Skip to content

Instantly share code, notes, and snippets.

View vin18-byte's full-sized avatar

Vineeth vin18-byte

View GitHub Profile
@vin18-byte
vin18-byte / palo_alto_block_non_compliant_apps.yml
Created July 15, 2025 17:57
This Ansible playbook ensures compliance with HIPAA/PCI-DSS by automatically blocking insecure applications (e.g., Telnet, FTP, SMB) on Palo Alto firewalls. Designed for automated audits and real-time policy remediation.
---
- name: Enforce policy to block non-compliant apps on Palo Alto
hosts: palo_fw
gather_facts: no
vars:
denied_apps:
- telnet
- ftp
- smb
---
- name: Deploy NAT and Security policies on Palo Alto Firewall
hosts: palo_fw
gather_facts: no
vars:
nat_rule_name: "NAT-Allow-HTTPS"
source_zone: "untrust"
dest_zone: "dmz"
source_ip: "203.0.113.25"
dest_ip: "10.0.2.10"