{"id":29980,"date":"2019-10-31T21:32:59","date_gmt":"2019-10-31T18:32:59","guid":{"rendered":"https:\/\/prohoster.info\/blog\/optimizator-politik-bezopasnosti-palo-alto-networks-ngfw\/"},"modified":"2019-10-31T21:32:59","modified_gmt":"2019-10-31T18:32:59","slug":"optimizator-politik-bezopasnosti-palo-alto-networks-ngfw","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/optimizator-politik-bezopasnosti-palo-alto-networks-ngfw","title":{"rendered":"Palo Alto Networks NGFW Security Policy Optimizer","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<h1>How to evaluate the effectiveness of NGFW configuration<\/h1>\n<p>\nThe most common task is to check how effectively your firewall is configured. There are free tools and services offered by companies specializing in NGFW. <\/p>\n<p>For example, it can be seen below that Palo Alto Networks provides the ability directly from <noindex><a rel=\"nofollow\" href=\"https:\/\/support.paloaltonetworks.com\/\">the support portal<\/a><\/noindex> to launch an analysis of firewall statistics \u2014 SLR reporting or best practices compliance analysis \u2014 BPA reporting. These are free online tools that can be used without installing anything.<br \/>\n<img decoding=\"async\" alt=\"Palo Alto Networks NGFW Security Policy Optimizer\" src=\"\/wp-content\/uploads\/2019\/03\/86d2f4d5f28af9f744b1d1842e461309.png\" style=\"display:block;margin: 0 auto;\" \/> <noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><\/p>\n<h3>CONTENTS<\/h3>\n<p>\n<noindex><a rel=\"nofollow\" href=\"#Expedition\">Expedition (Migration Tool)<\/a><\/noindex><br \/>\n<noindex><a rel=\"nofollow\" href=\"#PolicyOptimizer\">Policy Optimizer<\/a><\/noindex><br \/>\n<noindex><a rel=\"nofollow\" href=\"#ZeroTrust\">Zero Trust<\/a><\/noindex><br \/>\n<noindex><a rel=\"nofollow\" href=\"#Unused\">Click on Unused<\/a><\/noindex><br \/>\n<noindex><a rel=\"nofollow\" href=\"#UnusedApp\">Click on Unused App<\/a><\/noindex><br \/>\n<noindex><a rel=\"nofollow\" href=\"#AppsSpecified\">Click on No Apps Specified<\/a><\/noindex><br \/>\n<noindex><a rel=\"nofollow\" href=\"#MachineLearning\">But what about Machine Learning<\/a><\/noindex><br \/>\n<noindex><a rel=\"nofollow\" href=\"#UTD\">UTD<\/a><\/noindex><\/p>\n<p><noindex><a rel=\"nofollow\" name=\"Expedition\"><\/a><\/noindex><\/p>\n<h2>Expedition (Migration Tool)<\/h2>\n<p>\n<img decoding=\"async\" alt=\"Palo Alto Networks NGFW Security Policy Optimizer\" src=\"\/wp-content\/uploads\/2019\/03\/1d568bbbd1480eda4de7b5cdcaaae90a.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nA more complex method to check your settings is to download the free utility <noindex><a rel=\"nofollow\" href=\"https:\/\/live.paloaltonetworks.com\/t5\/Expedition-Migration-Tool\/ct-p\/migration_tool\">Expedition<\/a><\/noindex> (formerly Migration Tool). It is downloaded as a Virtual Appliance for VMware, no additional configuration is required \u2014 just download the image and deploy it on the VMware hypervisor, start it, and access the web interface. This utility deserves a separate discussion, as the course on it takes 5 days due to the many functions available now, including Machine Learning and migration of various policy configurations, NAT, and objects for different Firewall manufacturers. I will write more about Machine Learning later in the text.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"Po\"><\/a><\/noindex><\/p>\n<h2>Policy Optimizer<\/h2>\n<p>\nAnd the most convenient option (IMHO), which I will detail today \u2014 the policy optimizer built into the Palo Alto Networks interface itself. To demonstrate it, I installed a firewall at my home and wrote a simple rule: permit any to any. In fact, I sometimes see such rules even in corporate networks. Naturally, I enabled all NGFW security profiles, as shown in the screenshot:<br \/>\n<img decoding=\"async\" alt=\"Palo Alto Networks NGFW Security Policy Optimizer\" src=\"\/wp-content\/uploads\/2019\/03\/a53a1bff59708c7082bafb5b84634b11.