<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Please help clarify about action of DoS protection policy. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/please-help-clarify-about-action-of-dos-protection-policy/m-p/464371#M102488</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your detail.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 09 Feb 2022 04:50:30 GMT</pubDate>
    <dc:creator>Jitaphon</dc:creator>
    <dc:date>2022-02-09T04:50:30Z</dc:date>
    <item>
      <title>Please help clarify about action of DoS protection policy.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/please-help-clarify-about-action-of-dos-protection-policy/m-p/464164#M102452</link>
      <description>&lt;P&gt;We understand DoS protection works when we set action Protect.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We need to know the benefits to setting action Allow and Deny.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Because we think that option is the same as normal security policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jitaphon_0-1644319100938.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/39015iF954100D6F687663/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Jitaphon_0-1644319100938.png" alt="Jitaphon_0-1644319100938.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Feb 2022 11:18:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/please-help-clarify-about-action-of-dos-protection-policy/m-p/464164#M102452</guid>
      <dc:creator>Jitaphon</dc:creator>
      <dc:date>2022-02-08T11:18:31Z</dc:date>
    </item>
    <item>
      <title>Re: Please help clarify about action of DoS protection policy.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/please-help-clarify-about-action-of-dos-protection-policy/m-p/464231#M102468</link>
      <description>&lt;P&gt;Hello there.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;DoS policies are evaluated before security policies, if you truly follow the PANW flow logic.&lt;/P&gt;
&lt;P&gt;If true, then the DoS policies are extremely beneficial to protect your network.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Example:&amp;nbsp; Some companies want to block the EDLs (the 4 built in external dynamic lists), and they put them into the security policies, to typically DENY access.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Why not use a DoS policy with the DENY function.&amp;nbsp; This way, if any IP from the 4 EDLs attempt to connect to the FW (before a session is created) the action in DoS can be DENY.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now, there will always be workarounds, perhaps, the company wants to block foreign countries (example, block non-USA sourced traffic), and then some employees go on vacation to Mexico, and need access to GP.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Well, then you could create an ALLOW rule, above your non-foreign country rule, to allow MEX to try and establish a session.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In summary, I have provided both a DENY and an ALLOW explanations.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Feb 2022 15:33:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/please-help-clarify-about-action-of-dos-protection-policy/m-p/464231#M102468</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2022-02-08T15:33:30Z</dc:date>
    </item>
    <item>
      <title>Re: Please help clarify about action of DoS protection policy.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/please-help-clarify-about-action-of-dos-protection-policy/m-p/464371#M102488</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your detail.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Feb 2022 04:50:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/please-help-clarify-about-action-of-dos-protection-policy/m-p/464371#M102488</guid>
      <dc:creator>Jitaphon</dc:creator>
      <dc:date>2022-02-09T04:50:30Z</dc:date>
    </item>
  </channel>
</rss>

