<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is there a need for a book on PAN-OS &amp;quot;Policy as Code&amp;quot; subject? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-need-for-a-book-on-pan-os-quot-policy-as-code-quot/m-p/566566#M114496</link>
    <description>&lt;P&gt;Sounds like you're putting onto paper something that a lot of folks are trying to do but unable to cobble together. Appreciate the work you've already put into this, Nikolay!&lt;/P&gt;</description>
    <pubDate>Tue, 21 Nov 2023 21:57:52 GMT</pubDate>
    <dc:creator>chmotley</dc:creator>
    <dc:date>2023-11-21T21:57:52Z</dc:date>
    <item>
      <title>Is there a need for a book on PAN-OS "Policy as Code" subject?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-need-for-a-book-on-pan-os-quot-policy-as-code-quot/m-p/565367#M114337</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Dear All,&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am looking to determine if there is a demand in the market for a guide to PAN-OS security policy automation ("policy as code").&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There is plenty of reference information&amp;nbsp;(&lt;A href="https://pan.dev" target="_blank" rel="noopener"&gt;https://pan.dev&lt;/A&gt; is always a good starting point) but there is no resource/book that would take one of the available automation frameworks and demonstrate how to leverage it to build a comprehensive "real-world" firewall security policy based on business requirements. From personal experience, I also know that those who only start their careers with firewalls (and NGFWs in particular) usually have no clue how to implement a new policy with zero impact on end-users. The proposed guide would address both of these gaps.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you feel our Palo community would benefit from such a guide, please drop a short comment or a Like under this post. Below you can find a more detailed description of the contents.&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;TLDR summary is at the bottom of the post.&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;== book description ==&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT color="#0000FF"&gt;This book will demonstrate how to leverage simple Python programming and firewall API to build a comprehensive security policy for a typical scenario where Palo Alto Networks firewalls serve as web-filtering Internet gateways in a multi-site enterprise environment. Our main goals and drivers will be a risk-based approach to security, consistency, high manageability, and low administrative overhead.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;BR /&gt;&lt;FONT color="#0000FF"&gt;All aspects of policy design and implementation will be covered. Our solution will be suitable for companies of all sizes—from small and medium businesses comprised of a handful of offices with standalone firewalls to international corporations with hundreds of offices with firewalls managed by Panorama appliances.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT color="#0000FF"&gt;We will start by defining functional requirements and discussing the relevant software features of PAN-OS, as well as the specifics of packet processing in Next-Generation Firewalls. This will be followed by identifying necessary policy elements and structuring them to meet the defined requirements and adhere to security best practices. We will ensure the policy is risk-centric, user- and administrator-friendly, and integrates well with the company’s IT Help Desk system.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT color="#0000FF"&gt;Then, we will select a suitable automation framework and proceed to turn our ideas into software code. We will rely on object-oriented Python with elements of classic procedural programming and fill gaps with the help of ChatGPT.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT color="#0000FF"&gt;The testing and implementation section will conclude the book. We will discuss necessary policy testing and develop a methodology that will allow us to transition our firm’s sites to the new policy with zero impact on end-users. Another piece of code will be required to achieve this crucial part of our work.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT color="#0000FF"&gt;After reading this book and following along, you will be able to bid farewell to all infamous “any-any” policy rules and the poorly structured and inconsistent firewall policies your organization may have accumulated over the years, which cause endless trouble for your department.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT color="#0000FF"&gt;Equally, this book will provide you with a pocket “Swiss Army knife” of ready-made network security solutions for greenfield firewall deployments.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT color="#0000FF"&gt;=======&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;TLDR version:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Intro, Business context, Business requirements, NGFW basics&lt;/LI&gt;
&lt;LI&gt;Security Policy Design (how to put together all security features)&lt;/LI&gt;
&lt;LI&gt;Firewall Automation and Management Choices&lt;/LI&gt;
&lt;LI&gt;How to set up a Dev Environment&lt;/LI&gt;
&lt;LI&gt;Coding (transformation of the designed policy into Python code)&lt;/LI&gt;
&lt;LI&gt;QA and Testing of all policy features&lt;/LI&gt;
&lt;LI&gt;Deployment&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Thank you in advance.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;LI-PRODUCT title="Panorama" id="Panorama"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;LI-PRODUCT title="NGFW" id="NGFW"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Nov 2023 22:25:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-need-for-a-book-on-pan-os-quot-policy-as-code-quot/m-p/565367#M114337</guid>
      <dc:creator>Nikolay_M</dc:creator>
      <dc:date>2023-11-21T22:25:22Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a need for a book on PAN-OS "Policy as Code" subject?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-need-for-a-book-on-pan-os-quot-policy-as-code-quot/m-p/565436#M114350</link>
