<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Country Block and security policy ordering in Advanced Threat Prevention Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/country-block-and-security-policy-ordering/m-p/491104#M1632</link>
    <description>&lt;P&gt;We are currently setting up policies to block all traffic to\from all countries except a select few. The rules are in place and seem to be&amp;nbsp; working well. As a best practice, do you create a deny rule for all other out of country or do you just let the interzone-default rule catch the rest? If you do create a rule, is it best practice to keep defining your rules until both the&amp;nbsp;interzone-default &amp;amp;&amp;nbsp;intrazone-default rules don't get hit?&lt;/P&gt;</description>
    <pubDate>Tue, 24 May 2022 22:43:21 GMT</pubDate>
    <dc:creator>RussMc</dc:creator>
    <dc:date>2022-05-24T22:43:21Z</dc:date>
    <item>
      <title>Country Block and security policy ordering</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/country-block-and-security-policy-ordering/m-p/491104#M1632</link>
      <description>&lt;P&gt;We are currently setting up policies to block all traffic to\from all countries except a select few. The rules are in place and seem to be&amp;nbsp; working well. As a best practice, do you create a deny rule for all other out of country or do you just let the interzone-default rule catch the rest? If you do create a rule, is it best practice to keep defining your rules until both the&amp;nbsp;interzone-default &amp;amp;&amp;nbsp;intrazone-default rules don't get hit?&lt;/P&gt;</description>
      <pubDate>Tue, 24 May 2022 22:43:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/country-block-and-security-policy-ordering/m-p/491104#M1632</guid>
      <dc:creator>RussMc</dc:creator>
      <dc:date>2022-05-24T22:43:21Z</dc:date>
    </item>
    <item>
      <title>Re: Country Block and security policy ordering</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/country-block-and-security-policy-ordering/m-p/491323#M1635</link>
      <description>&lt;P&gt;Hi RussMc,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Its good to have a deny rule so that you can block malicious IP traffic from all allowed countries.&lt;/P&gt;&lt;P&gt;Else such accepted traffic may hit on one of the rule above default rules.(i mean example: any traffic from to DMZ/public facing servers)&lt;/P&gt;</description>
      <pubDate>Wed, 25 May 2022 07:54:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/country-block-and-security-policy-ordering/m-p/491323#M1635</guid>
      <dc:creator>BNSRIKAR</dc:creator>
      <dc:date>2022-05-25T07:54:18Z</dc:date>
    </item>
  </channel>
</rss>

