Palo Alto 防火墙安全配置指南,其中有很对有使用的最佳实践。 Table of Contents Overview .................................................................................................................................................................. 7 Intended Audience ........................................................................................................................................... 7 Consensus Guidance ........................................................................................................................................ 7 Typographical Conventions ......................................................................................................................... 8 Scoring Information ........................................................................................................................................ 8 Profile Definitions ............................................................................................................................................ 9 Acknowledgements ...................................................................................................................................... 10 Recommendations ............................................................................................................................................. 11 1 Device Setup ................................................................................................................................................ 11 1.1 General Settings ................................................................................................................................. 12 1.1.1 Ensure 'Login Banner' is set (Scored) ............................................................................... 12 1.1.2 Ensure 'Enable Log on High DP Load' is enabled (Scored)....................................... 13 1.2 Management Interface Settings ................................................................................................... 14 1.2.1 Ensure 'Permitted IP Addresses' is set to those necessary for device management (Scored) ........................................................................................................................ 14 1.2.2 Ensure 'Permitted IP Addresses' is set for all management profiles where SSH, HTTPS, or SNMP is enabled (Scored) ........................................................................................... 16 1.2.3 Ensure HTTP and Telnet options are disabled for the Management Interface (Scored) ................................................................................................................................................... 18 1.2.4 Ensure valid certificate is set for browser-based administrator interface (Not Scored) ..................................................................................................................................................... 20 1.3 Minimum Password Requirements ............................................................................................ 22 1.3.1 Ensure 'Minimum Password Complexity' is enabled (Scored) ............................... 22 1.3.2 Ensure 'Minimum Length' is greater than or equal to 12 (Scored) ....................... 24 1.3.3 Ensure 'Prevent Password Reuse Limit' is set to 24 or more passwords (Scored) ................................................................................................................................................... 26 1.3.4 Ensure 'Required Password Change Period' is less than or equal to 90 days (Scored) ................................................................................................................................................... 28
剩余142页未读,继续阅读
- 粉丝: 2
- 资源: 15
- 我的内容管理 展开
- 我的资源 快来上传第一个资源
- 我的收益 登录查看自己的收益
- 我的积分 登录查看自己的积分
- 我的C币 登录后查看C币余额
- 我的收藏
- 我的下载
- 下载帮助
最新资源
- 一对一MybatisProgram.zip
- 时变动态分位数CoVaR、delta-CoVaR,分位数回归 △CoVaR测度 溢出效应 动态 Adrian2016基于分位数回归方法计算动态条件在险价值 R语言代码,代码更数据就能用,需要修改的
- 人物检测37-YOLO(v5至v11)、COCO、CreateML、Paligemma、TFRecord、VOC数据集合集.rar
- 人物检测26-YOLO(v5至v11)、COCO、CreateML、Paligemma、TFRecord、VOC数据集合集.rar
- 人和箱子检测2-YOLO(v5至v11)、COCO、CreateML、Paligemma、TFRecord、VOC数据集合集.rar
- 清华大学2022年秋季学期 高等数值分析课程报告
- GEE错误集-Cannot add an object of type <Element> to the map. Might be fixable with an explicit .pdf
- 清华大学2022年秋季学期 高等数值分析课程报告
- 矩阵与线程的对应关系图
- 人体人员检测46-YOLO(v5至v9)、COCO、Darknet、TFRecord数据集合集.rar