A knowledge base article about How to Identify the Individual Profiles in a Security Profile Group provided by the UC Berkeley IT Service Hub - Knowledge Portal
Table of Contents
On the Palo Alto Firewall Platform, profiles are a collection of security settings that address individual areas of security (e.g., virus detection, file type restrictions, etc.) and are applied to firewall rules. The Information Security Office (ISO) publishes several profiles for campus use.
While profiles can be assigned individually to rules, it is generally advisable to use them as part of a Profile Group (a defined collection of profiles). This ensures consistency across multiple similar rules. ISO has established several Profile Groups recommended for different environments, such as servers vs. end-users or restricted vs. non-restricted data networks.
ucbsec- prefix.RD are specifically configured for Restricted Data systems or users.Note: These profiles are subject to change as new features are added or threats are discovered. The examples below represent current standards.
In the main window, open the profile group you wish to review. In this example, we are examining the default security group for high-security campus users.
By examining the group, you can identify which specific profiles are active. In this example, the group uses:
ucbsec-AV_standarducbsec-RD_AS_allucbsec-RD_VP_allucbsec-url_filterucbsec-RD_FB_on-campusucbsec-wildfire_cloudNote: A Data Filtering Profile is not shown as those are typically determined at the local departmental level.
To see the specific settings that make up each of the security profiles listed above, please refer to the following articles: