<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSH traffic on one policy appears to be denied by a policy that is currently disabled.  How is that even possible? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssh-traffic-on-one-policy-appears-to-be-denied-by-a-policy-that/m-p/565843#M114397</link>
    <description>&lt;P&gt;Sorry, I should have mentioned that I did commit the change.&lt;/P&gt;</description>
    <pubDate>Wed, 15 Nov 2023 15:29:38 GMT</pubDate>
    <dc:creator>pehlmanj</dc:creator>
    <dc:date>2023-11-15T15:29:38Z</dc:date>
    <item>
      <title>SSH traffic on one policy appears to be denied by a policy that is currently disabled.  How is that even possible?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssh-traffic-on-one-policy-appears-to-be-denied-by-a-policy-that/m-p/565667#M114374</link>
      <description>&lt;P&gt;I created a policy (number 21) that allows several types of traffic outbound (ssh, https, tcp 8989, tcp 61000 - 65535, and UDP 1024-65535).&amp;nbsp; All traffic seems to be passing except SSH, which is being blocked by policy number 25, which is supposed to be disabled.&amp;nbsp; During troubleshooting, it looked like policy 25 was responsible for denying my SSH traffic, so I disabled policy number 25 to continue troubleshooting, but when I look at the monitor, policy 25's name is being referenced as the reason the SSH traffic is being denied.&amp;nbsp; Is there something more to disabling a policy other than just highlighting the policy, and clicking the disable button?&amp;nbsp; The policy is "greyed out" so it looks like it's disabled, but my SSH traffic still isnt flowing.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Nov 2023 19:17:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssh-traffic-on-one-policy-appears-to-be-denied-by-a-policy-that/m-p/565667#M114374</guid>
      <dc:creator>pehlmanj</dc:creator>
      <dc:date>2023-11-14T19:17:01Z</dc:date>
    </item>
    <item>
      <title>Re: SSH traffic on one policy appears to be denied by a policy that is currently disabled.  How is that even possible?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssh-traffic-on-one-policy-appears-to-be-denied-by-a-policy-that/m-p/565695#M114380</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/323501"&gt;@pehlmanj&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After disabling a policy, please commit your changes to the firewall. Once committed, the disable should be enforced for new traffic.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Nov 2023 23:11:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssh-traffic-on-one-policy-appears-to-be-denied-by-a-policy-that/m-p/565695#M114380</guid>
      <dc:creator>JayGolf</dc:creator>
      <dc:date>2023-11-14T23:11:51Z</dc:date>
    </item>
    <item>
      <title>Re: SSH traffic on one policy appears to be denied by a policy that is currently disabled.  How is that even possible?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssh-traffic-on-one-policy-appears-to-be-denied-by-a-policy-that/m-p/565843#M114397</link>
      <description>&lt;P&gt;Sorry, I should have mentioned that I did commit the change.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Nov 2023 15:29:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssh-traffic-on-one-policy-appears-to-be-denied-by-a-policy-that/m-p/565843#M114397</guid>
      <dc:creator>pehlmanj</dc:creator>
      <dc:date>2023-11-15T15:29:38Z</dc:date>
    </item>
    <item>
      <title>Re: SSH traffic on one policy appears to be denied by a policy that is currently disabled.  How is that even possible?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssh-traffic-on-one-policy-appears-to-be-denied-by-a-policy-that/m-p/565898#M114404</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/323501"&gt;@pehlmanj&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;The&amp;nbsp;&lt;EM&gt;only&amp;nbsp;&lt;/EM&gt;way that makes any sense is if you've modified defaults so that 'rematch sessions' is not enabled, or you didn't actually commit the change. If you've actually committed the changes the only way this makes sense is if you've disabled rematch sessions in which case you'll want to change that back to default and just enable it again.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Nov 2023 22:22:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssh-traffic-on-one-policy-appears-to-be-denied-by-a-policy-that/m-p/565898#M114404</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2023-11-15T22:22:58Z</dc:date>
    </item>
    <item>
      <title>Re: SSH traffic on one policy appears to be denied by a policy that is currently disabled.  How is that even possible?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssh-traffic-on-one-policy-appears-to-be-denied-by-a-policy-that/m-p/566017#M114426</link>
      <description>&lt;P&gt;"Rematch sessions" is enabled. (It was never disabled).&amp;nbsp; And changes were committed.&amp;nbsp; The rule in question is showing up as "greyed out" but the monitor is still pointing to it as the cause of my SSH denials.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Nov 2023 16:43:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssh-traffic-on-one-policy-appears-to-be-denied-by-a-policy-that/m-p/566017#M114426</guid>
      <dc:creator>pehlmanj</dc:creator>
      <dc:date>2023-11-16T16:43:06Z</dc:date>
    </item>
  </channel>
</rss>

