<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Automate policy and object tightening in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/automate-policy-and-object-tightening/m-p/468321#M102846</link>
    <description>&lt;P&gt;Firewalls need to be able to improve their own status automatically by adjusting rules, policies and objects automatically to be more secure by using usage date. An example, system a talks to system b on a selection of ports all configured on the firewall. All designed and planned on human logic. After a month some ports have no traffic between the systems. The firewall should detect this and remove the unused ports from the configuration so that the rule is more secure. The same for source and destination ip addresses. If ip's or ranges show no usage after an extended period, firewall should tighten access to used ip addresses. Obviously allow an override where it's needed. Imaging installing a firewall, that gets more secure over time by removing unused ports, rules and ip's.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 24 Feb 2022 19:35:09 GMT</pubDate>
    <dc:creator>Greghayza</dc:creator>
    <dc:date>2022-02-24T19:35:09Z</dc:date>
    <item>
      <title>Automate policy and object tightening</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/automate-policy-and-object-tightening/m-p/468321#M102846</link>
      <description>&lt;P&gt;Firewalls need to be able to improve their own status automatically by adjusting rules, policies and objects automatically to be more secure by using usage date. An example, system a talks to system b on a selection of ports all configured on the firewall. All designed and planned on human logic. After a month some ports have no traffic between the systems. The firewall should detect this and remove the unused ports from the configuration so that the rule is more secure. The same for source and destination ip addresses. If ip's or ranges show no usage after an extended period, firewall should tighten access to used ip addresses. Obviously allow an override where it's needed. Imaging installing a firewall, that gets more secure over time by removing unused ports, rules and ip's.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Feb 2022 19:35:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/automate-policy-and-object-tightening/m-p/468321#M102846</guid>
      <dc:creator>Greghayza</dc:creator>
      <dc:date>2022-02-24T19:35:09Z</dc:date>
    </item>
    <item>
      <title>Re: Automate policy and object tightening</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/automate-policy-and-object-tightening/m-p/468459#M102848</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/210655"&gt;@Greghayza&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;I think you just described policy optimizer recommendations almost to a T, just that it's not automated&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":grinning_face:"&gt;😀&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Personally I don't think I would ever want my firewall automatically changing policies and removed "unused" app-ids or rulebase entries. There's plenty of rules and app-ids that I have across various clients that only get hit during quarterly or even yearly business practices. Policy Optimizer routinely tells me the rules are unused, even though the schedule assigned isn't active and I don't expect it to be hit for months to follow. I wouldn't want to suddenly find my firewall removed an app that was needed or a security rulebase entry that was needed.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Feb 2022 02:30:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/automate-policy-and-object-tightening/m-p/468459#M102848</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2022-02-25T02:30:24Z</dc:date>
    </item>
    <item>
      <title>Re: Automate policy and object tightening</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/automate-policy-and-object-tightening/m-p/471474#M103103</link>
      <description>&lt;P&gt;Same with expedition. Run our migration tool on a linux box, forward it some logs, give it your palo config, and it will recommend enhancements. See more &lt;A href="https://panos.pan.dev/docs/expedition/expedition_apiint" target="_self"&gt;here&lt;/A&gt;.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Or we are coming out with a similar solution for $, AIOps. See more &lt;A href="https://www.paloaltonetworks.com/network-security/aiops-for-ngfw" target="_self"&gt;here&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Mar 2022 19:03:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/automate-policy-and-object-tightening/m-p/471474#M103103</guid>
      <dc:creator>LAYER_8</dc:creator>
      <dc:date>2022-03-08T19:03:14Z</dc:date>
    </item>
  </channel>
</rss>

