← Back to Book Detail

Chapter 3. Advanced Networking (8/7) -- Palo Alto Firewall

Browse
114%

Chapter 3. Advanced Networking

Chapter 3. Advanced Networking 3.1 Captive Portal Learning Objectives - Configure VLANs - Configure captive portal Prerequisites: - Setup Zones - Some interface configuration - Configuring VLANs on the GNS3 switch - Knowledge of previous labs Scenario: Now let’s push for some advanced networking configurations. Sometimes you just have to push departments into their own VLANs for organization and compliance. Say we have a guest and employee network. We want to prevent communication between the two as much as possible. We would also want to implement some sort of login to access the internet for guests, much like hotels. | Device | Configuration | |---|---| | PaloAlto-1 | management: <IP_ADDRESS>/24 Ethernet1/1: Trunking Ethernet1/1.10: <IP_ADDRESS>/24 Ethernet1/1.20: <IP_ADDRESS>/24 Ethernet1/2: DHCP | | VLAN-10 | eth0: <IP_ADDRESS>/24 GW: <IP_ADDRESS> DNS: <IP_ADDRESS> | | VLAN-20 | eth0: <IP_ADDRESS>/24 GW: <IP_ADDRESS> DNS: <IP_ADDRESS> | | Management | eth0: <IP_ADDRESS>/24 | | Switchy | e0: Access mode, VLAN 10 e1: Access mode, VLAN 20 e7: dot1q, VLAN 1 | | Zone | Interface | |---|---| | VLAN10 | Ethernet1/1.10 | | VLAN20 | Ethernet1/1.20 | | Outside | Ethernet1/2 | Configure Sub Interfaces Under Network > Interfaces. Click on ethernet1/1. In this window, we just want to set the interface type to layer 3. Then press OK. Now while ethernet1/1 is still selected, click on add sub interface. We want to add 2 sub-interfaces. Here is what you should configure: | Interface | Configuration | |---|---| | Ethernet1/1.10 | Interface Name: 10 Tag: 10 Config tab: – Virtual Router: default – Security Zone: VLAN10 IPv4: – Type: Static – IP: <IP_ADDRESS>/24 | | Ethernet1/1.20 | Interface Name: 20 Tag: 20 Config tab: – Virtual Router: default – Security Zone: VLAN20 IPv4: – Type: Static – IP: <IP_ADDRESS>/24 | Semi-Advanced Security Policies Well, it’s not really advanced, but under Policies > Security, click Add. We will be making a policy to allow VLAN10 and VLAN20 into the Outside zone. We can do this by adding multiple zones under the source zone. Then click OK. Semi-Advanced NAT Policies Still not really advanced. But under Policies > NAT, click Add. We want to make a Static NAT policy for the Internet connectivity. But under the Original Packet tab, we can select multiple zones. Configure the rest for static NAT, then press OK. Add a User Under Device > Local User Database > Users. Click Add. Create any user you want with a username and password. Here is an example: Then click OK. Create an Authentication Profile Under Device > Authentication Profile, click Add. Under the Authentication tab, change the type to Local Database. Under the Advanced tab, add your user. Then press OK. Configure the Captive Portal Under Device, User Identification in the Authentication Portal Settings tab, click the settings icon. Configure these settings: | Parameter | Value | |---|---| | Enable Authentication Portal | Tick this box | | Authentication Profile | Select the one
← Previous Chapter Next Chapter →