Overview
Join Keith Barker as he describes and demonstrates setting up a Palo Alto firewall lab using an ESXi host from VMware.
Recommended Experience
- 1 to 2 years of network security of cybersecurity experience
Related Job Functions
- Security Analyst
- Cybersecurity Professional
- Security Engineer
Keith discovered a love for computers and networking in 1984 and began his IT career in 1985. He specializes in networking and security.
Intro to Building a Lab using ESXi
Keith introduces this set of videos.
ESXi Based Lab Overview
Keith presents an overview of building a Palo Alto firewall lab.
Knowledge Check
Which vendor's hypervisor is used in the lab?
Deploy the Firewall VM
Keith demonstrates the initial deployment of a Palo Alto VM on an ESXi hypervisor.
Knowledge Check
What is the best source to download a VM image for a Palo Alto firewall?
ESXi Networking
Keith explains the ESXi networking components used for the lab.
Knowledge Check
In the ESXi networking environment, which virtual switch has the port groups for both VLAN 10 and 20?
Lab Routing with Vyos
Keith shows the role and configuration of the lab router in the topology.
Knowledge Check
In the lab, which vendor's device is performing the routing services as a pseudo ISP at 23.1.2.1?
Setting up Basic FW Management
Keith demonstrates setting up the basic firewall management on the Palo Alto firewall VM.
Knowledge Check
What is the configured management IP address on the Palo Alto VM?
Configure L3 Zones, Virtual Routers, and Interfaces
Keith demonstrates configuring L3 zones, routing, and virtual interfaces.
Knowledge Check
When configuring the L3 interfaces on the Palo Alto device, which settings were configured on the interfaces? (Choose three)
LAB Clients and Servers
Keith demonstrates the use of client and server VMs in the lab environment.
Knowledge Check
In the lab, which subnet is the Windows computer in?
Conclusion
I hope this has been informative for you and I would like to thank you for consuming.
View Transcript
Intro to Building a Lab using ESXi
0:00[AUDIO LOGO]
0:07Hello, and welcome.
0:09My name is Keith Barker, and if we
0:11look at the recipe and all the ingredients
0:13for getting really good at something,
0:14one of those key ingredients is going to be hands-on practice.
0:17So in this set of videos, here's what I'd love to do.
0:20I'd love to chat with you about a few options for building
0:22a home-office lab so you can build one and then
0:25actually get hands-on practice with the Palo Alto Firewall.
0:27And then let's put a game plan together,
0:29and I'll walk you through step by step
0:31with one example of building such
0:33a lab in this set of videos.
0:34So if you're ready, I'm ready.
0:36I'll see you, my friend, in the very next video
0:38for the big-picture overview of building our lab.
ESXi Based Lab Overview
0:06In this video, you and I get to take a big picture look
0:08at a few of our options regarding
0:10creating a lab environment so we can get hands-on practice.
0:13And the two big options we have regarding getting hands
0:15on practice is use physical gear.
0:17So in the old days, they had this little, teeny baby bear
0:20unit called the PA-200, that's end of life,
0:22and then they came out with a PA-220, and that was OK.
0:26It was all right.
0:27It took maybe five or six minutes
0:30to do a commit sometimes, and if we rebooted it,
0:32it might take 15 minutes.
0:33Now, the good news, as of 2023, the PA-220 is now end of life,
0:37and so they have a PA-400 series,
0:39and the model I specifically like for a lab unit is the 440.
0:43There's a 410, but it doesn't do local logging,
0:46so if you want logging, if that's
0:48important to you in a lab environment,
0:49you definitely want to go ahead and get the PA-440.
0:52So you'd purchase the hardware, and also, they
0:54have a lab license that's good for one year
0:56to give you all the bells and whistles
0:58and features on the next generation firewall.
1:00So this is the PA-220 unit.
1:02There's the transformer.
1:04It plugs in on the back, and here's
1:05the front side of the PA-220.
1:07So with the PA-220, it was good in this day,
1:10but again, it takes a while for a commit,
1:12so it takes longer to reboot.
1:13And so the new models, the 400s, are a great answer
1:16for a home lab environment.
1:18So I've got a couple coming in, and once they arrive,
1:20I'll show those to you on camera as well.
1:22Now, in addition to the hardware,
1:23you also need to purchase an A license.
1:25So there's a special lab license that
1:27goes with the PA 400 series, and it's good for a year.
1:30So you want to have the hardware in place
1:31and also the lab license so you can use and practice
1:35with the features.
1:35Now, in the event that you have, either a physical appliance,
1:38but you don't have the license, there
1:41are still about 30% to 40% of the hands-on practice
1:45you can get even on a device that
1:47doesn't have a license for the next generation firewall.
1:49And that way, you can practice the basics
1:51like setting up permissions and security policies
1:55and address translation and routing, and so forth.
1:57However, without the license in place,
1:59you won't be able to do the advanced firewall
2:01features, such as things like threat prevention
2:03and antivirus and anti-malware and so forth.
2:06So now, let's turn our attention from physical gear
2:08to our options, regarding virtual.
2:11And there's a few options here.
2:12One is we could go ahead and we could rent the actual services
2:16of a Palo Alto firewall in the cloud,
2:18with a pay-as-you-go model, which is one of the options
2:21for our cloud providers, including from AWS.
2:23So in AWS, Amazon Web Services, we
2:26could go there, go to the marketplace,
2:28and actually, rent a virtual machine in AWS
2:32that we could use as our firewall.
2:34And let me show you what that looks like.
2:35So this is AWS Marketplace.
2:37I'm currently logged in to AWS, and in AWS Marketplace,
2:40we can do a search for Palo, press Enter,
2:42and there's a whole bunch of options regarding Palo Alto
2:44services.
2:45So here's one for Panorama.
2:47This one right here is the VM series
2:50next-generation firewall, BYOL, that's bring your own license,
2:53or you can purchase bundle 2, or bundle 3,
2:56and that has a license included in it.
2:59You're basically renting the services, including the license
3:02services through the VM, and they have a 15-day free trial
3:06if you want to set that up.
3:07However, I will warn you that if you have absolutely zero
3:10experience with AWS and security groups and connectivity,
3:13there may be a slight learning curve on the AWS side of it
3:17to get full access and functionality
3:19into your virtual machine.
3:20However, if you do have some AWS experience,
3:22it's a fantastic option for spitting up a firewall up
3:25in the cloud at AWS.
3:27Another option would be to spin up the firewall
3:29as a virtual machine on prem.
3:31So we could use something like VMware's ESXi,
3:34or if you use VMware's Fusion or VMware
3:37Workstation or a hypervisor from Microsoft, such as hyper-v,
3:41or you can even use tools like EVE-NG and GNS3.
3:45But once again, just remember that if you
3:47don't have the actual licenses for the VM,
3:49you can still get the VM up and running
3:52and set up the basic functionality
3:53for a stateful firewall.
3:54However, you won't be able to practice
3:56with any of the advanced features such as threat
3:58prevention and antivirus and anti-malware and so forth.
4:01So if we're going to implement the firewall as a VM in our lab
4:04environment, one of those options, as I mentioned,
4:06is use a VMware products, including ESXi.
4:09So let me clear this up, and let's
4:10do a rough draft regarding what a lab environment can
4:13look like leveraging ESXi.
4:15So let's imagine that this represents the ESXi
4:18host, a physical piece of hardware that's
4:21running the ESXi hypervisor from VMware.
4:24So I'll go ahead and label that, ESXi.
4:27And currently, behind me in my rack,
4:29I've got a few Dell server blades,
4:31which are all running ESXi.
4:33So we could place the Palo Alto firewall as a VM
4:36that's running inside of the ESXi hypervisor.
4:38Now, the question may be, well, if we're
4:40running this firewall as a VM, how
4:41does it interact with the rest of the world,
4:43and how do we actually make it perform
4:45like a traditional firewall would?
4:47Because at the moment, it's just stuck inside
4:49of this ESXi hypervisor.
4:50So here is the solution to that.
4:52What we can do is we can have some switches,
4:54some virtual switches inside of our hypervisor.
4:57So I'm going to go ahead and draw two of them,
4:59and I'm going to call this switch right
5:00here the management switch, which is going to be supporting
5:02our untagged traffic.
