data:image/s3,"s3://crabby-images/f28e4/f28e440b3f1717d5d34ed3bde155211d3524fd20" alt=""
In case there are sources attempting malicious attempts at your environment, we can blacklist them automatically if they exceed a certain severity threshold and tag them, so they are automatically denied by a security policy rather than going through another security phase over and over. Basically quarantining them.
Create a tag
Go to Objects > Tag
data:image/s3,"s3://crabby-images/96fe1/96fe1706bb6b02a2fe21145a733b3a71de17f742" alt=""
As you can see I’ve named it “Quarantaine-addresses”. Choose a color of your choice and add a comment.
Creating a log forwarding profile
Go to Objects Log Forwarding
data:image/s3,"s3://crabby-images/f210c/f210c939dedb8b88f38691dad735a5c749166304" alt=""
I’ve configured the src zone to be my “WAN” security zone and the destination zone “DMZ”, with a severity of greater of equal than medium. And a couple of exception are made. Select the log type as threat.
After this, you’ll have to configure Built-in Actions, see the following screenshot how I’ve configured it. Make sure to select the tag that you created earlier.
data:image/s3,"s3://crabby-images/36424/36424d7944135d34794be8d5e6df7554e7ae853b" alt=""
Address groups
We’ll need to maintain a list of addresses in a group to blacklist, here’s how we configure it.
Go to Objects > Addresses groups
data:image/s3,"s3://crabby-images/a5f20/a5f20bb5c199fff88ade55b1acdb90ef443d0d82" alt=""
Select the “Quarantaine-addresses” tag address we created.
Adding a security policy to block the quarantaine addresses.
I already have a block security profile in-place for my webserver, so all I’ve had to do it is add the address group.
data:image/s3,"s3://crabby-images/1a0ca/1a0ca4b6aecdcc93a9621a6832df6f7f89c49c41" alt=""
data:image/s3,"s3://crabby-images/b07b2/b07b2b0800d58309282165b94528ff3b9957cfc7" alt=""
Here we can see “DAG-quarantaine” address group included in the source address field.
Checking which IP addresses are blocked
This has to be done on the firewall itself, Panorama will not show it.
data:image/s3,"s3://crabby-images/eed53/eed5326c0b36814110b8ad5a8bed52b998809ab8" alt=""
data:image/s3,"s3://crabby-images/76c9a/76c9a6104b6b56f7f88a26a20ae7eb1a6f7e2cc5" alt=""
Here we can see the list of IP addresses that are blocked and we can unregister them by clicking on “Unregister tags” in case of a false positive. There’s also a search bar to easily find the IP address that you’re looking for.