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nThe screenshot below shows an example of my home unmanaged firewall, where almost all connections fall into the last rule: AllowAll, as indicated by the statistics in the Hit Count column.<br \/>\n<img decoding=\"async\" alt=\"Palo Alto Networks NGFW Security Policy Optimizer\" src=\"\/wp-content\/uploads\/2019\/03\/8b4e004f5488e6faa3109c956fb78c31.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n<noindex><a rel=\"nofollow\" name=\"ZeroTrust\"><\/a><\/noindex><\/p>\n<h2>Zero Trust<\/h2>\n<p>\nThere is an approach to security called <noindex><a rel=\"nofollow\" href=\"https:\/\/www.paloaltonetworks.com\/cyberpedia\/what-is-a-zero-trust-architecture\">Zero Trust<\/a><\/noindex>. What this means is that we should allow people inside the network only the connections they need and block everything else. That is, we need to add clear rules regarding applications, users, URL categories, file types; enable all IPS and antivirus signatures, turn on sandboxing, DNS protection, and utilize IOC from available Threat Intelligence databases. Overall, there are quite a few tasks in configuring a firewall. <\/p>\n<p>By the way, the minimum set of necessary configurations for Palo Alto Networks NGFW is described in one of the SANS documents: <noindex><a rel=\"nofollow\" href=\"https:\/\/www.sans.org\/reading-room\/whitepapers\/auditing\/paper\/35777\">Palo Alto Networks Security Configuration Benchmark<\/a><\/noindex> \u2014 I recommend starting with it. Of course, there is also a set of best practices for configuring the firewall from the manufacturer: <noindex><a rel=\"nofollow\" href=\"https:\/\/docs.paloaltonetworks.com\/best-practices\">Best Practice<\/a><\/noindex>.<\/p>\n<p>So, I have had a firewall sitting at home for a week. Let's take a look at the traffic in my network: <br \/>\n<img decoding=\"async\" alt=\"Palo Alto Networks NGFW Security Policy Optimizer\" src=\"\/wp-content\/uploads\/2019\/03\/b3b773f46e892b688f65cc83c7a5ef05.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nIf sorted by the number of sessions, the most are created by bittorrent, then SSL, followed by QUIC. This is combined statistics for both incoming and outgoing traffic: a lot of external scans on my router. There are 150 different applications in my network. <\/p>\n<p>So, all of this was passed with a single rule. Now let's see what the Policy Optimizer has to say about this. If you looked above at the screenshot of the security rules interface, you would have seen a small window at the bottom left hinting that there are rules that can be optimized. Let\u2019s click on that.<\/p>\n<p>What the Policy Optimizer shows:<\/p>\n<ul>\n<li>Which policies have not been used at all, for 30 days, 90 days. This helps to decide to delete them completely.<\/li>\n<li>Which applications were specified in the policies, but such applications were not found in the traffic. This allows you to remove unnecessary applications from the allowing rules.<\/li>\n<li>Which policies allowed everything, but there were real applications that would be good to specify explicitly according to the Zero Trust methodology.<\/li>\n<\/ul>\n<p><img decoding=\"async\" alt=\"Palo Alto Networks NGFW Security Policy Optimizer\" src=\"\/wp-content\/uploads\/2019\/03\/538a51166003e154430c16ff8cd01607.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n<noindex><a rel=\"nofollow\" name=\"Unused\"><\/a><\/noindex><\/p>\n<h3>Let's click on Unused.<\/h3>\n<p>\nTo show how this works, I added a few rules and so far today, none of them have passed any packets. Here\u2019s their list:<br \/>\n<img decoding=\"async\" alt=\"Palo Alto Networks NGFW Security Policy Optimizer\" src=\"\/wp-content\/uploads\/2019\/03\/227bc8339ce96a45370f2e07089eea03.