5:04Think of it like VLAN 1, the native VLAN.
5:06And over here, let's go ahead and use another virtual switch
5:09and make it our trunk switch.
5:11So anything that we're connecting to the trunk can
5:13support 802.1Q tags.
5:14So in an ESXi environment with virtual switches,
5:17each of the switches can have one or more port groups.
5:20And so here's the little port group right there.
5:22I'll put that in blue.
5:24I'll put another little port group right here in pink.
5:26I'll put another little port group here in green.
5:29And we can associate each of these port groups
5:30with a separate VLAN.
5:32So I'll have this little blue port group associated
5:34with VLAN 10, and I'll have the little pink port group
5:37here associated with VLAN 20.
5:39And for grins, I'll take this third one,
5:41and I'll make it associated with VLAN 30.
5:42So if we have VMs like this firewall or any other VMs that
5:45are running and we want them to have connectivity
5:47into VLAN 10 or 20 or 30, we can simply connect them
5:50to the respective port group.
5:52And over here, I've got one giant port group that
5:54represents, effectively, VLAN 1, the native VLAN with no 802.1Q
5:59tracking.
5:59So if we want to have connectivity
6:01between our firewall and VLAN 10,
6:03we can go ahead and take one of its logical network
6:06interface cards-- let's go and take the virtual NIC 1/1,
6:10and logically associate it with this port group right here,
6:13and boom, it's now directly connected
6:14to VLAN 10 off that 1/1 interface.
6:17We can do it also with another interface.
6:19Let's take 1/2, and we get associate
6:21that over here with the port group
6:23that's supporting VLAN 20.
6:24And the same thing for 1/3, we can go ahead and logically
6:29associate that with the port group associated with VLAN 30,
6:31and then this firewall is now directly connected
6:35to each of those three VLANs.
6:36And let me also create another port group right here,
6:39and I'll go ahead and say this one is associated with VLAN 23.
6:42In my lab environment, I'm using VLAN 23 as a logical connection
6:46to the internet.
6:47So if we wanted this firewall to have connectivity to that VLAN
6:50as well, we could take another interface.
6:52Let's go ahead and use 1/6.
6:53And we can associate that with this port group,
6:56and boom, now, we have connectivity to these three
6:58VLANs, which could be internal networks or maybe
7:01two internal networks and a DMZ as well as
7:04the VLAN that leads out to our service
7:05provider for outside access.
7:06Also, on the firewalls, they're also
7:08going to have a ethernet management interface.
7:10So on a physical firewall, that would be a physical port,
7:13and on a virtual machine, it'd be a logical port
7:16being used for management.
7:17And if we want to manage this firewall,
7:19let's say we want to manage it from our management network,
7:21we can go ahead and take that management interface
7:23and connect it over here, associate
7:24with a port group that's connected to our management
7:27network.
7:27So if we have some clients, let's imagine
7:29we have a Linux client, we can go ahead
7:31and associate its network interface card
7:33with this port group, which would put it also into VLAN 10.
7:36And if we have a Windows computer
7:38right there, we could associate this network interface card
7:41with VLAN 20, that port group, and any traffic
7:44from these clients going out to the internet
7:46would have to go through the firewall
7:47in order to get there, which would also require us to set up
7:50the appropriate network address translation and permissions
7:53and security policies here at the firewall.
7:55Now, as far is really getting to the internet,
7:58I've also got a little router--
8:00I'll go ahead and label it R right here for router.
8:02And that little virtual router is
8:03connected to VLAN 23 as well.
8:06So this is acting as our ISP, and its IP address is 23.1.2.1.
8:11That's connected back to this network.
8:13So my management network is 192.168.1.0,
8:17and I've got a physical router on my network here
8:20at 192.168.1.1.
8:24So the question may be, well, how
8:25does this little virtual router in your network, that's
8:27at 23.1.2.1, how does it actually
8:29get out to the real internet through this router?
8:31So we'll call this guy R1, and I'll call this guy R2.
8:34And the secret to that is I've got connectivity
8:36between this virtual switch here in my ESXi environment
8:39out to a physical switch.
8:41And this network interface here is
8:43one of the physical interfaces on the ESXi host
8:46that's logically connected to this management switch inside
8:49and physically connected through its physical interface
8:51to a physical switch on the outside.
8:53So it's connected here on a physical port.
8:55I also have my real router also on that same switch,
8:58and then this router has another connection
9:00out to the public internet.
9:02So from the firewall's perspective,
9:03it just thinks that, hey, it's the default route,
9:06and it's the next hop of 23.1.2.1 will get me there.
9:08This router is actually doing a little bit
9:10of network address translation trickery, forwarding it over
9:13to the 192.168.1 network, with the next hop of 192.168.1.1.
9:18And then this router is also doing address translation
9:21before forwarding that traffic out to the public internet.
9:23So there's a couple of layers of net here
9:25that's happening behind the scenes,
9:27but it's all to provide an environment that
9:28looks and feels just like a normal network would.
9:31With clients in separate VLANs, the firewall
9:34being the default gateway for those clients,
9:36then having the firewall policies and the routing
9:39and the net and everything else set up here at the firewall
9:41to allow that traffic to go out to the internet.
9:43So effectively here at this router,
9:45we're doing port address translation to whatever
9:47its egress or outbound interface is,
9:49and we're also doing PAT here at this router, router 2,
9:52swapping out the source IP addresses that
9:54are coming in with whatever the egress interface
9:57address is here on this router.
9:59So this is the nuts and bolts of how the physical connections
10:02are in place, but I also think it
10:03would be effective to take look at the logical topology that's
10:07in place once we put this together,
10:09and it would go something like this.
10:11We'd have our Palo Alto firewall right here,
10:13and for our lab environment, I'm going
10:15to use Palo Alto 15, because that's
10:17the IP address I'm going to put on all of its interfaces.
10:20So I'm going to go ahead and call up PA 15 here.
10:22So for its network interface cards on this VM,
10:24we're going to use 1/1 and 1/2, and I'll put 1/3 over here,
10:29and this is going to lead out to respective networks
10:32here and here.
10:34Let me also make a note of what those are.
10:36So this is going to be VLAN 10, and this is going to be VLAN
10:4020, and the address space here is 10.10.0.0,
10:44and on the VLAN 20, the IP address space is 10.20.0.0.
10:49Everything is going to be a /24, and then over here,
10:52we're going to have, for example, a Linux client,
10:54and over here, a Windows client.
10:56So I'll put L there for Linux and W for Windows.
10:59And over here, this can represent our DMZ network.
11:01And for our DMZ network, let's go ahead and use the address
11:04space of 10.30.0.0, again, with everything using a /24-bit
11:10mask.
11:10So that's going to be VLAN 30.
11:12Put that in parentheses.
11:14And then through the interface 1/6,
11:16that will be our connectivity out to the public internet
11:20or what the Palo Alto believes is the public internet.
11:22So the address space is 23.1.2.0,
11:25and the service providers IP address,
11:27which is R1 right here, would be at .1.
11:29And again, on the PA 15, all the interfaces
11:32are going to end with a .15.
11:34So in this video, we've taken a look at a few of our options
11:36regarding deploying a lab environment with physical
11:39or virtualized gear, and in this video,
11:40we did a behind-the-scenes look from a physical topology
11:43and also, from a logical view of what it would look like as a VM
11:46inside of an ESXi environment.
11:48So in the next video, what I'd like
11:49to do is start the process step by step of deploying each
11:53of these components and walking through that in case
11:55you want to do it as well.
11:56So see you in the next video for exactly that.
11:58Until then, I hope this has been informative,
12:00and I'd like to thank you for viewing.
Deploy the Firewall VM
0:00[AUDIO LOGO]
0:06Now that we've taken a look at some of the options regarding
0:08deploying the Palo Alto firewall as a VM in an ESXi
0:12environment, what I'd like to do is walk you
0:14through each of those components.
0:15You need a first hand view of what they look like.
0:18So our goal is to deploy the firewall as a VM and the ESXi
0:21environment.
0:22And in order to deploy that VM, we have to have the file.
0:25So the best place to go for those files
0:27is to your Palo Alto account.
0:30Go to Support and download the OVA file
0:33that's appropriate for the ESXi environment.
