<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global Zones / Rules in Strata Cloud Manager</title>
    <link>https://live.paloaltonetworks.com/t5/strata-cloud-manager/global-zones-rules/m-p/1256696#M149</link>
    <description>&lt;P&gt;Thanks&amp;nbsp; - I've had a look at this and it appears this is for Prisma access?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are currently focusing on device level, rather than user level protections to segment high risk area of our network off or area that are critical and need extra protection.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For example we have a rule to allow access to Microsoft Defender for Endpoint or the SIEM system that we want to be able to apply to multiple segmented area of the network, each segment is current in its own zone, with some of the zones been defined at a subfolder level.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From what I can see the best fix would be to define the zones at the root level so they can be used in root level config.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As we don't have Prisma it does not look like we can use the trust/untrusted functionality, nor does it appear to be in any of the mneus&lt;/P&gt;</description>
    <pubDate>Thu, 18 Jun 2026 11:09:11 GMT</pubDate>
    <dc:creator>R.Naylor</dc:creator>
    <dc:date>2026-06-18T11:09:11Z</dc:date>
    <item>
      <title>Global Zones / Rules</title>
      <link>https://live.paloaltonetworks.com/t5/strata-cloud-manager/global-zones-rules/m-p/1256390#M146</link>
      <description>&lt;P&gt;We want to create some standards rules that will apply to most zones - It looks like the only way to do this is to define all zones that needs these rules at a global level.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Looks like maybe tagging could be used&amp;nbsp; as an alternative to allow zones to be defined at a folder level, but this seems overly complex&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jun 2026 22:50:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/strata-cloud-manager/global-zones-rules/m-p/1256390#M146</guid>
      <dc:creator>R.Naylor</dc:creator>
      <dc:date>2026-06-15T22:50:52Z</dc:date>
    </item>
    <item>
      <title>Re: Global Zones / Rules</title>
      <link>https://live.paloaltonetworks.com/t5/strata-cloud-manager/global-zones-rules/m-p/1256498#M148</link>
      <description>&lt;P&gt;have you tried using Zone Mapping (from the Overview &amp;gt; Inherited Zones)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you can add all your internal zones to the Trust zone so you can make a rule that allows trust to anywhere which will include all your zones&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jun 2026 13:40:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/strata-cloud-manager/global-zones-rules/m-p/1256498#M148</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2026-06-16T13:40:31Z</dc:date>
    </item>
    <item>
      <title>Re: Global Zones / Rules</title>
      <link>https://live.paloaltonetworks.com/t5/strata-cloud-manager/global-zones-rules/m-p/1256696#M149</link>
      <description>&lt;P&gt;Thanks&amp;nbsp; - I've had a look at this and it appears this is for Prisma access?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are currently focusing on device level, rather than user level protections to segment high risk area of our network off or area that are critical and need extra protection.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For example we have a rule to allow access to Microsoft Defender for Endpoint or the SIEM system that we want to be able to apply to multiple segmented area of the network, each segment is current in its own zone, with some of the zones been defined at a subfolder level.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From what I can see the best fix would be to define the zones at the root level so they can be used in root level config.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As we don't have Prisma it does not look like we can use the trust/untrusted functionality, nor does it appear to be in any of the mneus&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jun 2026 11:09:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/strata-cloud-manager/global-zones-rules/m-p/1256696#M149</guid>
      <dc:creator>R.Naylor</dc:creator>
      <dc:date>2026-06-18T11:09:11Z</dc:date>
    </item>
  </channel>
</rss>