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\nOver time, traffic may go through them, and then they will disappear from this list. If they remain on this list for 90 days\u2014then, you can decide to delete these rules. After all, each rule provides an opportunity for a hacker.<\/p>\n<p>There is a real problem when configuring a firewall: a new employee looks at the firewall rules, and if there are no comments, and he doesn't know why this rule was created, whether it is really needed, or if it can be deleted: what if the person is on vacation and in 30 days the traffic goes back from the necessary service. And this function helps him make a decision\u2014if no one uses it\u2014delete it! <\/p>\n<p><noindex><a rel=\"nofollow\" name=\"UnusedApp\"><\/a><\/noindex><\/p>\n<h3>\n<h3>Let's click on Unused App.<\/h3>\n<p>\nWe click on Unused App in the optimizer and see interesting information open in the main window. <\/p>\n<p>We see that there are three rules where the number of allowed applications differs from the number of applications that actually went through this rule. <br \/>\n<img decoding=\"async\" alt=\"Palo Alto Networks NGFW Security Policy Optimizer\" src=\"\/wp-content\/uploads\/2019\/03\/423bfe9cd60e5236d0edd014eb8dbecd.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\nWe can click and view the list of these applications and compare these lists.<br \/>\nFor example, let\u2019s click the Compare button for the Max rule.<br \/>\n<img decoding=\"async\" alt=\"Palo Alto Networks NGFW Security Policy Optimizer\" src=\"\/wp-content\/uploads\/2019\/03\/1bf1659825811e1478a0d1441e9f5b58.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\nHere we can see that applications such as Facebook, Instagram, Telegram, and Vkontakte were allowed. However, traffic only went through some sub-applications. It's important to understand that the Facebook application contains several sub-applications. <\/p>\n<p>The entire list of NGFW applications can be seen on the portal <noindex><a rel=\"nofollow\" href=\"https:\/\/applipedia.paloaltonetworks.com\/\">applipedia.paloaltonetworks.com<\/a><\/noindex> and in the firewall interface under the Objects-&gt;Applications section. In the search, type the application name: Facebook, and you'll get a result like this:<br \/>\n<img decoding=\"async\" alt=\"Palo Alto Networks NGFW Security Policy Optimizer\" src=\"\/wp-content\/uploads\/2019\/03\/2259b709f372944508dd05343a33deae.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\nSo, part of these NGFW sub-applications was seen, while part was not. In reality, you can separately allow or deny different sub-functions of Facebook. For instance, allow viewing messages but deny chatting or file transfer. Accordingly, the Policy Optimizer reports this, and you can decide to allow not all Facebook applications, but only the main ones.<\/p>\n<p>Thus, we understood that the lists are different. You can configure the rules to allow only those applications that actually accessed the network. For this, you click the MatchUsage button. It looks like this:<br \/>\n<img decoding=\"async\" alt=\"Palo Alto Networks NGFW Security Policy Optimizer\" src=\"\/wp-content\/uploads\/2019\/03\/85137129471774d242f5d7fe1874c9b0.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\nYou can also add applications that you find necessary \u2014 the Add button is located on the left side of the window:<br \/>\n<img decoding=\"async\" alt=\"Palo Alto Networks NGFW Security Policy Optimizer\" src=\"\/wp-content\/uploads\/2019\/03\/23016dea6a835a07e3284b49845596ca.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\nAnd then this rule can be applied and tested. Congratulations!<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"AppsSpecified\"><\/a><\/noindex><\/p>\n<h3>Let's click No Apps Specified.<\/h3>\n<p>\nIn this case, an important security window will open.<br \/>\n<img decoding=\"async\" alt=\"Palo Alto Networks NGFW Security Policy Optimizer\" src=\"\/wp-content\/uploads\/2019\/03\/acac83fdf63c74fe537b4ce37c93e064.