Dell PowerConnect W-IAP3WN/P User Manual Page 267

  • Download
  • Add to my manuals
  • Print
  • Page
    / 377
  • Table of contents
  • TROUBLESHOOTING
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 266
In the CLI
To configure OpenDNS credentials:
(Instant AP)(config)# opendns <username <password>
(Instant AP)(config)# end
(Instant AP)# commit apply
Integrating a W-IAP with Palo Alto Networks Firewall
Palo Alto Networks (PAN) next-generation firewall offers contextual security for all users for safe enabling of
applications. A simple firewall beyond basic IP address or TCP port numbers only provides a subset of the enhanced
security required for enterprises to secure their networks. In the context of businesses using social networking sites,
legacy firewalls are not able to differentiate valid authorized users from casual social networking users.
The Palo Alto next-generation firewall is based on user ID, which provides many methods for connecting to sources
of identity information and associating them with firewall policy rules. For example, it provides an option to gather
user information from Active Directory or LDAP server.
Integration with Instant
The functionality provided by the PAN firewall based on user ID requires the collection of information from the
network. W-IAP maintains the network (such as mapping IP address) and user information for its clients in the
network and can provide the required information for the user ID feature on PAN firewall. Before sending the user-ID
mapping information to the PAN firewall, the W-IAP must retrieve an API key that will be used for authentication for
all APIs.
W-IAP and PAN firewall integration can be seamless with the XML-API that available with PAN-OS 5.0 or later.
To integrate a W-IAP with PAN user ID, a global profile is added. This profile can be configured on a W-IAP with
PAN firewall information such as IP address, port, user name, password, firewall enabled or disabled status.
The W-IAP sends messages to PAN based on the type of authentication and client status:
l After a client completes the authentication and is assigned an ip address, W-IAP will send the login message.
l After a client is disconnected or dissociated from the W-IAP, the W-IAP sends a logout message.
Configuring a W-IAP for PAN integration
You can configure a W-IAP for PAN firewall integration using the Instant UI or CLI.
In the Instant UI
1. Click More > Services. The Services window is displayed.
2. Click Network Integration. The PAN firewall configuration options are displayed.
Dell Networking W-Series Instant 6.4.0.2-4.1 | User Guide Services | 267
Page view 266
1 2 ... 262 263 264 265 266 267 268 269 270 271 272 ... 376 377

Comments to this Manuals

No comments