PANW-AG-000105 - The Palo Alto Networks security platform must use a Vulnerability Protection Profile that blocks any critical, high, or medium threats.

Information

If the network does not provide safeguards against DoS attacks, network resources may be unavailable to users.

Installation of content filtering gateways and application-layer firewalls at key boundaries in the architecture mitigates the risk of DoS attacks. These attacks can be detected by matching observed communications traffic with patterns of known attacks and monitoring for anomalies in traffic volume, type, or protocol usage.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

To add a Vulnerability Protection Profile:
Go to Objects >> Security Profiles >> Vulnerability Protection
Select 'Add'.
In the 'Vulnerability Protection Profile' window, complete the required fields.
In the 'Name' field, enter the name of the Vulnerability Protection Profile.
In the 'Description' field, enter the description of the Vulnerability Protection Profile.
In the 'Rules' tab, select 'Add'.
In the 'Vulnerability Protection Rule' window,
In the 'Rule Name' field, enter the Rule name,
In the 'Threat Name' field, enter 'any' (this will match all signatures),
In the 'Action' field, select 'block'.
In the 'Host type' field, select 'any',
Select the checkboxes above the 'CVE' and 'Vendor ID' boxes.
In the 'Severity' section, select the 'critical', 'high', and 'medium' check boxes.
Select 'OK'.

In the 'Vulnerability Protection Profile' window, select the configured rule, then select 'OK'.
Use the Profile in a Security Policy:
Go to Policies >> Security
Select an existing policy rule or select 'Add' to create a new one.
In the 'Actions' tab in the 'Profile Setting' section; in the 'Profile Type' field, select 'Profiles'. The window will change to display the different categories of Profiles.
In the 'Actions' tab in the 'Profile Setting' section; in the 'Vulnerability Protection' field, select the configured Vulnerability Protection Profile.
Select 'OK'.
Commit changes by selecting 'Commit' in the upper-right corner of the screen.
Select 'OK' when the confirmation dialog appears.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_PAN_Y24M10_STIG.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-5, CAT|II, CCI|CCI-002385, Rule-ID|SV-228861r831603_rule, STIG-ID|PANW-AG-000105, STIG-Legacy|SV-77093, STIG-Legacy|V-62603, Vuln-ID|V-228861

Plugin: Palo_Alto

Control ID: 71ddff9e69c09ef99efd45e9acf0011a9482a1604ef271fd5fb9dfa2a65450c5