CIS Palo Alto Firewall 10 v1.0.0 L2

Warning! Audit Deprecated

This audit file has been deprecated and will be removed in a future update.

View Next Version

Audit Details

Name: CIS Palo Alto Firewall 10 v1.0.0 L2

Updated: 7/11/2023

Authority: CIS

Plugin: Palo_Alto

Revision: 1.5

Estimated Item Count: 16

File Details

Filename: CIS_Palo_Alto_Firewall_10_Benchmark_v1.0.0_L2.audit

Size: 130 kB

MD5: acaf3df501eec742398790cd9fd1d2ff
SHA256: 43bdce4b1cf6a2779490b5651c41d1a6448983dbe1b297374dbbaa9bf832e682

Audit Changelog

 
Revision 1.5

Jul 11, 2023

Miscellaneous
  • Audit deprecated.
  • Metadata updated.
  • References updated.
Revision 1.4

Mar 7, 2023

Miscellaneous
  • Metadata updated.
  • References updated.
Revision 1.3

Jan 4, 2023

Miscellaneous
  • Metadata updated.
Revision 1.2

Dec 7, 2022

Miscellaneous
  • Variables updated.
Revision 1.1

Aug 11, 2022

Functional Update
  • 1.1.1.2 SNMPv3 traps should be configured - configuration
  • 1.1.1.2 SNMPv3 traps should be configured - hip match
  • 1.1.1.2 SNMPv3 traps should be configured - host
  • 1.1.1.2 SNMPv3 traps should be configured - ip-tag
  • 1.1.1.2 SNMPv3 traps should be configured - user-id
  • 1.6.3 Ensure that the Certificate Securing Remote Access VPNs is Valid - Certificates
  • 1.6.3 Ensure that the Certificate Securing Remote Access VPNs is Valid - GlobalProtect Gateways
  • 1.6.3 Ensure that the Certificate Securing Remote Access VPNs is Valid - GlobalProtect Portals
  • 2.1 Ensure that IP addresses are mapped to usernames - User ID Agents
  • 2.1 Ensure that IP addresses are mapped to usernames - Zones
  • 2.2 Ensure that WMI probing is disabled
  • 6.17 Ensure that a Zone Protection Profile with tuned Flood Protection settings enabled for all flood types is attached to all untrusted zones
  • 7.1 Ensure application security policies exist when allowing traffic from an untrusted zone to a more trusted zone
  • 8.3 Ensure that the Certificate used for Decryption is Trusted
Miscellaneous
  • Platform check updated.
  • References updated.
Added
  • 1.2.5 Ensure valid certificate is set for browser-based administrator interface
Removed
  • 1.2.5 Ensure valid certificate is set for browser-based administrator interface - Authentication Profile
  • 1.2.5 Ensure valid certificate is set for browser-based administrator interface - Certificate Profiles
  • 1.2.5 Ensure valid certificate is set for browser-based administrator interface - Certificates
Revision 1.0

Jul 15, 2022

Miscellaneous
  • Metadata updated.