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\nThere are likely many rules where no layer 7 application is explicitly specified in your network. In my network, there is such a rule \u2014 I recall that I created it during the initial setup specifically to demonstrate how the Policy Optimizer works.<\/p>\n<blockquote><p>The picture shows that the AllowAll rule allowed 220 gigabytes of traffic over the period from March 9 to March 17, with 150 different applications in my network. This is still a small number. Usually, in a medium-sized corporate network, there are 200-300 different applications.<\/p><\/blockquote>\n<p>\nSo, one rule allows as many as 150 applications. This typically indicates that the firewall is configured incorrectly, as usually, one rule permits 1-10 applications for various purposes. Let's take a look at what these applications are: click the Compare button.<br \/>\n<img decoding=\"async\" alt=\"Palo Alto Networks NGFW Security Policy Optimizer\" src=\"\/wp-content\/uploads\/2019\/03\/50050efc9d6f074d974c36d198447cc9.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\nThe most wonderful feature for administrators in Policy Optimizer is the Match Usage button \u2014 with a single click, you can create a rule that includes all 150 applications. Doing this manually would take quite a long time. The number of tasks for an administrator, even in my network of 10 devices, is enormous.<\/p>\n<blockquote><p>At home, I run 150 different applications that transmit gigabytes of traffic! How many do you have?<\/p><\/blockquote>\n<p>\nAnd what is happening in a network of 100 devices or 1000 or 10,000? I have seen firewalls with 8000 rules, and I am very glad that administrators now have such convenient automation tools.<\/p>\n<p>Some applications that the L7 application analysis module in NGFW identified may not be needed in your network, so you can simply remove them from the allow list, or clone the rules using the Clone button (in the main interface) and permit the applications in one rule while blocking them in another, as they are indeed unnecessary in your network. Such applications often include bittorrent, steam, ultrasurf, tor, hidden tunnels like tcp-over-dns, and others.<br \/>\n<img decoding=\"async\" alt=\"Palo Alto Networks NGFW Security Policy Optimizer\" src=\"\/wp-content\/uploads\/2019\/03\/4aff079413a0995eb5324e7509c6b156.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\nNow let's click on another rule \u2014 what do we see there?<br \/>\n<img decoding=\"async\" alt=\"Palo Alto Networks NGFW Security Policy Optimizer\" src=\"\/wp-content\/uploads\/2019\/03\/73ab263fc788b185d4717a02d91bdffe.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\nYes, here are applications typical for multicast. We need to allow them for video streaming over the network to work. Click Match Usage. Great! Thanks, Policy Optimizer.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"MachineLearning\"><\/a><\/noindex><\/p>\n<h2>What about Machine Learning?<\/h2>\n<p>\nIt's currently fashionable to talk about automation. What I described above helps a lot. There's another capability I need to mention. This is the Machine Learning functionality built into the Expedition utility, which was mentioned earlier. This utility allows you to transfer rules from your old firewall from another vendor. Additionally, it analyzes existing traffic logs from Palo Alto Networks and suggests what rules to write. This is similar to the Policy Optimizer functionality, but in Expedition, it is even more extensive and offers you a list of ready-made rules \u2014 you just need to approve them. <br \/>\n<noindex><a rel=\"nofollow\" name=\"UTD\"><\/a><\/noindex>To test this functionality, there is a laboratory assignment \u2014 we call it a test drive. This test can be performed by accessing the virtual firewalls, which the employees of Palo Alto Networks in Moscow will activate upon your request.