0:35So let me walk you through that right now.
0:37So I've logged in to the Palo Alto networks customer
0:40service portal.
0:41And on the left hand side here, I'm going to go down to Updates
0:45and expand that.
0:46And under Updates, we have a section for Software Updates.
0:49So I'll click here on Software Updates.
0:51And then we're getting software updates.
0:52I'm going to go ahead and do the PAN-OS
0:54for VM series based images.
0:56That's the one that's appropriate for an ESXi
0:59environment.
1:00There's also options there for KVM, and hyper-v, and others.
1:04And here is version 11.
1:06So we'll go ahead and click on the download link right here,
1:09and I'll simply download that to my downloads folder.
1:12And through the magic of editing,
1:13that download is already done.
1:15So our next step would be to log in to the ESXi host here,
1:18and this is the server that's behind me in the rack.
1:20And we'll simply deploy the OVA that we just
1:23downloaded from Palo Alto.
1:25So this is a power edge R630.
1:28It's got a whole bunch of RAM.
1:30And currently, it's not working very hard,
1:32so I think we're good to go.
1:33So I'm going to right click here on Host.
1:34And from the dropdown menu, I'm going to click here
1:37on Create/Register VM.
1:39And because we have an OVA file that we're
1:41going to use to deploy the VM, we'll
1:42go ahead and select that option here, and then click on Next.
1:45And I'm going to call this Demo PA Firewall,
1:48and then click here to go ahead and select the OVA
1:51file that I just downloaded.
1:52So I'll do that now.
1:53So I selected that file, PA VM ESX-11.0.0.OVA,
1:58and click on Next.
1:59And it's asking me which data store effectively-- what
2:02storage device do I use to support this VM?
2:04I'm going to go ahead and choose the local SSD,
2:06it's got some room there.
2:07We'll click on Next.
2:08It's going to power on automatically as it deploys.
2:11It's also going to use thin disk provisioning
2:13to not waste any space on the storage
2:15that doesn't really need.
2:16And for network mappings, it's going
2:18to place it in a port group that's
2:20on my management network.
2:21Now, this could be a problem and it
2:23happens to be a problem in my topology and I'll tell you why.
2:25I already have a device on my management network
2:28at 192.168.1.1.
2:31That's the default gateway for this main network right here.
2:34And by default, it's going to try to use
2:36the IP address of 192.168.1.1.
2:38So what I'm going to do is I'm going to go ahead and specify
2:41a different port group to connect this VM to because I
2:43don't want to have a conflict with the same IP address trying
2:46to be used twice on two different machines.
2:48So I'm going to go ahead and use a port group that I
2:50have that's called Parking Lot.
2:52Effectively, it's a port group on the virtual switches
2:54that goes nowhere.
2:55And that way, I can go in at the CLI,
2:57we can modify the IP address as needed , and then move forward.
3:00So they'll just be a temporary placement,
3:02and this is for the management interface on the VM.
3:06So we'll go ahead and click on Next,
3:07and then we'll click on Finish.
3:09All right, so if we go here to Recent Tasks.
3:11That is on its way.
3:14So that should take--
3:15I don't know, four or five minutes to deploy,
3:17and it may take another four or five
3:18minutes to fully initialize.
3:20So here's what I thought we would do.
3:21While that's cooking, in the next video,
3:24let me walk you through the details regarding
3:26the networking here on the ESXi host that's
3:29making this all possible.
3:30So I'll see you, my friend, in the next video
3:32as we take a closer look at that networking here inside of ESXi.
3:36Until then, I hope this has been informative,
3:38and I'd like to thank you for viewing.
ESXi Networking
0:00[AUDIO LOGO]
0:06In the previous video, we deployed the firewall,
0:08the OVA file inside of our ESXi environment.
0:11And that will take just a few minutes.
0:12So while that's cooking, let me also, in this video,
0:15show you the networking inside of ESXi
0:17that's making all the connectivity possible.
0:20So let me share with you inside of ESXi
0:21the details regarding this switch that we're
0:23using for trunking and also this switch
0:25that we're using to connect out to the management network.
0:28So here at the ESXi host, I'm using ESXi-3 for this.
0:32On the left-hand side, we can click on Networking.
0:34And let's start off with our switches.
0:36So I've got virtual switch zero, which I'm currently using
0:39for my management traffic.
0:40And then I've got a switch called
0:42trunk_switch that's supporting all the separate VLANs.
0:46So let's take a look at the trunk_switch
0:48first by clicking on it.
0:49And over here, on the right, we have the vSwitch topology.
0:52And I want to point out the VLANs
0:53that we had in our diagram.
0:55So here is a port group called VLAN 30 10:30.0.0.
0:58And effectively, what it is it's a port group that's
1:00associated with VLAN 30.
1:02So any devices that we connect to this port group
1:06are going to be connected to VLAN 30.
1:08So right now, it looks like I've got
1:10a couple of Linux computers.
1:12I've got a couple of PA firewalls
1:13I was playing with that are currently
1:15connected but not powered on.
1:16And if we scroll down to VLAN 10,
1:18here's yet another port group called VLAN 10,
1:21which is associated to VLAN 10.
1:23And once again, any devices that we connect to this port group
1:26will have connectivity into that VLAN.
1:28And so, if we use the IP address space of 10.10.0 all
1:32the devices in this port group, that's what effectively makes
1:35this VLAN 10 associated with the 10.10.0 network.
1:38So as we scroll down, here is VLAN 23.
1:41This is for the service provider network.
1:44And so any devices that we connect here,
1:46including this little device here,
1:47is going to be connected to VLAN 23.
1:50And then our last network was VLAN 20,
1:52that we had in our topology.
1:53So here's VLAN 20, which is a port group here
1:56on this virtual switch.
1:57And then virtual machines where we connect their little VM
2:00network adapter logically to this VLAN 20 port group.
2:04That's what makes them part or connected to VLAN 20.
2:07Let me also show you vSwitch0, which I'm currently
2:09using for management.
2:10So here is a port group.
2:11It's called A 192 management PG for Port Group.
2:14And effectively, any device that we connect here
2:17have physical connectivity to my external switch.
2:20So this vmnic0, vmnic, is the name of the physical interface
2:24on ESXi host that's used for connectivity
2:27between the ESXi host and the outside ethernet physical
2:30environment.
2:30And currently, I have a few different devices
2:32that are currently connected there as well.
2:34So if we look back at our topology to kind of put this
2:36all together, this is a representation of four
2:38of the port groups that we just looked at, VLAN 10, VLAN
2:4120, VLAN 30, and also VLAN 23.
2:43And then over here, we have our vSwitch0,
2:45which I've labeled here as management switch.
2:47And then this virtual switch has connectivity
2:49out to the physical world out to the vmni interface
2:52on the ESXi host.
2:53And that's how this device, R1, and this topology
2:55is getting access to the outside world
2:57is because this interface right here
2:59is connected to this virtual switch
3:01and this virtual switch has connectivity
3:02to the physical switch on the outside.
3:04So that's the networking component inside the ESXi host.
3:07And in the next video, let's take a closer look
3:09at this device right here, which is labeled in our topology
3:11as R1, which has one of its interfaces
3:14here in the port group called 23 and another interface connected
3:18to my management switch, which leads off
3:20to the other router in my environment,
3:22which then leads out to the public internet
3:24because I want to show you the details of what I'm doing here
3:26as well, in the event that you want to replicate this and do
3:29it too.
3:29So I'll see you in the next video
3:31as we take a closer look at this router right here.
3:33Until then, I hope this has been informative,
3:35and I'd like to thank you for viewing.
Lab Routing with Vyos
0:00[AUDIO LOGO]
0:06A key component to helping our lab feel alive and real
0:10is making sure we have internet connectivity.
0:12So in my lab environment, I've got a little virtual machine
0:14running on the ESXi host, which is playing
0:16the role of an internet service provider,
0:19and it's in this video that you and I
0:21get to take a closer look at the configuration of that device.
0:24So this router right here is performing NAT services.
0:28So from the firewalls perspective,
0:29as it forwards traffic to its default gateway at 23.1.2.1,
0:33this device is doing port address translation,
0:36forwarding it over my home office network
0:38192.168.1 down to the next router in the path who's
0:42also doing PAT to forward that traffic out to the internet.
