Skip to content

Commit 9cb2666

Browse files
authored
Merge pull request #793 from crowdsecurity/hes/integrations_update-paloalto-doc
update paloalto integration doc
2 parents 07fa06e + 1c43ebe commit 9cb2666

File tree

8 files changed

+52
-5
lines changed

8 files changed

+52
-5
lines changed
400 KB
Loading
175 KB
Loading
316 KB
Loading
167 KB
Loading
242 KB
Loading
218 KB
Loading
378 KB
Loading

crowdsec-docs/unversioned/integrations/paloalto.mdx

Lines changed: 52 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -3,8 +3,8 @@ id: paloalto
33
title: Palo Alto
44
---
55

6-
import ThemedImage from "@theme/ThemedImage";
7-
import useBaseUrl from "@docusaurus/useBaseUrl";
6+
import ThemedImage from "@theme/ThemedImage"
7+
import useBaseUrl from "@docusaurus/useBaseUrl"
88

99
The CrowdSec Palo Alto integration allows you to block malicious IPs in your Palo Alto firewall. This guide will walk you through the steps to integrate CrowdSec blocklists with your Palo Alto firewall.
1010

@@ -43,11 +43,58 @@ Once the integration is generated you will be presented with a credentials scree
4343
<ThemedImage
4444
alt="Palo Alto Integration Credentials Screen"
4545
sources={{
46-
light: useBaseUrl("/img/console_integrations_paloalto_credentials_light.png"),
47-
dark: useBaseUrl("/img/console_integrations_paloalto_credentials_dark.png"),
46+
light: useBaseUrl(
47+
"/img/console_integrations_paloalto_credentials_light.png"
48+
),
49+
dark: useBaseUrl(
50+
"/img/console_integrations_paloalto_credentials_dark.png"
51+
),
4852
}}
4953
/>
5054

55+
## Palo Alto Configuration
56+
57+
To configure the paloalto firewall, we will:
58+
59+
1. Create External dynamic list and choose your update frequency.
60+
61+
Go to Objects > External Dynamic Lists > Add
62+
63+
![](/img/paloalto_step1.png)
64+
65+
:::info
66+
You need to put the username and password provided by the console in the "URL" so it can use basic authentication:
67+
68+
```
69+
https://<username>:<password>@admin.api.crowdsec.net/v1/integrations/<integration_id>/content
70+
```
71+
72+
:::
73+
74+
![](/img/paloalto_step2.png)
75+
76+
2. Create a security policy with this dynamic list
77+
78+
Go to Policies > Security > Add
79+
80+
![](/img/paloalto_step3.png)
81+
82+
In General tab, add the general info about the policy.
83+
84+
![](/img/paloalto_step4.png)
85+
86+
In Source tab, select your source zone then the dynamic list created in the source address.
87+
88+
![](/img/paloalto_step5.png)
89+
90+
In Actions tab, select the action ‘Drop‘ and log the action (recommended).
91+
92+
![](/img/paloalto_step6.png)
93+
94+
You should have your policy created, don't forget to click on ‘commit‘.
95+
96+
![](/img/paloalto_step7.png)
97+
5198
[Palo Alto Documentation](https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-admin/policy/use-an-external-dynamic-list-in-policy/external-dynamic-list#idf36cb80a-77f1-4d17-9c4b-7efe9fe426af)
5299
[Video Tutorial](https://www.youtube.com/watch?v=QFVI4sOFoaI)
53100

@@ -66,4 +113,4 @@ Since CrowdSec is a community-driven project, we welcome contributions to this d
66113

67114
## Next Steps
68115

69-
Now that you have integrated CrowdSec integration with your Palo Alto Firewall, you can proceed to the [Blocklist Catalog](console/blocklists/catalog.md) to find what blocklists you can subscribe too.
116+
Now that you have integrated CrowdSec integration with your Palo Alto Firewall, you can proceed to the [Blocklist Catalog](console/blocklists/catalog.md) to find what blocklists you can subscribe too.

0 commit comments

Comments
 (0)