<br \/>\n<img decoding=\"async\" alt=\"Palo Alto Networks NGFW Security Policy Optimizer\" src=\"\/wp-content\/uploads\/2019\/03\/1be20da261e12f93736c4607f18299dc.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\nRequests can be sent to Russia@paloaltonetworks.com with the message: 'I want to do a UTD on Migration Process.'<\/p>\n<p>In fact, there are several options for laboratory assignments called Unified Test Drive (UTD) and all of them <noindex><a rel=\"nofollow\" href=\"https:\/\/use.cloudshare.com\/Ent\/CsClient.mvc\/#\/vendor\/welcome\">are available remotely<\/a><\/noindex> after the request.<\/h3>\n<p class=\"for_users_only_msg\">Only registered users can participate in the survey. <noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/auth\/login\/\">Please log in<\/a><\/noindex>, please.<\/p>\n<h2 class=\"default-block__polling-title\">Would you like someone to help you optimize your firewall policies?<\/h2>\n<ul class=\"content-list content-list_polling\">\n<li class=\"content-list__item content-list__item_polling\">\n<p>                    Yes<\/p>\n<\/li>\n<li class=\"content-list__item content-list__item_polling\">\n<p>                    No<\/p>\n<\/li>\n<li class=\"content-list__item content-list__item_polling\">\n<p>                    I will do everything myself<\/p>\n<\/li>\n<\/ul>\n<p>    No one has voted yet. No abstentions.<br \/>\n<br \/>Source: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/post\/444582\/\">habr.com<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041a\u0430\u043a \u043e\u0446\u0435\u043d\u0438\u0442\u044c \u044d\u0444\u0444\u0435\u043a\u0442\u0438\u0432\u043d\u043e\u0441\u0442\u044c \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0438 NGFW \u0421\u0430\u043c\u0430\u044f \u0447\u0430\u0441\u0442\u0430\u044f \u0437\u0430\u0434\u0430\u0447\u0430 \u2014 \u043f\u0440\u043e\u0432\u0435\u0440\u0438\u0442\u044c \u043d\u0430\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u044d\u0444\u0444\u0435\u043a\u0442\u0438\u0432\u043d\u043e \u043d\u0430\u0441\u0442\u0440\u043e\u0435\u043d \u0432\u0430\u0448 \u043c\u0435\u0436\u0441\u0435\u0442\u0435\u0432\u043e\u0439 \u044d\u043a\u0440\u0430\u043d. \u0414\u043b\u044f \u044d\u0442\u043e\u0433\u043e \u0441\u0443\u0449\u0435\u0441\u0442\u0432\u0443\u044e\u0442 \u0431\u0435\u0441\u043f\u043b\u0430\u0442\u043d\u044b\u0435 \u0443\u0442\u0438\u043b\u0438\u0442\u044b \u0438 \u0441\u0435\u0440\u0432\u0438\u0441\u044b \u0443 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0439 \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u0437\u0430\u043d\u0438\u043c\u0430\u044e\u0442\u0441\u044f NGFW. \u041d\u0430\u043f\u0440\u0438\u043c\u0435\u0440, \u043d\u0438\u0436\u0435 \u0432\u0438\u0434\u043d\u043e, \u0447\u0442\u043e \u0443 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Palo Alto Networks \u0435\u0441\u0442\u044c \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u044c \u043f\u0440\u044f\u043c\u043e \u0438\u0437 \u043f\u043e\u0440\u0442\u0430\u043b\u0430 \u043f\u043e\u0434\u0434\u0435\u0440\u0436\u043a\u0438 \u0437\u0430\u043f\u0443\u0441\u0442\u0438\u0442\u044c \u0430\u043d\u0430\u043b\u0438\u0437 \u0441\u0442\u0430\u0442\u0438\u0441\u0442\u0438\u043a\u0438 \u043c\u0435\u0436\u0441\u0435\u0442\u0435\u0432\u043e\u0433\u043e \u044d\u043a\u0440\u0430\u043d\u0430 \u2014 SLR \u043e\u0442\u0447\u0435\u0442 \u0438\u043b\u0438 \u0430\u043d\u0430\u043b\u0438\u0437 \u0441\u043e\u043e\u0442\u0432\u0435\u0442\u0441\u0442\u0432\u0438\u044f \u043b\u0443\u0447\u0448\u0438\u043c [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[],"tags":[],"class_list":["post-29980","post","type-post","status-publish","format-standard","hentry"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041a\u0430\u043a \u043e\u0446\u0435\u043d\u0438\u0442\u044c \u044d\u0444\u0444\u0435\u043a\u0442\u0438\u0432\u043d\u043e\u0441\u0442\u044c \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0438 NGFW \u0421\u0430\u043c\u0430\u044f \u0447\u0430\u0441\u0442\u0430\u044f \u0437\u0430\u0434\u0430\u0447\u0430 \u2014 \u043f\u0440\u043e\u0432\u0435\u0440\u0438\u0442\u044c \u043d\u0430\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u044d\u0444\u0444\u0435\u043a\u0442\u0438\u0432\u043d\u043e \u043d\u0430\u0441\u0442\u0440\u043e\u0435\u043d \u0432\u0430\u0448 \u043c\u0435\u0436\u0441\u0435\u0442\u0435\u0432\u043e\u0439 \u044d\u043a\u0440\u0430\u043d.