0:44And this way, in my lab environment,
0:46I could avoid using RFC 1918 addresses
0:49on the outside interface of the firewall.
0:51So, in this case, the firewall thinks, oh, I'm
0:53connected to the 23.1.2.1 network
0:55with our service provider, who this device is pretending
0:57to be, being the default next hop address for access
1:01out to the internet.
1:02So let me show you a closer look at the details regarding
1:05this router inside of our virtualized environment.
1:08So if we go back to Networking and we look at vSwitch0 here,
1:12one of the devices that's connected to this management
1:14port group here on vSwitch0 is this bad boy right here.
1:18It's called vyos-23 SP-A, and that's that little router.
1:22So we click on that device that's
1:23going to show us the details for that specific VM.
1:26So this is a vyos router.
1:27They're very small images.
1:29And I'll walk through the configuration
1:30here in just a moment.
1:31But as far as its network connectivity,
1:33look down here at the rightful.
1:35For this little VM, it's got adapter 1
1:38that's connected to the port group
1:39VLAN 23.1.2, which is the port group supporting VLAN 23.
1:43And it's got a second network adapter connected to my port
1:47group that's over on vSwitch0, which leads off to the next hop
1:50address for the other routers in my topology
1:53that lead off towards the internet.
1:54So when we look at the VM, adapter number 1
1:57is going to show up as ethernet 0,
1:58and adapter 2 is going to show up as ethernet 1.
2:02So let me open up a console to this little VM,
2:05and let me show you the config.
2:06So it's opening up a VMware Remote Console.
2:09And let me make the screen just a little bit bigger.
2:11All right, that's a little bit better.
2:13So I'm going to log in as vyos with the default
2:15password of vyos.
2:17And let me go ahead and do a show config and press enter.
2:21So here's the configuration for ethernet
2:230, which is this adapter right here.
2:25I'll just make a note of that, ethernet 0.
2:27And it has the IP address of 23.1.2.1 with a 24-bit mask.
2:31And then adapter 2, which is called in the interface
2:34ethernet 1, I'm using DHCP.
2:36So whatever IP addresses are available on my management
2:39network, the 192.168.1 network, it'll
2:41go ahead and simply grab an IP address.
2:43And then, as we scroll down just a little bit,
2:45I'll press enter a few times here.
2:46So next, let's take a look at the network address translation
2:49I've got set up.
2:49So I set up a rule for source NAT.
2:51It's rule 100, which says if traffic is leaving or going out
2:55of ethernet 1, which is the 192 address space interface,
3:00and if the source is coming from 23.1.2.anything,
3:04then I want to go ahead and do masquerading.
3:07Effectively, that means they're doing port address translation.
3:09So any traffic that comes in on the firewall here if the source
3:13address 23.1.2.anything, it'll go ahead and do port address
3:17translation overloading on whatever the DHCP assigned
3:20address is here on ethernet 1.
3:22And by setting up those constraints,
3:23by making sure we're only going to accept source
3:25addresses in this range, it also is
3:27going to help us reinforce the idea that, hey,
3:29if we have clients going through our firewall,
3:31we need to make sure that the Palo Alto is doing address
3:34translation if we want that traffic to successfully make it
3:37out to the internet because this device right here,
3:40this little vyos device is not going
3:42to do address translation on anything sourced outside
3:45of the 23.1.2 address space.
3:47And as we scroll down a little bit further,
3:49let's see if there's anything else of note.
3:51I also have DHCP services on that network.
3:53So if we wanted to have our WAN interface
3:55or our WAN-facing interface on the Palo Alto,
3:58be it DHCP client, this little vyos router
4:01would hand out an IP address, and that is pretty much it
4:03regarding this little VM that's playing the role of our service
4:07provider in our lab network.
4:08So now that we've taken a look, first of all,
4:10at the networking inside of ESXi and now we've
4:13taken a look at the little router
4:14providing the ISP services from our virtualized environment
4:17out to the physical world, in the next video,
4:20let's continue our configuration of the OVA,
4:22the firewall OVA that we deployed a few videos ago.
4:25So I'll see you in the next video for exactly that.
4:27Until then, I hope this has been informative,
4:29and I'd like to thank you for viewing.
Setting up Basic FW Management
0:00[AUDIO LOGO]
0:06A few videos ago, we deploy the OVA
0:09from Palo Alto inside of our ESXi environment,
0:12and did it in about 15 or 20 minutes
0:14to go ahead and initialize.
0:15In this video, I'd like to continue
0:17our bootstrap configuration of that OVA,
0:19of that virtual machine.
0:21And on this virtual machine, this Palo Alto OVA that we just
0:24deployed, we're going to use .15 for all of its interfaces.
0:27So I'd like to start off with the management
0:29interface through its configuration first,
0:31and then we'll proceed to look at the details
0:34for the other network interface cards
0:35to make sure they're placed in the appropriate VLANs
0:38by associating those interfaces with the appropriate port
0:40groups inside the ESXi environment.
0:43So here in the ESXi environment, let
0:45me go ahead and find that VM.
0:46So here's our demo PA firewall right there,
0:49and it's going to open up a console to it.
0:51So that way, we can begin our initial configuration.
0:53So we'll go ahead and click here on Launch Remote Console.
0:56So here is our console.
0:57And let me make that a little bit bigger.
0:59Here we go, that's better.
1:01Also just as a note, when you first deploy the OVA,
1:04it might take up to 15 minutes before it's fully ready for you
1:07to log in.
1:08So I've noticed that even though it gives me a login prompt,
1:11the logins are not going to function
1:13until it's had enough time to settle
1:15and get fully initialized.
1:16So the default login here on this VM
1:19that we just deployed from the OVA file we got from Palo Alto,
1:22the default username is admin, and the default password
1:25is admin.
1:26So once we supplied that, it wants us to go ahead and change
1:29the password.
1:30So I'm going to put in the old password of admin,
1:32and then put in the new password of something
1:34different than admin.
1:35So I supplied that password, and I'll now
1:37confirm it and press Enter, and now
1:40we go ahead and begin our configuration.
1:41So we'll type in configure, press Enter,
1:43and we want to do a few things, including
1:45setting up the management IP address
1:47on this device to 192.168.1.15.
1:51So if we issue the command show and press Enter,
1:53it'll show us the full configuration.
1:55So we want to specify the type as set
1:57to static as opposed to being a DHCP client.
1:59And let's go ahead and set the type to static.
2:02And then furthermore, I'll hit the up arrow key,
2:04and let's go ahead and set the IP address itself
2:06with the command set device config system IP dash address.
2:10And then we'll go and put the IP address in of 192.168.1.15.
2:15And we can also follow that up right here
2:17with the net mask, which is three octets on, 255.255.255.0.
2:23And we can also further put the DNS information there as well.
2:26But I'm going to press Enter, and I'll
2:28do that on a separate line.
2:29So we'll begin with set device config system,
2:31and we'll go ahead and do DNS dash setting.
2:34And we'll say the primary DNS server,
2:36and we'll do a question mark for context sensitive help.
2:38We'll type in servers, and context sensitive help,
2:41and primary, and we use Google at 8888, that'll work.
2:45And then type in commit to go ahead and commit that.
2:47And once it's done, we should be able to ping 192.168.1.15,
2:52which is on the management interface,
2:55from my management computer, which is on that same network.
2:57So while that's doing its commit, let me go ahead
2:59and bring up a command prompt and we'll
3:01test some basic connectivity.
3:02So here is a command prompt on my local management computer,
3:05and let's do a ping out to 192.168.1.15.
3:10and services, and the ping is not working.
3:15So let's think about why that is.
3:16Let me go ahead and do an ARP dash A,
3:19and I don't even have the layer 2 address for .15, why is that?
3:22Oh, I know why that is.
3:24[LAUGHS]
3:25Let's take a look at this Palo Alto firewall we just deployed,
3:28I put all of its adapters in the parking lot.
3:30So let me go ahead and let me add some additional adapters
3:34here.
3:34And also while we're here, let's go ahead
3:36and place those adapters in the appropriate VLANs.
3:39So we're going to want a total of seven interfaces
3:42because the first interface here is going to be our management
3:44interface, and then the second interface is
3:46going to be 1/1 and so forth.
