<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cortex XDR Host Firewall Rule evaluation in Cortex XSIAM Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/cortex-xdr-host-firewall-rule-evaluation/m-p/1247948#M344</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/328168"&gt;@Lakshminarayan&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Greetings for the day.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes, your understanding is correct. In this scenario, the Host Firewall will allow the outbound traffic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The Cortex XSIAM/XDR Host Firewall evaluates rules using a&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;top-down&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;approach, where the first rule that matches the traffic criteria is applied.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is how the evaluation logic works for your specific example:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt;Direction Matching:&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;The firewall checks the traffic direction (Inbound vs. Outbound) as a primary matching criterion. "Inbound" rules only match traffic initiating from a remote source to the local host, while "Outbound" rules match traffic initiating from the local host to a remote destination.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Sequential Processing:&lt;/STRONG&gt;
&lt;UL&gt;
&lt;LI&gt;When&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Outbound&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;traffic is initiated, the firewall evaluates the first rule (your Inbound rule). Since the direction does not match (the traffic is Outbound, but the rule is Inbound), this rule is skipped.&lt;/LI&gt;
&lt;LI&gt;The firewall proceeds to the next rule (your Outbound rule). The direction matches (Outbound), and since it is configured to "Allow all," the traffic matches and is&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Allowed&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Because the Inbound rule does not match the criteria for Outbound traffic, it does not block or interfere with it. The rules function independently based on the direction of the connection.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking like and on&amp;nbsp;&lt;STRONG&gt;"mark this as a Solution".&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards,&lt;BR /&gt;S. Subashkar Sekar&lt;/P&gt;</description>
    <pubDate>Wed, 11 Feb 2026 14:43:33 GMT</pubDate>
    <dc:creator>susekar</dc:creator>
    <dc:date>2026-02-11T14:43:33Z</dc:date>
    <item>
      <title>Cortex XDR Host Firewall Rule evaluation</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/cortex-xdr-host-firewall-rule-evaluation/m-p/1227036#M180</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;
&lt;P&gt;I have a doubt about Host Firewall rule evaluation. Let say i have a rule created to allow all internal application inbound traffic on specific port / Remote IP. In the same rule group if i create another outbound rule and action type : allow all outbound traffic on any port/IP how it will evaluate the rule. It means it will allow all outbound traffic right.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Apr 2025 07:27:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/cortex-xdr-host-firewall-rule-evaluation/m-p/1227036#M180</guid>
      <dc:creator>Lakshminarayan</dc:creator>
      <dc:date>2025-04-22T07:27:26Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Host Firewall Rule evaluation</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/cortex-xdr-host-firewall-rule-evaluation/m-p/1247948#M344</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/328168"&gt;@Lakshminarayan&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Greetings for the day.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes, your understanding is correct. In this scenario, the Host Firewall will allow the outbound traffic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The Cortex XSIAM/XDR Host Firewall evaluates rules using a&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;top-down&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;approach, where the first rule that matches the traffic criteria is applied.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is how the evaluation logic works for your specific example:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt;Direction Matching:&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;The firewall checks the traffic direction (Inbound vs. Outbound) as a primary matching criterion. "Inbound" rules only match traffic initiating from a remote source to the local host, while "Outbound" rules match traffic initiating from the local host to a remote destination.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Sequential Processing:&lt;/STRONG&gt;
&lt;UL&gt;
&lt;LI&gt;When&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Outbound&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;traffic is initiated, the firewall evaluates the first rule (your Inbound rule). Since the direction does not match (the traffic is Outbound, but the rule is Inbound), this rule is skipped.&lt;/LI&gt;
&lt;LI&gt;The firewall proceeds to the next rule (your Outbound rule). The direction matches (Outbound), and since it is configured to "Allow all," the traffic matches and is&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Allowed&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Because the Inbound rule does not match the criteria for Outbound traffic, it does not block or interfere with it. The rules function independently based on the direction of the connection.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking like and on&amp;nbsp;&lt;STRONG&gt;"mark this as a Solution".&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards,&lt;BR /&gt;S. Subashkar Sekar&lt;/P&gt;</description>
      <pubDate>Wed, 11 Feb 2026 14:43:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/cortex-xdr-host-firewall-rule-evaluation/m-p/1247948#M344</guid>
      <dc:creator>susekar</dc:creator>
      <dc:date>2026-02-11T14:43:33Z</dc:date>
    </item>
  </channel>
</rss>

