<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Block all countries except two - US and India in Advanced Threat Prevention Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/block-all-countries-except-two-us-and-india/m-p/227770#M377</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;The use of the rules is one for inbound and the other for outbound traffic. While yes a DENY ALL at the end could suffice, it just saves the firewall to keep having to match the traffic to the whole policy list. It's always top to bottom and left ot right until a match is found.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that clarifies things.&lt;/P&gt;</description>
    <pubDate>Tue, 21 Aug 2018 19:06:16 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2018-08-21T19:06:16Z</dc:date>
    <item>
      <title>Block all countries except two - US and India</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/block-all-countries-except-two-us-and-india/m-p/196301#M171</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; Im trying to find out if its possible to block all countries except for two - United States and India easily. The only way we can see right now is to go country by country adding them into the list. Can someone please assist if theres an easier way to accomplish this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;James&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jan 2018 00:42:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/block-all-countries-except-two-us-and-india/m-p/196301#M171</guid>
      <dc:creator>JGFireOwls</dc:creator>
      <dc:date>2018-01-23T00:42:00Z</dc:date>
    </item>
    <item>
      <title>Re: Block all countries except two - US and India</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/block-all-countries-except-two-us-and-india/m-p/196318#M172</link>
      <description>&lt;P&gt;You have a couple alternatives.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;One is to use two (or three) Security Policies, The first one allowing all traffic from (and/or a second rule for trafic *to*) US and India Regions, the&amp;nbsp;next rule listed right after these&amp;nbsp;rules, blocking destination any.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The second option is to use the Negate option. You would&amp;nbsp;configure a Deny rule, and add US and India, then in the Source or Destination Address (depending on which direction of sessions you want to block, you may need to use separate rules for either direction) use the Negate checkbox, which will say, Deny everything 'except' these two Regions.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;#1 Pros:&amp;nbsp;Configuration is obvious to anyone reading it, especially if you need to add security profiles in the Actions tab.&lt;/P&gt;
&lt;P&gt;#1 Cons: You need two (or three, to cover sessions in either direction) rules&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;#2 Pros: You need only one rule (or two, to cover&amp;nbsp;sessions in either direction)&lt;/P&gt;
&lt;P&gt;#2 Cons: Configuration may look awkward to someone who doesn't understand what the Negate option does, and it's also counter-intuitive to see Security Profiles configured in a Deny policy.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jan 2018 01:26:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/block-all-countries-except-two-us-and-india/m-p/196318#M172</guid>
      <dc:creator>mivaldi</dc:creator>
      <dc:date>2018-01-23T01:26:41Z</dc:date>
    </item>
    <item>
      <title>Re: Block all countries except two - US and India</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/block-all-countries-except-two-us-and-india/m-p/196327#M173</link>
      <description>&lt;P&gt;Awesome, this makes sense, thank you very much&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jan 2018 01:20:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/block-all-countries-except-two-us-and-india/m-p/196327#M173</guid>
      <dc:creator>JGFireOwls</dc:creator>
      <dc:date>2018-01-23T01:20:28Z</dc:date>
    </item>
    <item>
      <title>Re: Block all countries except two - US and India</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/block-all-countries-except-two-us-and-india/m-p/227743#M376</link>
      <description>&lt;P&gt;Thanks for the explanation. Just a quick question - In option 1 do we need 2 rules wouldnt the default deny take care of denying everything except the countries that are allowed?&lt;/P&gt;</description>
      <pubDate>Tue, 21 Aug 2018 16:50:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/block-all-countries-except-two-us-and-india/m-p/227743#M376</guid>
      <dc:creator>Dee</dc:creator>
      <dc:date>2018-08-21T16:50:53Z</dc:date>
    </item>
    <item>
      <title>Re: Block all countries except two - US and India</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/block-all-countries-except-two-us-and-india/m-p/227770#M377</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;The use of the rules is one for inbound and the other for outbound traffic. While yes a DENY ALL at the end could suffice, it just saves the firewall to keep having to match the traffic to the whole policy list. It's always top to bottom and left ot right until a match is found.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that clarifies things.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Aug 2018 19:06:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/block-all-countries-except-two-us-and-india/m-p/227770#M377</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-08-21T19:06:16Z</dc:date>
    </item>
  </channel>
</rss>