3:47So I'm going to click here on Edit to edit
3:50the details for this VM.
3:51And let me add some network adapters 1, 2, 3, 4.
3:56And there they are.
3:57I'll click on Save.
3:58So there's our seven adapters, and let's go back to editing
4:01and let me put them in the right VLANs.
4:03So interface number 1 is the management interface.
4:06And so I want that on my management network.
4:08And interface number 2 is 1/1.
4:11So let me document those real quick.
4:13So this is the management interface.
4:14This is 1/1, 1/2, 1/3 1/4, 1/5, and 1/6.
4:22Also before I make these changes here
4:24at the VM network interface level,
4:26let me also just take a look at our topology and make sure
4:28I'm going to put the right interface in the right VLAN.
4:30So if we go back to our drawings here,
4:33we want 1/1, that's going to be in VLAN 10, 1/2
4:38in VLAN 20, 1/3 in VLAN 30, and 1/6 in VLAN 23.
4:43And we won't be, for the moment, using interfaces 1/4 or 1/5.
4:47All right.
4:48So with that in mind, let's go make
4:49sure those interfaces are appropriately assigned.
4:51So the management interface will be in the 192 management port
4:55group, and then 1/1 is going to be assigned to VLAN 10.
4:59So we'll apply that there.
5:00And 1/2 is going to be assigned to VLAN 20.
5:03So let me go ahead and grab that port group right there.
5:06And one last is going to be in VLAN 30, which is right there.
5:11We're not using five or six at the moment,
5:12so we put them in the parking lot.
5:14It's basically a port group that goes nowhere.
5:16And also take network adapter seven
5:18which is on the appliance, that's going to be 1/6,
5:20and let's put that into VLAN 23 just like that.
5:24And then we'll click on Save.
5:26I also want to confirm that that took.
5:27So let's go ahead and check our work.
5:29So the first interface, which is the management interfaces,
5:32is on the network, that port group.
5:34And then 1/1 is in VLAN 10 1/2 is in VLAN 20,
5:381/3 is in VLAN 30, and then 1/6, which in the interface here
5:43on the ESXi host shows is adapter number seven is in VLAN
5:4623.
5:47That's going to go over to our VyOS router, which
5:50is serving the role of our internet service
5:52provider in the lab topology.
5:54So now, we should be able to-- from my management computer,
5:57which is also on the network 192.168.1.15,
5:59we should be able to ping the .15 addresses associated
6:02with the management interface on the Palo Alto.
6:04So here's the command prompt on my local computer.
6:07And let me do an IP config real quick just
6:09to verify my IP address.
6:10So sure enough, I'm at 192.168.1,
6:13and my host address is 151.
6:15And let's do a quick ping over to 192.168.1.15.
6:20And service says-- yay, [LAUGHS] that's a good indication.
6:23So we're able to go ahead and connect to the management
6:26interface from my management computer.
6:28What that also means is that we should
6:29be able to open up a browser and connect via HTTPS, once again,
6:33from this management computer over to the management
6:36interface on the Palo Alto.
6:38So let's try that as well.
6:40All right.
6:40So I've opened up a browser with HTTPS to that IP address
6:43and it says, we don't trust the certificate.
6:45So we'll go ahead and click on Advanced.
6:47That's expected on a brand new device.
6:49And we'll click on Proceed, and then we'll go ahead and log in.
6:52So I'll log in as admin with the password
6:54that I changed earlier at the command line.
6:56And says welcome to Pan OS 11.
6:58And I say, great, thank you very much.
6:59Click on Close.
7:00And here, we have the graphical user interface
7:03for this Palo Alto firewall.
7:04So currently, it is not licensed.
7:07So we look here at the VM license, that says none.
7:09And if we were to go over to the device tab
7:11up here, and on the left hand side,
7:13go down to licensing by clicking here on licenses,
7:17currently, it is not licensed.
7:18But once again, even if you have a VM or even
7:21an appliance that's not licensed,
7:23you can still do a lot of the basic functionality, including
7:26network address translation, and many different security
7:28policies, and practice with the stateful filtering
7:31nature of the firewall even though it doesn't
7:34have the full capabilities that you would in the event
7:36that you had a license.
7:37So we go back to the dashboard, and let
7:39me also confirm a couple of pieces as well.
7:41Since we're right here in the interface,
7:42let's go to-- under Device, we'll go to Setup.
7:44So here under Interfaces-- so Device, Set Up and Interfaces,
7:48if you click on the Management Interface,
7:50here it has the IP address that we signed.
7:52Oh, and it doesn't have a default gateway.
7:54So let's go ahead and do that now.
7:55I forgot to do that at the CLI.
7:56So we'll do a 192.168.1.1.
7:59And from the management network, that is the default gateway
8:03that this Palo Alto can use as it does things
8:05like connect up to the Palo Alto cloud, and gets updates,
8:09and so forth.
8:09So I need that to be in place.
8:11So I'm glad we checked that.
8:12We're allowing ping on this management interface.
8:14That's why we could ping it earlier.
8:16We'll click on OK.
8:17And also while we're here, let's click on Services
8:19and click on the gear icon, and just verify
8:23that our DNS is currently set up.
8:24It is.
8:25And if we want to set up NTP, we can do that right here as well.
8:28So that all looks good.
8:29So I'm going to go ahead and click up here
8:31on Commit in the upper right just to make sure
8:33that changes about the default gateway are now in play
8:36and they're running configuration.
8:37And we'll click on Commit.
8:38So while that finishes the commit,
8:40let's take a look, once again, at our topology.
8:42So up to this point, here's what we've got.
8:44We've got these interfaces--
8:451/1, 1/2, 1/3, all associated with the correct port groups.
8:49The management interface is also associated
8:50with the correct port group.
8:51We were able to-- from my management computer,
8:54which is sitting here in my home office network.
8:56So here's our management PC right here.
8:58I was able to go ahead and connect
9:00to that firewall with HTTPS.
9:02And we preceded that with a quick connectivity test
9:04with a ping.
9:05And so now we've got this basic firewall
9:07sitting there ready to go.
9:08So in the next video, what I'd like to do
9:10is let's start off by doing some basic configuration regarding
9:13the IP addresses associated with these interfaces.
9:16So we'll assign this interface 1/1 with the IP address
9:19of 10.10.0.15.
9:22And then for 1/2, it'll be 10.20.0.15 based on these IP
9:28address spaces that we're using for those respective VLANs.
9:30And by setting up the interfaces with their appropriate IP
9:33addresses, we're further building this basic foundation
9:36in our lab environment which we can then build on.
9:39So join me in the next video as we
9:40continue our journey in the configuration of this firewall
9:43by applying basic IPv4 addresses to its interfaces.
9:46So I'll see you there in just a moment.
9:48Until then, I hope this has been informative,
9:50and I'd like to thank you for viewing.
Configure L3 Zones, Virtual Routers, and Interfaces
0:06In the previous video, we both configured and verified
0:09basic management access over to the firewall that's running
0:12inside the ESXi environment.
0:13In this video, we're going to continue our configuration
0:16by applying IP addresses to the interfaces on the firewall.
0:20Also, for this firewall that we just deployed,
0:22which is this one right here, the demo PA firewall,
0:25I'm going to go ahead and shut it down.
0:26In fact, I'm going to go ahead and rudely powered off,
0:29because I'm going to switch over to a firewall,
0:31same exact version, version 11, of the firmware running
0:35on the Palo Alto, but I'm going to go ahead and start off
0:38with a Palo Alto firewall that I've already
0:40taken the steps of licensing.
0:41And that way later, when we get to the advanced features
0:44of threat prevention and so forth,
0:46the licenses will already be in place.
0:47So I'm going to take this existing firewall that we just
0:49deployed a few moments ago, and I'm
0:51going to remove it from my ESXi environment, just like that.
0:56All right, so it is gone, and the firewall
0:58that I want to go ahead and bring up,
0:59where it'll pick up right where the other one left off,
1:02is this one right here, which is PA-15.
1:04So let's go ahead and take a look at the details before we
1:07power it on.
1:07So it's got seven network adapters, a management
1:10interface, plus one for VLAN 10, VLAN 20, VLAN 30, and also one
1:14on interface 1/6, which is connected to VLAN 23.
1:18So we'll go ahead and we'll launch this
1:20by clicking Power On, and through the magic
1:22of editing, that power on is going
1:25to take just a few seconds.
1:26In a production environment or in a lab environment,
1:28it may take 4 to 6 minutes for the firewall
1:32to fully initialize and get going.
1:34So while that's coming up, I'm going
1:36to bring up a Command prompt here from my management
1:38computer and just do a real quick ping over
1:40to 192.168.1.15.
1:42I use the same exact IP addresses that we
1:44did in the demo a moment ago.
1:46Press Enter.
1:47So we have basic IP connectivity,
1:49so the next step would be to go ahead and bring up a browser
1:52and see if we can connect via HTTPS.
1:55So it's been about a minute or two.
1:56Let's go ahead and try logging in again
1:58to the Palo Alto firewall.
1:59All right, so I am logged in.
2:01So again, just to verify a few components.
2:03If we click here on Device and on the left,
2:05we select Setup and we go to Interfaces,
2:08here, I've got the management IP address that's currently set.
2:11I've got the default gateway set.
2:12Fantastic.
2:13We're allowing ping on the interface as well
2:15as HTTPS and SSH.
2:17Great.
2:18Great.
2:18Great.
2:18And then if we click here on Services
2:20and we click on the gear here, I just
2:22want to verify that I have my DNS information set up,
2:25and I think I also set up NTP, which I did.
2:28So we're able to synchronize with an NTP server
2:30on the internet.
2:31So no changes there.
2:32So that looks good.
2:33So having verified that, we can continue our configuration
2:36of the actual interfaces here.
2:38So let's take a moment, look at our topology,
2:40have a good plan in place, and then we'll
2:42go ahead and implement it.
2:43Also, now that we've taken a look at the details
2:45around the connectivity with the firewall
2:47and the virtual switches in the outside world, let's go ahead
2:50and clean this up a little bit for a standard topology
2:53that we can use going forward.
2:54And I'm going to name this one PA-15.
2:56And that's because on this firewall,
2:57every single interface it has, it's
2:59going to have the last number of its IPv4 address as 15.
3:04And then for the interfaces, we have interface 1/1 and 1/2
3:08and interface 1/3 that we're going to be using.
3:11And as we verified, each of those interfaces
3:13is now connected to a respective VLAN.
3:15So interface 1/1 goes to VLAN 10,
3:17and interface 1/2 goes to VLAN 20,
3:21and interface 1/3 is connected to VLAN 30.
3:25I'll label those as well.
3:26So that's VLAN 30 there, and its IP dressing space is 10.30.0.0.
3:32And for VLAN 20, I'm going to label that, V20,
3:35and its IP address space for using there is 10.20.0.0,
3:38and for VLAN 10, the IP dressing space we're using there is
3:4210.10.0.0, and we draw some connectivity there.
3:47So we are connected to that VLAN there
3:49through 1/1, and this VLAN here through 1/2 and to this VLAN 30
3:54network, through 1/3.
3:56And then to the outside world, we're
3:58using the interface of 1/6, which
4:01from the Palo Alto's perspective is connected out
4:03to the internet.
4:04So I'll go ahead and draw a cloud representing
4:05the internet, and behind the scenes,
4:07this connectivity out to the internet
4:09is really in my lab environment using VLAN 23.
4:12And the service provider's IP address here, at the edge,
4:15in my little lab environment is that little wireless router,
4:17and it's at .1, and this network address space
4:20is 23.1.2.0 with a 24-bit mask.
4:24And also, just for reference, I've
4:26also got the management interface
4:27right here, which in the VMware environment
4:29is the first adapter, the network adapter, and that
4:32is the 192.168.1 address space.
4:36And again the PA-15 is going to be using .15 on all
4:40of its respective interfaces.
4:42Now, a big part of most vendors' firewalls,
4:44including the Palo Alto firewall,
4:45is to leverage the concept of zones.
4:48So in our case, we could say that these two
4:50internal networks, these VLANs 10 and 20, perhaps,
4:53they are part of a zone called Inside,
4:56so I'll label that as the Inside zone.
4:58And everything that's hanging off of interface 1/6,
5:02going out towards the internet, which is a less trusted network
5:05address space, to be sure, we can
5:07put that interface in a zone called the Outside zone.
5:09And then for VLAN 30, perhaps we wanted
5:11to use it as a demilitarized zone, and so what we could do
5:15is we could put interface 1/3 in its own zone,
5:17and perhaps, we call it DMZ.
5:20So that's the DMZ zone.
5:21And one of the benefits of setting up zones
5:23is that we can use zones as part of our security policies
5:26to specify what is allowed.
5:27For example, we may want to use our-- in fact,
5:29let's draw a couple of computers here.
5:31So let's imagine we have a Linux computer right here
5:33that's connected to this network,
5:36and let's imagine a Windows client here
5:39that's connected to this VLAN, and let's also
5:42imagine a server that we could place on our DMZ, which
5:46is connected there.
5:47I'll put S for server.
5:48And while we're at it, I'm going to document what that IP
5:50address is, it's .100 on that 10.30.0 subnet.
5:54While the Linux client and the Windows client
5:56can both be DHCP clients getting an IP address assigned
5:59from a DHCP server, which could be a server running
6:02in this environment, or we could have the Palo Alto
6:05itself act as a DHCP server.
6:07And back to our discussion regarding zones,
6:09we can set up policies that specify
6:11that traffic that is sourced from devices that are coming
6:13into the firewall on the interfaces that are part
6:16of the inside zone, if that traffic is destined to IP
6:19addresses that are routed out through this outside zone
6:22through 1/6, we can specify that traffic is allowed.
6:25Or if we had people on the internet
6:27that we wanted to be able to access a public-facing server,
6:29for example, we could go ahead and do destination NAT,
6:32so this server appears as a globally routable address here
6:36on the internet.
6:36And from a permissions perspective
6:39we could specify the permissions to allow traffic
6:41from people on the outside zone, as they're
6:44trying to access the server, which is on the DMZ zone.
6:46And so the reason I also bring up the concept of zones right
6:49here is because, if we're about to configure IP addresses
6:52on these interfaces, on interface 1/1,
6:55giving it the IP address of 10.10.0.15 and on 1/2,
6:59the IP address of 10.20.0.15, and so forth,
7:01part of that configuration is going to be asking us,
7:04not only what is the IP address, but also,
7:05what zone do you want to put that interface in.
7:08So as far as our game plan, I would
7:10like to have three zones to begin with,
7:11the outside zone, the DMZ zone, and the inside zone,
7:14and then when we put the IP addresses on those interfaces,
7:17we'll make sure we also include these zones
7:19that those interfaces belong to.
7:21So having said that, let's go back to our firewall,
7:23and let's configure the IP address and zone membership for
7:26interfaces 1/1, 1/2, 1/3, and 1/6.
7:31So to configure those interfaces,
7:32we're currently at the Dashboard tab.
7:34We want to go over to the Network tab
7:35here on the Palo Alto.
7:37And at the very top on the left, it's
7:38showing us the option to configure the interfaces.
7:41Right below that, we have the option here for creating zones.
7:45Now, one of the benefits is, if you
7:46don't have zones already created,
7:48while you're configuring the interfaces gives us
7:50the opportunity to step out for just a moment, create the zone,
7:53and then make sure that interface belongs to the zone.
7:56So even though we want the three zones,
7:57we don't have to go here first to create them.
7:59We can just do it right here from interfaces.
8:01So let's start off with interface 1/1,
8:04which is connected to VLAN 10.
8:06So to configure interface 1/1, we'll click on it.
8:09We're going to specify the interface type.
8:11So we're going to go ahead and have separate videos
8:13and discussions.
8:14We're getting interface types and how they work
8:16and why they're important.
8:17For now, we're going to do traditional Layer 3 interfaces.
8:20Think of a Layer 3 interface as an interface
8:22that's going to have an IP address associated with it.
8:24And here, on the subtab called config,
8:26it's asking us, regarding this interface, who
8:29do you want to assign it to?
8:30For example, which security zone do
8:31you want it to be a member of.
8:32So we use the dropdown, and we don't have any,
8:34so this is the moment where we can go ahead and create one.
8:37So we want ethernet 1 to be in a zone called Inside.
