How to change the default profile for your vsys

A knowledge base article about How to change the default profile for your vsys provided by the UC Berkeley IT Service Hub - Knowledge Portal

Table of Contents

Overview

For many campus firewall administrators, the Panorama “Security Profiles” and “Security Profile Groups” created by the Information Security Office (ISO) represent an acceptable balance between security and functionality. These shared profiles are identified by names starting with ucbsec- and are located in the Global Device Group.

The recommended settings are bundled into a default Profile Group that is automatically assigned to new rules. If your specific environment requires a different baseline for the majority of your rules, follow the steps below to modify that default behavior.

Note: This guide specifically covers overriding the default group with a custom profile. For instructions on creating a custom profile, see KB0012866 - How to Customize a Security Profile.


Steps to Modify the Default Profile Group

  1. Log into https://panorama.net.berkeley.edu using single sign-on.
  2. Select the Objects tab from the top navigation bar.
  3. In the left-hand column, choose Security Profile Groups.
    Panorama sidebar menu with the Security Profile Groups option selected under the Objects tab.
  4. In the main window, locate the profile group named default. Open it and note the current settings in case you need to revert to them later.
  5. With the default group selected, click the Override button at the bottom of the window.
    Panorama bottom menu bar showing the Override button highlighted for the default group.
  6. In the Security Profile Group window, use the drop-down menus to change the desired profiles. (In this example, we are updating the File Blocking Profile).
    Security Profile Group settings window with dropdown menus for selecting Antivirus, File Blocking, and other profiles.
  7. Click OK.
  8. From the Commit menu at the top of the screen, choose Commit to Panorama. Once finished, select Push to Device from the same menu.
    Panorama Commit menu dropdown with options for Commit to Panorama and Push to Device.

Important: Impact on Existing Rules

CRITICAL NOTICE: Overriding the default profile group is a global change for your vsys. This modification will apply to all new rules you create AND any existing rules that currently have the default Security Profile Group assigned.