How to Identify the Individual Profiles in a Security Profile Group

A knowledge base article about How to Identify the Individual Profiles in a Security Profile Group provided by the UC Berkeley IT Service Hub - Knowledge Portal

Table of Contents

Overview

On the Palo Alto Firewall Platform, profiles are a collection of security settings that address individual areas of security (e.g., virus detection, file type restrictions, etc.) and are applied to firewall rules. The Information Security Office (ISO) publishes several profiles for campus use.

While profiles can be assigned individually to rules, it is generally advisable to use them as part of a Profile Group (a defined collection of profiles). This ensures consistency across multiple similar rules. ISO has established several Profile Groups recommended for different environments, such as servers vs. end-users or restricted vs. non-restricted data networks.

Naming Conventions

Note: These profiles are subject to change as new features are added or threats are discovered. The examples below represent current standards.

How to Identify Profiles within a Group

  1. Log into https://panorama.net.berkeley.edu using single sign-on.
  2. Select the Objects tab from the top navigation bar.
  3. In the left-hand column, select Security Profile Groups.
    Panorama sidebar showing the Security Profile Groups option highlighted under the Objects tab.
  4. In the main window, open the profile group you wish to review. In this example, we are examining the default security group for high-security campus users.

    The configuration window for a Security Profile Group showing the specific profiles assigned to each category.
  5. By examining the group, you can identify which specific profiles are active. In this example, the group uses:

    • Anti-Virus: ucbsec-AV_standard
    • Anti-Spyware: ucbsec-RD_AS_all
    • Vulnerability: ucbsec-RD_VP_all
    • URL Filtering: ucbsec-url_filter
    • File Blocking: ucbsec-RD_FB_on-campus
    • WildFire Analysis: ucbsec-wildfire_cloud

    Note: A Data Filtering Profile is not shown as those are typically determined at the local departmental level.

Detailed Security Profile Guides

To see the specific settings that make up each of the security profiles listed above, please refer to the following articles: