<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: policy, objects and smtp in Advanced Threat Prevention Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/policy-objects-and-smtp/m-p/476726#M1570</link>
    <description>&lt;P&gt;It of course depends on you other rules, but something like this would allow SNMP inbound, but block all other traffic:&lt;/P&gt;&lt;P&gt;Policies-&amp;gt;Security&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Name="Allow SMTP in to mailserver", SrcZone=WAN, SrcAddr=any, DstZone=DMZ, DstAddr=mailserver, Application=SMTP,SMTP_AUTH, Service=any Action=Allow&lt;/LI&gt;&lt;LI&gt;Name="Block all ElSalvador traffic inbound",&amp;nbsp;SrcZone=WAN, SrcAddr=Regions:SV, DstZone=any, DstAddr=any, Application=any, Service=any Action=Drop&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;If you also want to block requests outbound to that country:&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;3.&amp;nbsp;Name="Block all traffic outbound to El Salvador",&amp;nbsp;SrcZone=LAN, SrcAddr=any, DstZone=WAN, DstAddr=Regions:SV, Application=any, Service=any Action=Drop&lt;/P&gt;</description>
    <pubDate>Tue, 29 Mar 2022 23:09:07 GMT</pubDate>
    <dc:creator>Adrian_Jensen</dc:creator>
    <dc:date>2022-03-29T23:09:07Z</dc:date>
    <item>
      <title>policy, objects and smtp</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/policy-objects-and-smtp/m-p/476520#M1563</link>
      <description>&lt;P&gt;howdy,&lt;/P&gt;&lt;P&gt;I can not get my head around how to do this.&lt;/P&gt;&lt;P&gt;Allow smtp from a country but block every other service, application.&lt;/P&gt;&lt;P&gt;You can negate countries but not services/applications.&lt;/P&gt;&lt;P&gt;can one do any/any with an exception?&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2022 01:00:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/policy-objects-and-smtp/m-p/476520#M1563</guid>
      <dc:creator>PA200-1</dc:creator>
      <dc:date>2022-03-29T01:00:51Z</dc:date>
    </item>
    <item>
      <title>Re: policy, objects and smtp</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/policy-objects-and-smtp/m-p/476628#M1568</link>
      <description>&lt;P&gt;Your question is a bit open ended... Do you want to block everything but SMTP from a specific country? Or block all traffic to anywhere, except for SMTP from a specific country? Generally you are going to want to try and build rules with specific allows, followed by global drops for anything else.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2022 15:52:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/policy-objects-and-smtp/m-p/476628#M1568</guid>
      <dc:creator>Adrian_Jensen</dc:creator>
      <dc:date>2022-03-29T15:52:07Z</dc:date>
    </item>
    <item>
      <title>Re: policy, objects and smtp</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/policy-objects-and-smtp/m-p/476676#M1569</link>
      <description>&lt;P&gt;Allow smtp from 1 specific country but block every other service, application from that 1 specific country.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2022 19:58:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/policy-objects-and-smtp/m-p/476676#M1569</guid>
      <dc:creator>PA200-1</dc:creator>
      <dc:date>2022-03-29T19:58:52Z</dc:date>
    </item>
    <item>
      <title>Re: policy, objects and smtp</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/policy-objects-and-smtp/m-p/476726#M1570</link>
      <description>&lt;P&gt;It of course depends on you other rules, but something like this would allow SNMP inbound, but block all other traffic:&lt;/P&gt;&lt;P&gt;Policies-&amp;gt;Security&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Name="Allow SMTP in to mailserver", SrcZone=WAN, SrcAddr=any, DstZone=DMZ, DstAddr=mailserver, Application=SMTP,SMTP_AUTH, Service=any Action=Allow&lt;/LI&gt;&lt;LI&gt;Name="Block all ElSalvador traffic inbound",&amp;nbsp;SrcZone=WAN, SrcAddr=Regions:SV, DstZone=any, DstAddr=any, Application=any, Service=any Action=Drop&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;If you also want to block requests outbound to that country:&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;3.&amp;nbsp;Name="Block all traffic outbound to El Salvador",&amp;nbsp;SrcZone=LAN, SrcAddr=any, DstZone=WAN, DstAddr=Regions:SV, Application=any, Service=any Action=Drop&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2022 23:09:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/policy-objects-and-smtp/m-p/476726#M1570</guid>
      <dc:creator>Adrian_Jensen</dc:creator>
      <dc:date>2022-03-29T23:09:07Z</dc:date>
    </item>
  </channel>
</rss>