8:40So we'll click here on New Zone.
8:41For the name, we'll call it Inside.
8:43I'll leave everything else to the defaults, click on OK.
8:46And now, this interface, once we commit the whole process,
8:48will be a member of the Inside security zone.
8:51I also want to go ahead, for routing purposes,
8:54and I want to create a special logical router
8:56that each of these interfaces is going
8:58to be associated with as well.
9:00So here next a virtual router, it currently says None.
9:02We'll use the dropdown, and let's go ahead
9:04and create a brand new virtual router.
9:06So over here on the left, there's
9:08also the option to create a new virtual router,
9:10but we can do it right here as well,
9:11and let's call this Our Router, just like that,
9:15and we'll take all the other defaults and click on OK.
9:18So now, this interface, once we commit the process,
9:20is going to be associated with the zone called Inside,
9:23and also, any network it's directly connected
9:26is going to become part of this logical router called
9:29Our Router.
9:29And then, of course, we want to assign an IP address,
9:32so we'll click here on the IPv4 subtab,
9:33and we'll click here on Add to add an IP address.
9:36And the IP address we're going to add is 10.10.0.15,
9:40based on our plan, with a 24-bit mask,
9:42and then we'll click on OK.
9:44So there we go, interface 1/1 done,
9:46and we'll repeat that process for 1/2.
9:48So we'll click on 1/2, we'll specify
9:51that it's a layer interface, meaning an interface that's
9:53going to have an IP address.
9:54We'll associate it with the virtual router called
9:57Our Router and the security zone called Inside.
10:01And then we'll click on the IPv4 subtab,
10:03and we'll assign the IP address there as 10.20.0.15 with
10:08a 24-bit mask, just like that, and click on OK.
10:12And then we'll go to 1/3, which is associated with VLAN 30,
10:15which is using the 10.30 address space.
10:17So we'll click on ethernet 1/3, we'll
10:20specify that it's Layer 3 interface as well.
10:22And then for the security zone, we
10:24want it to be in a security zone called DMZ, which doesn't exist
10:27yet, so we'll go ahead and click right here on New Zone
10:29to create it.
10:30So we'll call it DMZ and click on OK,
10:33and we'll send this interface also to the new virtual router
10:35we just created and then click on the subtab for IPv4
10:39and specify its IP address based on our plan,
10:42which is 10.30.0.15 with a 24-bit mask, just like that,
10:47and we'll click on OK.
10:48And then we want to go down to interface 1/6, in fact,
10:50let's take a look at our notes real quick.
10:52So interface 1/6 is in VLAN 23, and we're
10:55going to want to assign the address of 23.1.2.15
10:58to that interface, and we're also
11:00going to want to make sure we assign it
11:01to a zone called Outside, which will also create.
11:04So we'll go down to interface 1/6,
11:07we'll specify the interface type of Layer 3,
11:09and we'll assign this to the virtual router called
11:12Our Router, and the security zone we want it in is Outside.
11:16So it doesn't exist yet, so we'll click here on New Zone
11:18to create it.
11:19We'll call it Outside, click on OK,
11:21and then click on the subtab for IPv4, click on Add,
11:25and we'll add the address of 23.1.2.15 with a 24-bit mask,
11:29just like that, and click on OK.
11:31So now, we've configured four Layer 3 interfaces
11:34with IP addresses.
11:35We assigned them all to the same virtual router,
11:38and we assigned them all to the respective security zones--
11:40Inside, Inside, DMZ, and Outside.
11:43Now, you'll notice that none of these link states
11:45show as active, and also, all these configuration changes,
11:48they are not running yet on the actual firewall.
11:52And that's because to apply these changes,
11:53we need to click here on Commit.
11:55So in the upper, right-hand corner, we'll click on Commit.
11:57It's giving us a scope regarding what it's doing,
11:59so it's creating some new zone objects,
12:02and it's also creating a new virtual router and also,
12:06assigning some interfaces to that virtual router
12:08and to those zones and also, applying IP addresses.
12:11We can expand that to take a look at the details there.
12:14We also have an option of previewing the changes.
12:16So if we click here on Preview Changes and then click on OK,
12:19it's now showing us the changes that are about to be made.
12:22So we're adding some details to each of the interfaces,
12:25we are creating a new virtual router,
12:27and we're creating some new zones, so all that looks good,
12:30and we'll click on Commit.
12:31So depending on the platform and how many changes there are,
12:34the commit may take anywhere between 15 seconds
12:36and several minutes.
12:38So if we click on Close right here,
12:40it doesn't mean we're canceling the commit,
12:42it's still in the background working
12:43on that commit to the running configuration.
12:45And if we want to see our current status, down here
12:47on the bottom right, if we click on Tasks,
12:49that will bring up our listing of all tasks,
12:52including the commit that is currently in place.
12:54All right, so that's almost done.
12:56So while that completes, in the next video,
12:58let me also walk through some of the virtual machines
13:01that we'll be using inside of ESXi,
13:03as part of our lab environment.
13:04So I'll see you there in just a moment for exactly that.
13:07Until then, I hope this has been informative,
13:09and I'd like to thank you for viewing.
LAB Clients and Servers
0:00[AUDIO LOGO]
0:06In the previous video, we configured some zones,
0:09a new virtual router.
0:10We had configured IP addresses on four of the interfaces
0:13and assigned them to the appropriate zones
0:15on the virtual router.
0:16In this video, I'd like to walk you through some of the VMs
0:18that we're going to be using as part of our lab topology.
0:21So here in our topology, I would like
0:23to have a little Linux machine sitting right here on VLAN 10,
0:26a little Windows computer sitting here on VLAN 20,
0:29and our server over here on VLAN 30.
0:32So to make that happen inside of ESXi we take those VMs
0:35and make sure their network interface card
0:36is associated with the appropriate port
0:38group on the virtual switch.
0:40So the Linux machine should be connected
0:42to the little port group for VLAN 10
0:44on the trunk virtual switch.
0:46And the Windows computer should be connected to the VLAN 20
0:48port group.
0:49And the server, on one of its interfaces,
0:51should be connected to the VLAN 30 port group.
0:54So let's go into the ESXi environment
0:56and verify those three.
0:57So here inside of ESXi--
0:59let me go to Virtual Machines, and let me
1:01sort by which ones are currently running.
1:04So there's our lab firewall right there that we're using.
1:06And let me scroll down.
1:08And let's use this Windows 11 computer right here.
1:11In fact, I'm going to rename that.
1:12I'll right click and rename the entry just here in VMware.
1:16I'm going to call it Win 11 for Palo Alto.
1:19Press Enter and then click on Rename.
1:21And that way I'll make sure I get the right one every time.
1:24And while we're here, let's click on it,
1:26and let's verify where it's currently connected.
1:28So it shows as being associated with the VLAN 20 port group,
1:31so that should be in the VLAN 20 network, just like that.
1:35So let me go ahead and power it on.
1:37And while that's powering it on, let
1:38me go back and look at our other virtual machines.
1:40And let's find a Linux machine for VLAN 10.
1:44And here we go right there.
1:46In fact, let me rename this.
1:47So I'll rename that little VM here
1:49instead of the ESXi Hypervisor, let's
1:51call it Linux for Palo Alto and click on Rename.
1:55And then let's click on it, and take a look at the details.
1:58So currently this little VM is connected
1:59to a port group that's associated
2:01with VLAN 10, which is great.
2:03So let me ahead and power that one on as well.
2:05So let's open up consoles for each of these.
2:07So here on the Windows 11 machine,
2:09there's a few ways of doing it.
2:11We can right click here and go to the console
2:13and say Launch Remote console right here.
2:16Or we could do it from here Launch Remote console.
2:19Or depending on how the defaults are set up
2:21on your virtualized environment, you just click here
2:23and that will open up a console.
2:25So here is our Windows client right here.
2:28And let's bring up a command prompt.
2:30Let's just verify its IP address with an ipconfig.
2:33And it shows there's no default gateway,
2:36but it has an IP address of 10.10.0.150.
2:39And if we look at the details for how that's configured,
2:41that is configured as a static IP address.
2:45As we look at the properties of the interface,
2:47so if we want to get an IP address automatically via DHCP,
2:50we can go ahead and specify that we do.
