<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can I migrate policy rules from pre-rules to post-rules category and push to Firewalls without causing downtime? in Panorama Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/panorama-discussions/can-i-migrate-policy-rules-from-pre-rules-to-post-rules-category/m-p/542556#M1549</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/282220"&gt;@fbarnard&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have moved rules between pre- and post- many times with no down time.&amp;nbsp; HOWEVER, with that said there is always a chance of an outage when you change the order or rules.&amp;nbsp; Verify the new order of rules is good, and you should be fine.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Edit:&amp;nbsp; I just moved my outbound rule to the Internet from each device group to Shared.&amp;nbsp; I was doing an outbound ping, and I dropped one packet.&lt;/P&gt;</description>
    <pubDate>Fri, 19 May 2023 13:22:09 GMT</pubDate>
    <dc:creator>TomYoung</dc:creator>
    <dc:date>2023-05-19T13:22:09Z</dc:date>
    <item>
      <title>Can I migrate policy rules from pre-rules to post-rules category and push to Firewalls without causing downtime?</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/can-i-migrate-policy-rules-from-pre-rules-to-post-rules-category/m-p/542555#M1548</link>
      <description>&lt;P&gt;So, I am new to palo-alto and I created some pretty general policies for internal-to-dmz communication, I now wanted to create a policy that would target specific host-to-destinations for testing, however, I noticed that the primary "Allow All" policy was set in the pre-rules, which takes precedence in the hierarchy. (Top to bottom). So what I need to do is migrate my "Allow All" policy to the Post-rules section so that my test policy can be hit before the first rule comes in play.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;SO, now that's out of the way, my real question is; If I apply these changes in Panorama then push to my firewalls, will there be a loss in connection, sessions etc when the policy is moved down in the hierarchy?&amp;nbsp;&lt;BR /&gt;I did a test from one of my sandbox environments, looked like there was no hiccup with ping, but ping is no stateful connection if you know what I mean ;).&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 May 2023 00:27:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/can-i-migrate-policy-rules-from-pre-rules-to-post-rules-category/m-p/542555#M1548</guid>
      <dc:creator>fbarnard</dc:creator>
      <dc:date>2023-05-18T00:27:17Z</dc:date>
    </item>
    <item>
      <title>Re: Can I migrate policy rules from pre-rules to post-rules category and push to Firewalls without causing downtime?</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/can-i-migrate-policy-rules-from-pre-rules-to-post-rules-category/m-p/542556#M1549</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/282220"&gt;@fbarnard&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have moved rules between pre- and post- many times with no down time.&amp;nbsp; HOWEVER, with that said there is always a chance of an outage when you change the order or rules.&amp;nbsp; Verify the new order of rules is good, and you should be fine.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Edit:&amp;nbsp; I just moved my outbound rule to the Internet from each device group to Shared.&amp;nbsp; I was doing an outbound ping, and I dropped one packet.&lt;/P&gt;</description>
      <pubDate>Fri, 19 May 2023 13:22:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/can-i-migrate-policy-rules-from-pre-rules-to-post-rules-category/m-p/542556#M1549</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-05-19T13:22:09Z</dc:date>
    </item>
    <item>
      <title>Re: Can I migrate policy rules from pre-rules to post-rules category and push to Firewalls without causing downtime?</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/can-i-migrate-policy-rules-from-pre-rules-to-post-rules-category/m-p/542631#M1552</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Thank you for the confirmation! Yes, I am keeping in mind the rules currently set, we are still in the phase of policy control setup, right now we are testing the communication between zones. I just wanted to make sure I was putting my more broad policy in the right hierarchy before implementing more stringent or specific policy.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 18 May 2023 16:10:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/can-i-migrate-policy-rules-from-pre-rules-to-post-rules-category/m-p/542631#M1552</guid>
      <dc:creator>fbarnard</dc:creator>
      <dc:date>2023-05-18T16:10:21Z</dc:date>
    </item>
  </channel>
</rss>

