<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Application Logmein identified but not dropped by rulebase in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/application-logmein-identified-but-not-dropped-by-rulebase/m-p/14285#M10503</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry, but I hav&amp;nbsp; implemented a brand New PAN solution with Url cat and AV license.&lt;/P&gt;&lt;P&gt;All configuration works find. I have a visitor zone on a DMZ and I want them to access Internet but with my Url Categorisation, so I can't let them use Remote access application.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I Have implemented a rulebase with&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[...]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Name "Rule 30"&lt;/P&gt;&lt;P&gt;Src Zone "DMZ"&lt;/P&gt;&lt;P&gt;Src "DmzUserNetwork-1" &amp;amp; "DmzUserNetwork-2 "&lt;/P&gt;&lt;P&gt;Dst Zone "Internet"&lt;/P&gt;&lt;P&gt;Dst "Any"&lt;/P&gt;&lt;P&gt;Application: "Logmein" &amp;amp; "tcp-over-dns" &amp;amp; application group "peer-to-peer" =&amp;gt; App-group have all filtered apps with catégorie p2p&lt;/P&gt;&lt;P&gt;Profil "None"&lt;/P&gt;&lt;P&gt;Action Drop&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Name "Rule 50"&lt;/P&gt;&lt;P&gt;Src Zone "DMZ"&lt;/P&gt;&lt;P&gt;Src "DmzUserNetwork-2"&lt;/P&gt;&lt;P&gt;Dst Zone "Internet"&lt;/P&gt;&lt;P&gt;Dst "Any"&lt;/P&gt;&lt;P&gt;Application "Any"&lt;/P&gt;&lt;P&gt;Profil "Service Group MyProtectedPol" (=&amp;gt; AV, Url-cat, and Malware rules)&lt;/P&gt;&lt;P&gt;Action Allow&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[...]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The point is that from a device connected in DmzUserNetwork-2, when I try to connect the web browser to logmein service, PAN Monitor show me an allowed connexion based on rule 50. Rule 30 is Enabled, and placed before Rule 50. It seems that the firewall doesn't applied denied rule. Note that I have already commited config and saved.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have any suggestions?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, BR.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 29 Feb 2012 15:35:38 GMT</pubDate>
    <dc:creator>d_aznar</dc:creator>
    <dc:date>2012-02-29T15:35:38Z</dc:date>
    <item>
      <title>Application Logmein identified but not dropped by rulebase</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-logmein-identified-but-not-dropped-by-rulebase/m-p/14285#M10503</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry, but I hav&amp;nbsp; implemented a brand New PAN solution with Url cat and AV license.&lt;/P&gt;&lt;P&gt;All configuration works find. I have a visitor zone on a DMZ and I want them to access Internet but with my Url Categorisation, so I can't let them use Remote access application.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I Have implemented a rulebase with&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[...]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Name "Rule 30"&lt;/P&gt;&lt;P&gt;Src Zone "DMZ"&lt;/P&gt;&lt;P&gt;Src "DmzUserNetwork-1" &amp;amp; "DmzUserNetwork-2 "&lt;/P&gt;&lt;P&gt;Dst Zone "Internet"&lt;/P&gt;&lt;P&gt;Dst "Any"&lt;/P&gt;&lt;P&gt;Application: "Logmein" &amp;amp; "tcp-over-dns" &amp;amp; application group "peer-to-peer" =&amp;gt; App-group have all filtered apps with catégorie p2p&lt;/P&gt;&lt;P&gt;Profil "None"&lt;/P&gt;&lt;P&gt;Action Drop&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Name "Rule 50"&lt;/P&gt;&lt;P&gt;Src Zone "DMZ"&lt;/P&gt;&lt;P&gt;Src "DmzUserNetwork-2"&lt;/P&gt;&lt;P&gt;Dst Zone "Internet"&lt;/P&gt;&lt;P&gt;Dst "Any"&lt;/P&gt;&lt;P&gt;Application "Any"&lt;/P&gt;&lt;P&gt;Profil "Service Group MyProtectedPol" (=&amp;gt; AV, Url-cat, and Malware rules)&lt;/P&gt;&lt;P&gt;Action Allow&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[...]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The point is that from a device connected in DmzUserNetwork-2, when I try to connect the web browser to logmein service, PAN Monitor show me an allowed connexion based on rule 50. Rule 30 is Enabled, and placed before Rule 50. It seems that the firewall doesn't applied denied rule. Note that I have already commited config and saved.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have any suggestions?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, BR.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Feb 2012 15:35:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-logmein-identified-but-not-dropped-by-rulebase/m-p/14285#M10503</guid>
      <dc:creator>d_aznar</dc:creator>
      <dc:date>2012-02-29T15:35:38Z</dc:date>
    </item>
    <item>
      <title>Re: Application Logmein identified but not dropped by rulebase</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-logmein-identified-but-not-dropped-by-rulebase/m-p/14286#M10504</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Team,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Seems that upgrade from 4.1.1 to 4.1.3 resolved the case.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No changes on the rulebase. But now, the Ref "Rule 30" drop rule is correctly interpreted and logmein trafic is dropped.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;David&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Mar 2012 10:10:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-logmein-identified-but-not-dropped-by-rulebase/m-p/14286#M10504</guid>
      <dc:creator>d_aznar</dc:creator>
      <dc:date>2012-03-01T10:10:01Z</dc:date>
    </item>
  </channel>
</rss>

