The Best Practice Assessment (BPA) is a tool provided by Palo Alto Networks that evaluates your Next-Generation Firewall (NGFW) and Panorama configurations against established best practices. It performs over 200 checks to identify potential misconfigurations and provides actionable recommendations to enhance your security posture.
Key features include:
Learn more: Best Practice Assessment for NGFW and Panorama
The BPA heatmap provides a visual representation of how well your security policies align with best practices. It uses color-coding to indicate areas of strength and those needing improvement.
The heatmap helps in:
Watch an introduction to BPA heatmaps: BPA Tool - Intro to Heatmaps
To perform a BPA:
Detailed instructions: Dashboard: On Demand BPA
Video tutorial: Understanding the Best Practice Assessment (BPA) Tool
To evaluate your Palo Alto Networks firewall or Panorama configurations against best practices, follow these steps to generate a BPA report:
The TSF contains the necessary configuration and system information required for the BPA. To generate it:
The BPA tool is integrated into AIOps for NGFW. To access it:
Within AIOps for NGFW:
To initiate the BPA:
Once the TSF is processed:
For a visual walkthrough, you can refer to the following video:
Regularly running BPAs allows organizations to:
For a comprehensive guide on implementing best practices: Identify and Prioritize Best Practices