<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Fortinet Migration - Internet Services Database objects  conversion to Palo Alto in Expedition Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/expedition-discussions/fortinet-migration-internet-services-database-objects-conversion/m-p/525545#M4321</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/138808"&gt;@Gordan&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In Palo Alto there is no such thing as an internet service database.&lt;/P&gt;
&lt;P&gt;It has for Microsoft services example EDL that you can generate for this.&lt;BR /&gt;&lt;A href="https://docs.paloaltonetworks.com/resources/edl-hosting-service" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/resources/edl-hosting-service&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;EDLs are dynamic lists containing the IP URL domains of certain Microsoft 365, Azure, AWS, Salesforce, GCP services for example provided by Palo Alto but you can also generate your own.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here although it sounds like a bit more effort, I recommend the following:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That you identify in Fortinet those policies with Internet Service Database and rule by rule, filter in fortinet the destinations either URLs, IPs, domains, subdomains, and based on that information that you collect you close the any rules in Palo Alto, only with the destinations that you need and thus avoid those any.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers&lt;/P&gt;</description>
    <pubDate>Fri, 30 Dec 2022 20:00:30 GMT</pubDate>
    <dc:creator>Metgatz</dc:creator>
    <dc:date>2022-12-30T20:00:30Z</dc:date>
    <item>
      <title>Fortinet Migration - Internet Services Database objects  conversion to Palo Alto</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/fortinet-migration-internet-services-database-objects-conversion/m-p/524849#M4315</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;A Fortigate firewall uses Fortinet 'Internet Services' objects. There are many of them, they are predefined and some of them contain several tens of thousands of IP addresses (Amazon-AWS object, for example currently contains 75114 objects, there are various objects for Microsoft services, Adobe services, etc).&lt;/P&gt;
&lt;P&gt;Expedition tool converts those multiple (destination) objects as 'all', therefore creating an 'allow all' rule (from the defined source to all objects in the destination zone (Internet) allowing all services and with all applications.&lt;BR /&gt;This does not seem right because it essentially nullifies all other, tight, rules from the source address.&lt;BR /&gt;Is there any way to avoid this and create tight rules for these services?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Dec 2022 11:03:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/fortinet-migration-internet-services-database-objects-conversion/m-p/524849#M4315</guid>
      <dc:creator>Gordan</dc:creator>
      <dc:date>2022-12-22T11:03:16Z</dc:date>
    </item>
    <item>
      <title>Re: Fortinet Migration - Internet Services Database objects  conversion to Palo Alto</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/fortinet-migration-internet-services-database-objects-conversion/m-p/525545#M4321</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/138808"&gt;@Gordan&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In Palo Alto there is no such thing as an internet service database.&lt;/P&gt;
&lt;P&gt;It has for Microsoft services example EDL that you can generate for this.&lt;BR /&gt;&lt;A href="https://docs.paloaltonetworks.com/resources/edl-hosting-service" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/resources/edl-hosting-service&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;EDLs are dynamic lists containing the IP URL domains of certain Microsoft 365, Azure, AWS, Salesforce, GCP services for example provided by Palo Alto but you can also generate your own.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here although it sounds like a bit more effort, I recommend the following:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That you identify in Fortinet those policies with Internet Service Database and rule by rule, filter in fortinet the destinations either URLs, IPs, domains, subdomains, and based on that information that you collect you close the any rules in Palo Alto, only with the destinations that you need and thus avoid those any.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers&lt;/P&gt;</description>
      <pubDate>Fri, 30 Dec 2022 20:00:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/fortinet-migration-internet-services-database-objects-conversion/m-p/525545#M4321</guid>
      <dc:creator>Metgatz</dc:creator>
      <dc:date>2022-12-30T20:00:30Z</dc:date>
    </item>
  </channel>
</rss>

