<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Security policies not matching traffic in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/security-policies-not-matching-traffic/m-p/495846#M105097</link>
    <description>&lt;P&gt;That was it! This resolved so many issues for me. I couldn't understand how traffic wasn't matching for quite a few other apps/functions within my network. I greatly appreciate the help!&lt;/P&gt;</description>
    <pubDate>Tue, 31 May 2022 16:00:35 GMT</pubDate>
    <dc:creator>dustin.campbell</dc:creator>
    <dc:date>2022-05-31T16:00:35Z</dc:date>
    <item>
      <title>Security policies not matching traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policies-not-matching-traffic/m-p/495675#M105087</link>
      <description>&lt;P&gt;Hello! I am having quite a few strange behaviors from the Palo Alto firewalls. I have a rule for an entire subnet (10.209.82.0/24) to be allowed from inside to outside zones via any port to any IP address yet there is still somehow traffic being denied. Obviously, this isn't the greatest from a security perspective, but I arrived there out of frustration and trying to get this to work. This is happening with a few other rules as well. I have one that allows 10.209.69.0/25 out to any IP and any port. This one is odd because 10.209.69.110 can match this rule and successfully get out to a public resource that it builds a VPN tunnel to, but 10.209.69.111 doesn't match that rule at all and ends up hitting the default deny rule. I have double checked the objects over and over to ensure the subnets are correctly configured. A basic NAT is setup to NAT inside to outside to the outside IP address of the Palo Alto, which does work for everything else. I'm able to browse the web and most other functions within the data center (too many to list) are working correctly. I'm just starting to have more and more wonky issues like this lately.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 31 May 2022 14:58:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policies-not-matching-traffic/m-p/495675#M105087</guid>
      <dc:creator>dustin.campbell</dc:creator>
      <dc:date>2022-05-31T14:58:01Z</dc:date>
    </item>
    <item>
      <title>Re: Security policies not matching traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policies-not-matching-traffic/m-p/495700#M105089</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have you checked that the subnets are configured correctly on the interfaces within the zone you are writing in your security rule?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Maybe you can share a screenshot with traffic logs and security rule for check it.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Regards&lt;/P&gt;</description>
      <pubDate>Tue, 31 May 2022 15:05:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policies-not-matching-traffic/m-p/495700#M105089</guid>
      <dc:creator>Alpalo</dc:creator>
      <dc:date>2022-05-31T15:05:59Z</dc:date>
    </item>
    <item>
      <title>Re: Security policies not matching traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policies-not-matching-traffic/m-p/495726#M105090</link>
      <description>&lt;P&gt;Thanks for your response! I have checked that the subnets are correct a few times. I keep questioning that myself, but they are correct. Here's two screenshots. One of the actual rule configured, which is essentially wide open for that subnet. The second is a screenshot of the logs where traffic has been denied today.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="dustincampbell_0-1654010002677.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/41497iB5A1330AC7CC2BFC/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="dustincampbell_0-1654010002677.png" alt="dustincampbell_0-1654010002677.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="dustincampbell_1-1654010015914.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/41498i724507D29E7CE154/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="dustincampbell_1-1654010015914.png" alt="dustincampbell_1-1654010015914.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 31 May 2022 15:13:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policies-not-matching-traffic/m-p/495726#M105090</guid>
      <dc:creator>dustin.campbell</dc:creator>
      <dc:date>2022-05-31T15:13:43Z</dc:date>
    </item>
    <item>
      <title>Re: Security policies not matching traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policies-not-matching-traffic/m-p/495753#M105092</link>
      <description>&lt;P&gt;Delete application-default and try again...&lt;/P&gt;&lt;P&gt;You are trying connect to port 10000 and open-vpn use&amp;nbsp;tcp/1194, tcp/443, udp/1194&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;TABLE cellspacing="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;STRONG&gt;Name:&amp;nbsp;&amp;nbsp;&lt;/STRONG&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;open-vpn&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;STRONG&gt;Standard Ports:&amp;nbsp;&amp;nbsp;&lt;/STRONG&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;tcp/1194, tcp/443, udp/1194&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;STRONG&gt;Depends on:&amp;nbsp;&amp;nbsp;&lt;/STRONG&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;ssl, web-browsing&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Tue, 31 May 2022 15:21:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policies-not-matching-traffic/m-p/495753#M105092</guid>
      <dc:creator>Alpalo</dc:creator>
      <dc:date>2022-05-31T15:21:24Z</dc:date>
    </item>
    <item>
      <title>Re: Security policies not matching traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policies-not-matching-traffic/m-p/495846#M105097</link>
      <description>&lt;P&gt;That was it! This resolved so many issues for me. I couldn't understand how traffic wasn't matching for quite a few other apps/functions within my network. I greatly appreciate the help!&lt;/P&gt;</description>
      <pubDate>Tue, 31 May 2022 16:00:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policies-not-matching-traffic/m-p/495846#M105097</guid>
      <dc:creator>dustin.campbell</dc:creator>
      <dc:date>2022-05-31T16:00:35Z</dc:date>
    </item>
  </channel>
</rss>