2:52Want to be a DHCP client click on OK.
2:54Click on OK again, and then go back to the CLI.
2:57Hit the up arrow key for ipconfig.
2:59And currently, no IP address yet.
3:02And one of the problems is that we don't have a DHCP server
3:04present.
3:05And that's why we're getting an automatic private IP address
3:07assignment space here on this interface
3:09is because there's no DHCP server available.
3:11And you know what because we're going to want some DHCP
3:14services, let's also take a moment right now as part
3:17of our bootstrapping of this firewall,
3:19to enable DHCP services on interface 1/1 and 1/2.
3:24So in our topology, we want to enable DHCP services here
3:28to support the 10.10 network.
3:29And here on the 1/2 interface to support the 10.20 network.
3:33And that way when we bring up our clients,
3:35that'll confirm also that this client and the interface
3:38on the FortiGate are in their respective same VLAN
3:41and also the same thing for the Linux machine
3:43and interface 1/1.
3:45If we can set up DHCP services and these clients
3:47can get the appropriate IP address from those DHCP
3:50servers running on the Palo Alto interfaces,
3:52then we have confirmation that we are on the same VLAN.
3:54So let's take a moment and also set up DHCP services
3:58on interface 1/1 and 1/2 here on the Palo Alto.
4:02And the way to do that is pretty easy here on the Palo Alto.
4:04We simply go to the Network tab up here.
4:06And with the Network tab selected,
4:08over on the left-hand side, we're
4:09going to click on DHCP, the Dynamic Host Configuration
4:12Protocol.
4:13And we're simply going to add DHCP servers,
4:16one for each of the interfaces.
4:17So to do that, here's a list of current interfaces supporting
4:20DHCP.
4:21And there aren't any so we'll click right here on Add.
4:23So we'll click on Add.
4:24And then we'll specify we want interface 1/1
4:27to act as a DHCP server.
4:29And then we'll go ahead and ping before allocating a new IP
4:32address to help verify whether or not
4:34that IP address is already in use, and we'll click on Add.
4:37And we'll specify this pool is going to be 10.10.0.
4:40and we'll go 51 all the way through 10.10.0.99.
4:45And then for the options, let's also specify a default gateway,
4:49which once configured will be the firewall at 10.10.0.15.
4:54And the mask is going to be a three octet mask.
4:57And the primary DNS, let's hand out a Google DNS server.
5:00And with those in place, we'll click on OK.
5:02And let's do a similar treatment over for interface 2.
5:05So we'll look here an Add and we'll specify interface 1/2.
5:09And we'll do the ping, and also, instead of auto, I'm
5:12going to go ahead and specify just enable it no matter what.
5:15And then for the pool, we'll click on Add,
5:17so the pool for VLAN 20, which is 10.20.0.
5:20And let's do 51 all the way through 10.20.0.99.
5:24And go to options.
5:26And the default gateway there would be the Palo Alto once
5:29it's all set up, which is 10.20.0.15.
5:32and the mask is a 24-bit mask, so we'll put that in.
5:35And the primary DNS server that we can hand out is 8.8.8.8.
5:39And for the lease, let me also go ahead and change
5:41the timeout.
5:41So instead of saying an unlimited timeout,
5:43let's go ahead and just have it timeout after one day.
5:45So a client, if their lease is about to expire,
5:48they'll renew their lease, or they'll
5:49attempt to renew their lease.
5:50All right, so go ahead and click OK there.
5:53And before we commit to put this all in play,
5:56let me also go ahead and modify ethernet 1/1
5:59and specify the timeout there as well.
6:02I'll go ahead and use one day.
6:03And also set this one to enable as opposed to auto and click
6:07on OK.
6:08Oh, and I don't see the DNS here information.
6:11So let's go ahead and look at ethernet 1/2.
6:13Maybe I didn't save it.
6:14Under Options, DNS, yeah, I must not have saved it 8.8.8.8,
6:18and then we'll click on OK.
6:20And let's check our work.
6:21So the lease time is one day on each.
6:23Here's the subnet ranges from which
6:25they'll handle IP addresses.
6:27And they're both handing out a default gateway pointing
6:29to their own IP address.
6:30Once we get the firewall configured,
6:32it'll be able to support that.
6:33So to put this in play, we'll go ahead and click on Commit.
6:36We can preview the changes if we want to see them.
6:38Otherwise, just click on Commit one more time.
6:40And then in about a minute or two,
6:42that information that we just configured
6:44will be part of the actual running configuration
6:46on the actual firewall itself.
6:48So we'll click on Close there.
6:49We'll let that finish in the background.
6:51And let's go take a look at our VMs.
6:52So our other machine, besides the Windows machine and VLAN
6:5520, we have our Linux machine.
6:57We've already powered it on.
6:58Let's go take a look at that one as well.
7:00So here is that Linux computer right here.
7:02And because we just configured the DHCP services here on 1/1,
7:06we just applied the commit, I'm going to go ahead
7:08and reboot this Linux computer.
7:09So go here and click on the power button
7:12and say please restart.
7:14And when it restarts, it should initiate the DHCP process
7:17as a client.
7:18And hopefully, we'll have an IP address in the 10.10 address
7:21space here on VLAN 10.
7:24So we'll give that a moment to initialize, and let's
7:26go to a command prompt.
7:27And let's verify whether or not it has an IP address.
7:29So on Linux, it's ifconfig, press Enter,
7:32and here in this first interface, is 10.10.0.51.
7:35That's fantastic.
7:36So we'll also verify at the Palo Alto
7:39that that is indeed the IP address that we've handed out
7:41from our DHCP services.
7:43Also, while we're at it, let's check on the Windows computer
7:45right here.
7:46So I'll move the Linux out of the way.
7:47And here's our Windows computer.
7:49So we already confirm that the interface is configured
7:52to act as a DHCP client.
7:54Let's just confirm that one more time.
7:56So if we look at the properties of IPv4
7:58obtain an IP address automatically, fantastic.
8:00And so if I just disable this interface and give it a moment
8:03and then right click and enable it again,
8:05what that should cause in the background when it comes up,
8:08it should have cause the DHCP process to kick in.
8:10And this computer should get an IP address from the 10.20
8:14address space handed out from the Palo Alto.
8:16So let's open up a command prompt and verify that.
8:18So here at the command prompt, we'll do an ipconfig on this
8:21Windows computer and sure enough 10.20.0.51.
8:24So let's just verify for a moment
8:26that this Palo Alto did indeed hand out
8:29both of those IP addresses.
8:30The 10.10.0.51 to the Linux client and the 10.20.0 address
8:34over here to the Windows computer.
8:36So back to the Palo Alto we go.
8:37So up at the top, we're still on the Networks tab.
8:40And over on the left, we've selected DHCP.
8:42And then if we want to look at the leases for interface 1/1,
8:46we click right here under IP Pools, the link
8:48that says View Allocation.
8:50So we'll click that link, and sure enough,
8:52it's handed out the 10.10.0.51 to the Linux computer.
8:55And we'll do the same for ethernet 2,
8:57and click here on the link for View Allocation.
8:59Here it has the IP address handed out
9:01to the Windows computer, which helps
9:02us to confirm that the interfaces that we configured
9:05on the VMs and also the VM acting as the Palo Alto
9:09firewall, are all in the correct VLANs.
9:11So let's summarize.
9:12We now have this Palo Alto firewall
9:14that's running in our ESXi environment
9:15along with a Linux VM a Windows VM.
9:19We also have the server.
9:20We don't need him quite yet.
9:21We'll come back, and we'll verify that connectivity
9:23once we start using it.
9:24And we also have the interface 1/6,
9:26which is connected out to our little pseudo internet service
9:30provider router, which is our VIOS device.
9:32So now that we have this infrastructure in place,
9:34it provides a fantastic foundation
9:36on which we can build as we start
9:37working with, configuring, and managing a Palo Alto firewall.
9:41So thanks for joining me in this set of videos.
9:43And I look forward to seeing you, my friend,
9:44in the very next set.
9:45Until then, I hope this has been informative,
9:47and I'd like to thank you for viewing.
Team training path
Turn this skill into assignable team training
This free skill is a preview of the courses your team can assign, track, and report on with CBT Nuggets.
$708
seat / year