<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Security Policy in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/security-policy/m-p/568147#M2203</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have created a security policy with the below details. I am the hitting following URL &lt;A href="https://10.x.x.x:15671" target="_blank"&gt;https://10.x.x.x:15671&lt;/A&gt;&amp;nbsp;and I see the 'connection is reset' in the browser. I see traffic is hitting the policy (Hit count) but it's not logging. When I set the action to Deny/Drop/reset-client\reset-server the traffic is logging when hits the rule. What could be the reason why traffic is not logging for action 'Allow' and why traffic is not passing through?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Application - Any&lt;/P&gt;
&lt;P&gt;Services - Application default&lt;/P&gt;
&lt;P&gt;Action - Allow&lt;/P&gt;
&lt;P&gt;Logging - Log st session start and end&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Srikar&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="srikarpuligandla_0-1701627610318.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/55630i36B1D9E4F1125811/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="srikarpuligandla_0-1701627610318.png" alt="srikarpuligandla_0-1701627610318.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="srikarpuligandla_1-1701627668060.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/55631iFDBD9D58815421EF/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="srikarpuligandla_1-1701627668060.png" alt="srikarpuligandla_1-1701627668060.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 03 Dec 2023 18:21:45 GMT</pubDate>
    <dc:creator>srikarpuligandla</dc:creator>
    <dc:date>2023-12-03T18:21:45Z</dc:date>
    <item>
      <title>Security Policy</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/security-policy/m-p/568147#M2203</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have created a security policy with the below details. I am the hitting following URL &lt;A href="https://10.x.x.x:15671" target="_blank"&gt;https://10.x.x.x:15671&lt;/A&gt;&amp;nbsp;and I see the 'connection is reset' in the browser. I see traffic is hitting the policy (Hit count) but it's not logging. When I set the action to Deny/Drop/reset-client\reset-server the traffic is logging when hits the rule. What could be the reason why traffic is not logging for action 'Allow' and why traffic is not passing through?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Application - Any&lt;/P&gt;
&lt;P&gt;Services - Application default&lt;/P&gt;
&lt;P&gt;Action - Allow&lt;/P&gt;
&lt;P&gt;Logging - Log st session start and end&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Srikar&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="srikarpuligandla_0-1701627610318.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/55630i36B1D9E4F1125811/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="srikarpuligandla_0-1701627610318.png" alt="srikarpuligandla_0-1701627610318.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="srikarpuligandla_1-1701627668060.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/55631iFDBD9D58815421EF/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="srikarpuligandla_1-1701627668060.png" alt="srikarpuligandla_1-1701627668060.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 03 Dec 2023 18:21:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/security-policy/m-p/568147#M2203</guid>
      <dc:creator>srikarpuligandla</dc:creator>
      <dc:date>2023-12-03T18:21:45Z</dc:date>
    </item>
    <item>
      <title>Re: Security Policy</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/security-policy/m-p/568215#M2205</link>
      <description>&lt;P&gt;Your service is set to application default while you're using port 15671 for ssl traffic (default port 443)&lt;/P&gt;
&lt;P&gt;This means you will not be using this security rule to handle the traffic. You're most likely dropping down to the default intrazone deny rule, which has logging disabled&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;reason you're seeing the hit counter increase is when the SYN paxcket arrives there's no app-id yet, so no default port to enforce, the policy match goes by the 6tuple (source zone, source ip, destination zone, destination ip, destination port, protocol)&lt;/P&gt;
&lt;P&gt;since you have an any any rule, the syn packet is allowed through until app-id kicks in, the rulebase is chcked again, this rule no longer matches and the next best match is de default rule&lt;/P&gt;</description>
      <pubDate>Mon, 04 Dec 2023 13:43:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/security-policy/m-p/568215#M2205</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2023-12-04T13:43:31Z</dc:date>
    </item>
    <item>
      <title>Re: Security Policy</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/security-policy/m-p/568813#M2226</link>
      <description>&lt;P&gt;Thank you&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Dec 2023 05:00:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/security-policy/m-p/568813#M2226</guid>
      <dc:creator>srikarpuligandla</dc:creator>
      <dc:date>2023-12-07T05:00:27Z</dc:date>
    </item>
  </channel>
</rss>

