Skip to content

Commit

Permalink
Revert "Update-PaloAlto-Connection (#376)" (#378)
Browse files Browse the repository at this point in the history
This reverts commit de32d50.
  • Loading branch information
thomast1906 authored Jan 8, 2025
1 parent de32d50 commit 9859000
Show file tree
Hide file tree
Showing 3 changed files with 69 additions and 11 deletions.
61 changes: 61 additions & 0 deletions source/network/F5AdminPortal.html.md.erb
Original file line number Diff line number Diff line change
@@ -0,0 +1,61 @@
---
title: Palo Alto Admin Portal
last_reviewed_on: 2024-09-20
review_in: 6 months
weight: 10
---

# <%= current_page.data.title %>

## UK South

You can connect to the Palo VMs via the HMCTS VPN by following the following steps:

### Sandbox

1. Create the NSG rule to allow your IP on port 443. (Example and links to VMs below).
2. Retrieve the url of the Palo VM you want to connect to via the 'Virtual machines' section below.
3. (skip in production which is SSO enabled) Retrieve the admin password from the sandbox key vault:

```bash
az keyvault secret show --vault-name hmcts-infra-dmz-sbox-int --name firewall-password --query value -o tsv
```

4. Use the local account `localadmin` to log in.

#### Sandbox Virtual Machines

- [hmcts-hub-sbox-int-palo-vm-0](https://portal.azure.com/#@HMCTS.NET/resource/subscriptions/ea3a8c1e-af9d-4108-bc86-a7e2d267f49c/resourceGroups/hmcts-hub-sbox-int/providers/Microsoft.Compute/virtualMachines/hmcts-hub-sbox-int-palo-vm-0/overview) - https://hmcts-hub-sbox-int-palo-mgmt-0.uksouth.cloudapp.azure.com
- [hmcts-hub-sbox-int-palo-vm-1](https://portal.azure.com/#@HMCTS.NET/resource/subscriptions/ea3a8c1e-af9d-4108-bc86-a7e2d267f49c/resourceGroups/hmcts-hub-sbox-int/providers/Microsoft.Compute/virtualMachines/hmcts-hub-sbox-int-palo-vm-1/overview) - https://hmcts-hub-sbox-int-palo-mgmt-1.uksouth.cloudapp.azure.com

### Non-prod

1. Connect to the [HMCTS VPN](https://portal.platform.hmcts.net/).
2. Retrieve the url of the Palo VM you want to connect to via the 'Virtual machines' section below.
3. Retrieve the admin password from the relevant key vault:

```bash
# Non production
az keyvault secret show --vault-name hmcts-infra-dmz-nonprodi --name firewall-password --query value -o tsv
```

4. Use the local account `localadmin`

#### Non-prod virtual machines

- [hmcts-hub-nonprodi-palo-vm-0](https://portal.azure.com/#@HMCTS.NET/resource/subscriptions/fb084706-583f-4c9a-bdab-949aac66ba5c/resourceGroups/hmcts-hub-nonprodi/providers/Microsoft.Compute/virtualMachines/hmcts-hub-nonprodi-palo-vm-0/overview) - https://hmcts-hub-nonprodi-palo-mgmt-0.uksouth.cloudapp.azure.com
- [hmcts-hub-nonprodi-palo-vm-1](https://portal.azure.com/#@HMCTS.NET/resource/subscriptions/fb084706-583f-4c9a-bdab-949aac66ba5c/resourceGroups/hmcts-hub-nonprodi/providers/Microsoft.Compute/virtualMachines/hmcts-hub-nonprodi-palo-vm-1/overview) - https://hmcts-hub-nonprodi-palo-mgmt-1.uksouth.cloudapp.azure.com

### Production

1. Connect to the [HMCTS VPN](https://portal.platform.hmcts.net/).
2. Retrieve the url of the Palo VM you want to connect to via the 'Virtual machines' section below.
3. Click 'Use Single Sign-On'.
4. Press 'Continue' leaving the first text box prompt empty.

