How to change the default profile for your vsys

A knowledge base article about How to change the default profile for your vsys provided by the UC Berkeley IT Service Hub - Knowledge Portal

For many campus firewall administrators, the Panorama “Security Profiles” and “Security Profiles Groups” created by the Information Security Office (ISO) should represent an acceptable balance between security and functionality and should work for most of their needs. These shared profiles can be identified by their name starting with “ucbsec-”  and by their location in the Global Device Group. Further, the recommended settings have been grouped together into a default Profile group that will be assigned to new rules when they are created. If it is necessary for the majority of rules to get a profile group that is different from the default profile group then the following steps should be taken:

 

Below are the steps to modify the default profile group with a custom File Blocking profile. For information on creating a custom profile see the instructions at https://ucb.service-now.com/kb_view.do?sysparm_article=KBT0012686

  1.  Log into https://panorama.net.berkeley.edu using single sign-on
  2. From the tabs at the top of the window choose “Objects”
  3. In the column on the left chose “Security Profile Groups” 
    Screenshot showing security profiles list
  4. In the main window open the profile group named “default” and note the settings in case you should want or need to revert later.
  5. With the “default” security profile group selected, click on the “Override” option at the bottom of the window.
    Screenshot showing "default" security group selected with option to select "override" at the bottom
  6. From the “Security Profile Group” window for the default profile change any profiles. In this example the profile being changed is the File Blocking Profile
    Screenshot of security profile group page
  7. Click “OK”
  8. From the “Commit” menu near the top of the screen chose “Commit to Panorama“ and then when the commit option is finished, from the same menu select “Push to Device”
    Screenshot showing option to select "commit" and "commit to panorama"

 

Once this has been done, the default Profile Group will have the new profile associated with it.

 

PLEASE NOTE: This change will not only be in place for any new rules created, but will also affect any rules that were already created and had the default “Security Profile Group” assigned.