uploads\/2026\/02\/cropped-PIF_Logo-Color-Horizontal-Rounded-1.png?fit=489%2C250&ssl=1","contentUrl":"https:\/\/i0.wp.com\/packitforwarding.com\/wp-content\/uploads\/2026\/02\/cropped-PIF_Logo-Color-Horizontal-Rounded-1.png?fit=489%2C250&ssl=1","width":489,"height":250,"caption":"Ben Story"},"logo":{"@id":"https:\/\/i0.wp.com\/packitforwarding.com\/wp-content\/uploads\/2026\/02\/cropped-PIF_Logo-Color-Horizontal-Rounded-1.png?fit=489%2C250&ssl=1"},"description":"In the course of my career, I have had the pleasure of working in multiple verticals including Education, Logistics and Healthcare. Although I started as a systems administrator (aka server jockey), I am now firmly in the network engineering arena. Currently I am working for a multi-state hospital system.","sameAs":["https:\/\/www.facebook.com\/packitforwarding","https:\/\/www.linkedin.com\/in\/benstory","https:\/\/x.com\/https:\/\/www.twitter.com\/ntwrk80"]}]}},"jetpack_publicize_connections":[],"jetpack_featured_media_url":"https:\/\/i0.wp.com\/packitforwarding.com\/wp-content\/uploads\/2023\/02\/pexels-photo-12652839.jpeg?fit=1880%2C1255&ssl=1","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/pay9MD-q5","jetpack-related-posts":[{"id":1300,"url":"https:\/\/packitforwarding.com\/index.php\/2021\/02\/12\/pcnsa-1-2\/","url_meta":{"origin":1617,"position":0},"title":"PCNSA &#8211; 1.2","author":"Ben Story","date":"February 12, 2021","format":false,"excerpt":"Identify the components and operation of Single-Pass ParallelProcessing architecture.Palo Alto PCNSA Study Guide v10 Single-Pass Parallel Processing The Palo Alto firewalls use a single-pass parallel processing architecture. It combines single-pass software with parallel processing hardware. The goal is to \"scan it all, scan it once.\" The software uses stream processing.\u2026","rel":"","context":"In &quot;Blog&quot;","block_context":{"text":"Blog","link":"https:\/\/packitforwarding.com\/index.php\/category\/blog\/"},"img":{"alt_text":"Security","src":"https:\/\/i0.wp.com\/packitforwarding.com\/wp-content\/uploads\/2018\/07\/security-protection-anti-virus-software-60504.jpeg?fit=1200%2C800&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/packitforwarding.com\/wp-content\/uploads\/2018\/07\/security-protection-anti-virus-software-60504.jpeg?fit=1200%2C800&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/packitforwarding.com\/wp-content\/uploads\/2018\/07\/security-protection-anti-virus-software-60504.jpeg?fit=1200%2C800&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/packitforwarding.com\/wp-content\/uploads\/2018\/07\/security-protection-anti-virus-software-60504.jpeg?fit=1200%2C800&ssl=1&resize=700%2C400 2x, https:\/\/i0.wp.com\/packitforwarding.com\/wp-content\/uploads\/2018\/07\/security-protection-anti-virus-software-60504.jpeg?fit=1200%2C800&ssl=1&resize=1050%2C600 3x"},"classes":[]},{"id":1329,"url":"https:\/\/packitforwarding.com\/index.php\/2021\/03\/12\/pcnsa-2-5\/","url_meta":{"origin":1617,"position":1},"title":"PCNSA 2.5","author":"Ben Story","date":"March 12, 2021","format":false,"excerpt":"Given a network diagram, create the appropriate security zones.Palo Alto Networks PCNSA Study Guide v10 Palo Alto firewalls use security zones to define where traffic is analyzed, controlled and logged. Zones logically group networks. Example zones are Outside, VPN, Infrastructure, Users, Extranet, Partners and Data Center. Security zones are either\u2026","rel":"","context":"In &quot;Blog&quot;","block_context":{"text":"Blog","link":"https:\/\/packitforwarding.com\/index.php\/category\/blog\/"},"img":{"alt_text":"Photo by Engin Akyurt from Pexels","src":"https:\/\/i0.wp.com\/packitforwarding.com\/wp-content\/uploads\/2019\/01\/pexels-photo-1552617.jpeg?fit=640%2C426&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/packitforwarding.com\/wp-content\/uploads\/2019\/01\/pexels-photo-1552617.jpeg?fit=640%2C426&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/packitforwarding.com\/wp-content\/uploads\/2019\/01\/pexels-photo-1552617.jpeg?fit=640%2C426&ssl=1&resize=525%2C300 1.5x"},"classes":[]},{"id":1342,"url":"https:\/\/packitforwarding.com\/index.php\/2021\/04\/05\/pcnsa-2-9\/","url_meta":{"origin":1617,"position":2},"title":"PCNSA 2.9","author":"Ben Story","date":"April 5, 2021","format":false,"excerpt":"Identify and configure Security policy match conditions, actions, and logging options.Palo Alto Networks PCNSA Study Guide v10 Implicit vs Explicit The two predefined interzone and intrazone rules are the only implicit rules on a Palo Alto firewall. Explicit rules are defined by an administrator and always are before the implicit\u2026","rel":"","context":"In &quot;Blog&quot;","block_context":{"text":"Blog","link":"https:\/\/packitforwarding.com\/index.php\/category\/blog\/"},"img":{"alt_text":"adult american football athlete audience","src":"https:\/\/i0.wp.com\/packitforwarding.com\/wp-content\/uploads\/2021\/03\/pexels-photo-209954.jpeg?fit=1200%2C800&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/packitforwarding.com\/wp-content\/uploads\/2021\/03\/pexels-photo-209954.jpeg?fit=1200%2C800&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/packitforwarding.com\/wp-content\/uploads\/2021\/03\/pexels-photo-209954.jpeg?fit=1200%2C800&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/packitforwarding.com\/wp-content\/uploads\/2021\/03\/pexels-photo-209954.jpeg?fit=1200%2C800&ssl=1&resize=700%2C400 2x, https:\/\/i0.wp.com\/packitforwarding.com\/wp-content\/uploads\/2021\/03\/pexels-photo-209954.jpeg?fit=1200%2C800&ssl=1&resize=1050%2C600 3x"},"classes":[]},{"id":1319,"url":"https:\/\/packitforwarding.com\/index.php\/2021\/03\/01\/pcnsa-2-2\/","url_meta":{"origin":1617,"position":3},"title":"PCNSA 2.2","author":"Ben Story","date":"March 1, 2021","format":false,"excerpt":"Identify how to manage firewall configurations.Palo Alto Networks PCNSA Study Guide v10 Manage Configurations Using Candidate and Running Configurations Candidate Configurations: All changes to a firewall are made to a candidate configuration. This resides in memory on the control plane. A commit activates this configuration into the running configuration on\u2026","rel":"","context":"In &quot;Certification&quot;","block_context":{"text":"Certification","link":"https:\/\/packitforwarding.com\/index.php\/category\/certification\/"},"img":{"alt_text":"gray metal cubes decorative","src":"https:\/\/i0.wp.com\/packitforwarding.com\/wp-content\/uploads\/2021\/03\/pexels-photo-1005644.jpeg?fit=900%2C1200&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/packitforwarding.com\/wp-content\/uploads\/2021\/03\/pexels-photo-1005644.jpeg?fit=900%2C1200&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/packitforwarding.com\/wp-content\/uploads\/2021\/03\/pexels-photo-1005644.jpeg?fit=900%2C1200&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/packitforwarding.com\/wp-content\/uploads\/2021\/03\/pexels-photo-1005644.jpeg?fit=900%2C1200&ssl=1&resize=700%2C400 2x"},"classes":[]},{"id":1335,"url":"https:\/\/packitforwarding.com\/index.php\/2021\/03\/29\/pcnsa-2-7\/","url_meta":{"origin":1617,"position":4},"title":"PCNSA &#8211; 2.7","author":"Ben Story","date":"March 29, 2021","format":false,"excerpt":"Given a scenario, identify steps to create and configure a virtual router.Palo Alto Networks PCNSA Study Guide v10 Virtual Routers PAN-OS has two types of virtual route engines. The first is the BGP route engine. It ONLY