#### Prod Virtual machines

- [hmcts-hub-prod-int-palo-vm-0](https://portal.azure.com/#@HMCTS.NET/resource/subscriptions/0978315c-75fe-4ada-9d11-1eb5e0e0b214/resourceGroups/hmcts-hub-prod-int/providers/Microsoft.Compute/virtualMachines/hmcts-hub-prod-int-palo-vm-0/overview) - https://uksouth-prod-palo-0.platform.hmcts.net
- [hmcts-hub-prod-int-palo-vm-1](https://portal.azure.com/#@HMCTS.NET/resource/subscriptions/0978315c-75fe-4ada-9d11-1eb5e0e0b214/resourceGroups/hmcts-hub-prod-int/providers/Microsoft.Compute/virtualMachines/hmcts-hub-prod-int-palo-vm-1/overview) - https://uksouth-prod-palo-1.platform.hmcts.net

---
18 changes: 7 additions & 11 deletions source/network/connecting-palos.html.md.erb
Original file line number Diff line number Diff line change
@@ -1,22 +1,18 @@
---
title: Connecting to a Palo Alto firewall
weight: 60
last_reviewed_on: 2025-01-06
last_reviewed_on: 2024-07-12
review_in: 6 months
---

# <%= current_page.data.title %>

This page provides information on how to connect to a Palo Alto firewall.
### SSO login steps
## UK South

## SSO login steps
Panorama is a centralized management system that provides global visibility and control over multiple Palo Alto Networks next generation firewalls through an easy-to-use web-base interface.
You can connect to the Palo VMs via the HMCTS VPN by following the following steps:

### Prerequisite
- VPN connection via F5
- Active HMCTS or Justice account

### Open Panorama
### Sandbox

1. Connect to the [HMCTS VPN](https://portal.platform.hmcts.net/).
2. Retrieve the url of the Palo VM you want to connect to via the 'Virtual machines' section below.
Expand All @@ -40,7 +36,7 @@ Panorama is a centralized management system that provides global visibility and
- [panorama sandbox](https://panorama-sandbox.hmcts.net)
- [panorama production](https://panorama.hmcts.net)

### Access All systems via F5 VPN:
### Access All systems via VPN:

#### Panorama
- [panorama-sbox](https://panorama-sbox-uks-0.sandbox.platform.hmcts.net)
Expand Down Expand Up @@ -77,7 +73,7 @@ Panorama is a centralized management system that provides global visibility and
- [hmcts-hub-prod-int-palo-vm-0](https://portal.azure.com/#@HMCTS.NET/resource/subscriptions/0978315c-75fe-4ada-9d11-1eb5e0e0b214/resourceGroups/hmcts-hub-prod-int/providers/Microsoft.Compute/virtualMachines/hmcts-hub-prod-int-palo-vm-0/overview)
- [hmcts-hub-prod-int-palo-vm-1](https://portal.azure.com/#@HMCTS.NET/resource/subscriptions/0978315c-75fe-4ada-9d11-1eb5e0e0b214/resourceGroups/hmcts-hub-prod-int/providers/Microsoft.Compute/virtualMachines/hmcts-hub-prod-int-palo-vm-1/overview)

### SSH to PaloAlto VMs
#### SSH to PaloAlto VMs

This needs done from Bastion server and ssh using the private IP from the Virtual machines in Azure. Get the credentials from Key Vault (for example `hmcts-infra-hub-prod-int` for production) for the `firewall-username` and `firewall-password`.

Expand Down
1 change: 1 addition & 0 deletions source/network/index.html.md.erb
Original file line number Diff line number Diff line change
Expand Up @@ -23,6 +23,7 @@ weight: 70

## F5

- [Admin Portal](F5AdminPortal.html)
- [User Accounts](accounts.html)
- [Setup access to internal apps](VPN-routing-config.html)
- [Troubleshooting Clients](f5-troubleshooting-clients.html)
Expand Down

0 comments on commit 9859000

Please sign in to comment.