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/optimizator-politik-bezopasnosti-palo-alto-networks-ngfw\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041e\u043f\u0442\u0438\u043c\u0438\u0437\u0430\u0442\u043e\u0440 \u043f\u043e\u043b\u0438\u0442\u0438\u043a \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 Palo Alto Networks NGFW | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041a\u0430\u043a \u043e\u0446\u0435\u043d\u0438\u0442\u044c \u044d\u0444\u0444\u0435\u043a\u0442\u0438\u0432\u043d\u043e\u0441\u0442\u044c \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0438 NGFW \u0421\u0430\u043c\u0430\u044f \u0447\u0430\u0441\u0442\u0430\u044f \u0437\u0430\u0434\u0430\u0447\u0430 \u2014 \u043f\u0440\u043e\u0432\u0435\u0440\u0438\u0442\u044c \u043d\u0430\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u044d\u0444\u0444\u0435\u043a\u0442\u0438\u0432\u043d\u043e \u043d\u0430\u0441\u0442\u0440\u043e\u0435\u043d \u0432\u0430\u0448 \u043c\u0435\u0436\u0441\u0435\u0442\u0435\u0432\u043e\u0439 \u044d\u043a\u0440\u0430\u043d.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/optimizator-politik-bezopasnosti-palo-alto-networks-ngfw\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T18:32:59+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T18:32:59+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Palo Alto Networks NGFW Policy Optimizer | ProHoster","description":"How to assess the effectiveness of NGFW configuration? The most common task is to check how effectively your firewall is configured.","canonical_url":"https:\/\/prohoster.info\/en\/blog\/optimizator-politik-bezopasnosti-palo-alto-networks-ngfw","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041e\u043f\u0442\u0438\u043c\u0438\u0437\u0430\u0442\u043e\u0440 \u043f\u043e\u043b\u0438\u0442\u0438\u043a \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 Palo Alto Networks NGFW | ProHoster","og:description":"\u041a\u0430\u043a \u043e\u0446\u0435\u043d\u0438\u0442\u044c \u044d\u0444\u0444\u0435\u043a\u0442\u0438\u0432\u043d\u043e\u0441\u0442\u044c \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0438 NGFW \u0421\u0430\u043c\u0430\u044f \u0447\u0430\u0441\u0442\u0430\u044f \u0437\u0430\u0434\u0430\u0447\u0430 \u2014 \u043f\u0440\u043e\u0432\u0435\u0440\u0438\u0442\u044c \u043d\u0430\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u044d\u0444\u0444\u0435\u043a\u0442\u0438\u0432\u043d\u043e \u043d\u0430\u0441\u0442\u0440\u043e\u0435\u043d \u0432\u0430\u0448 \u043c\u0435\u0436\u0441\u0435\u0442\u0435\u0432\u043e\u0439 \u044d\u043a\u0440\u0430\u043d.","og:url":"https:\/\/prohoster.info\/en\/blog\/optimizator-politik-bezopasnosti-palo-alto-networks-ngfw","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T18:32:59+00:00","article:modified_time":"2019-10-31T18:32:59+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"29980","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"Article","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-20 23:17:19","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 03:44:39","updated":"2026-01-20 23:17:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/29980","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=29980"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/29980\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=29980"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=29980"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=29980"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}