supports BGP and static routing. It can be found on the PA-7000, PA-5200,\u2026","rel":"","context":"In &quot;Blog&quot;","block_context":{"text":"Blog","link":"https:\/\/packitforwarding.com\/index.php\/category\/blog\/"},"img":{"alt_text":"sign arrow direction travel","src":"https:\/\/i0.wp.com\/packitforwarding.com\/wp-content\/uploads\/2021\/03\/sign-places-travel-information-52526.jpeg?fit=806%2C1200&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/packitforwarding.com\/wp-content\/uploads\/2021\/03\/sign-places-travel-information-52526.jpeg?fit=806%2C1200&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/packitforwarding.com\/wp-content\/uploads\/2021\/03\/sign-places-travel-information-52526.jpeg?fit=806%2C1200&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/packitforwarding.com\/wp-content\/uploads\/2021\/03\/sign-places-travel-information-52526.jpeg?fit=806%2C1200&ssl=1&resize=700%2C400 2x"},"classes":[]},{"id":1322,"url":"https:\/\/packitforwarding.com\/index.php\/2021\/03\/05\/pcnsa-2-3\/","url_meta":{"origin":1617,"position":5},"title":"PCNSA 2.3","author":"Ben Story","date":"March 5, 2021","format":false,"excerpt":"Identify and schedule dynamic updates.Palo Alto Networks PCNSA Study Guide v10 Dynamic Updates Antivirus Includes signatures as well as WildFire signatures and C2 signatures. WildFire signatures are based on malware first seen by other firewalls around the world. New antivirus signatures are published daily and require a Threat Prevention subscription.\u2026","rel":"","context":"In &quot;Certification&quot;","block_context":{"text":"Certification","link":"https:\/\/packitforwarding.com\/index.php\/category\/certification\/"},"img":{"alt_text":"update lettering text on black background","src":"https:\/\/i0.wp.com\/packitforwarding.com\/wp-content\/uploads\/2021\/02\/pexels-photo-5697254.jpeg?fit=1200%2C800&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/packitforwarding.com\/wp-content\/uploads\/2021\/02\/pexels-photo-5697254.jpeg?fit=1200%2C800&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/packitforwarding.com\/wp-content\/uploads\/2021\/02\/pexels-photo-5697254.jpeg?fit=1200%2C800&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/packitforwarding.com\/wp-content\/uploads\/2021\/02\/pexels-photo-5697254.jpeg?fit=1200%2C800&ssl=1&resize=700%2C400 2x, https:\/\/i0.wp.com\/packitforwarding.com\/wp-content\/uploads\/2021\/02\/pexels-photo-5697254.jpeg?fit=1200%2C800&ssl=1&resize=1050%2C600 3x"},"classes":[]}],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/packitforwarding.com\/index.php\/wp-json\/wp\/v2\/posts\/1617","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/packitforwarding.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/packitforwarding.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/packitforwarding.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/packitforwarding.com\/index.php\/wp-json\/wp\/v2\/comments?post=1617"}],"version-history":[{"count":1,"href":"https:\/\/packitforwarding.com\/index.php\/wp-json\/wp\/v2\/posts\/1617\/revisions"}],"predecessor-version":[{"id":1620,"href":"https:\/\/packitforwarding.com\/index.php\/wp-json\/wp\/v2\/posts\/1617\/revisions\/1620"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/packitforwarding.com\/index.php\/wp-json\/wp\/v2\/media\/1619"}],"wp:attachment":[{"href":"https:\/\/packitforwarding.com\/index.php\/wp-json\/wp\/v2\/media?parent=1617"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/packitforwarding.com\/index.php\/wp-json\/wp\/v2\/categories?post=1617"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/packitforwarding.com\/index.php\/wp-json\/wp\/v2\/tags?post=1617"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}