      <description>&lt;P&gt;This sounds like a brilliant idea!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Nov 2023 00:04:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-need-for-a-book-on-pan-os-quot-policy-as-code-quot/m-p/565436#M114350</guid>
      <dc:creator>JayGolf</dc:creator>
      <dc:date>2023-11-14T00:04:50Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a need for a book on PAN-OS "Policy as Code" subject?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-need-for-a-book-on-pan-os-quot-policy-as-code-quot/m-p/565555#M114363</link>
      <description>&lt;P&gt;Thank you! Let's see if anyone else thinks the same &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Nov 2023 13:00:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-need-for-a-book-on-pan-os-quot-policy-as-code-quot/m-p/565555#M114363</guid>
      <dc:creator>Nikolay_M</dc:creator>
      <dc:date>2023-11-14T13:00:46Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a need for a book on PAN-OS "Policy as Code" subject?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-need-for-a-book-on-pan-os-quot-policy-as-code-quot/m-p/566513#M114486</link>
      <description>&lt;P&gt;Nikolay, documenting the practical experience would be very helpful.&amp;nbsp; I for one would purchase it.&amp;nbsp; Having the knowledge and understanding of what tighter security should look like combined with the automation as the vehicle to get it done quickly and at scale would be the holy grail.&amp;nbsp; Too many times either the resources do not exist to get it done or there is concern over operational impact due to a lack of knowledge.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Nov 2023 14:45:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-need-for-a-book-on-pan-os-quot-policy-as-code-quot/m-p/566513#M114486</guid>
      <dc:creator>gbarnhart</dc:creator>
      <dc:date>2023-11-21T14:45:37Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a need for a book on PAN-OS "Policy as Code" subject?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-need-for-a-book-on-pan-os-quot-policy-as-code-quot/m-p/566566#M114496</link>
      <description>&lt;P&gt;Sounds like you're putting onto paper something that a lot of folks are trying to do but unable to cobble together. Appreciate the work you've already put into this, Nikolay!&lt;/P&gt;</description>
      <pubDate>Tue, 21 Nov 2023 21:57:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-need-for-a-book-on-pan-os-quot-policy-as-code-quot/m-p/566566#M114496</guid>
      <dc:creator>chmotley</dc:creator>
      <dc:date>2023-11-21T21:57:52Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a need for a book on PAN-OS "Policy as Code" subject?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-need-for-a-book-on-pan-os-quot-policy-as-code-quot/m-p/566740#M114523</link>
      <description>&lt;P&gt;There's plenty of material on Python, Ansible, Terraform out there and how to operationalise them.&lt;BR /&gt;There's lots of vendor documentation for PAN-OS out there too.&lt;BR /&gt;There is not much content, by comparison, where those two circles overlap on a Venn diagram. PAN-OS specific guidance on using and operationalising automation would be worthy of a book IMO.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Nov 2023 17:56:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-need-for-a-book-on-pan-os-quot-policy-as-code-quot/m-p/566740#M114523</guid>
      <dc:creator>JimmyHolland</dc:creator>
      <dc:date>2023-11-22T17:56:30Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a need for a book on PAN-OS "Policy as Code" subject?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-need-for-a-book-on-pan-os-quot-policy-as-code-quot/m-p/566763#M114529</link>
      <description>&lt;P&gt;I think such a book would enable many FW administrators to give policy automation a try.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If I may, I would suggest a section about drift handling. Both from "detection and revert" (to the code source of truth) and from the "detection and integrate" (changes done manually becoming part of the code) points of view.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Nov 2023 21:06:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-need-for-a-book-on-pan-os-quot-policy-as-code-quot/m-p/566763#M114529</guid>
      <dc:creator>xhoms</dc:creator>
      <dc:date>2023-11-22T21:06:53Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a need for a book on PAN-OS "Policy as Code" subject?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-need-for-a-book-on-pan-os-quot-policy-as-code-quot/m-p/566768#M114531</link>
      <description>&lt;P&gt;It's a good point, thank you. I will see how I can cover this.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Nov 2023 22:58:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-need-for-a-book-on-pan-os-quot-policy-as-code-quot/m-p/566768#M114531</guid>
      <dc:creator>Nikolay_M</dc:creator>
      <dc:date>2023-11-22T22:58:03Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a need for a book on PAN-OS "Policy as Code" subject?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-need-for-a-book-on-pan-os-quot-policy-as-code-quot/m-p/566814#M114538</link>
      <description>&lt;P&gt;I'm on the same page as the other users who commented. A guide like that would be super handy for a bunch of people and would really fill a content gap.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Nov 2023 07:49:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-need-for-a-book-on-pan-os-quot-policy-as-code-quot/m-p/566814#M114538</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2023-11-23T07:49:55Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a need for a book on PAN-OS "Policy as Code" subject?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-need-for-a-book-on-pan-os-quot-policy-as-code-quot/m-p/1237770#M125105</link>
      <description>&lt;P&gt;The book has now been published. I am not sure if the forum's policies allow posting links to online bookstores (probably not :)), but you can use Google to search for "Palo Alto Networks from Policy to Code" to find it on Amazon and in a variety of other online stores.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Sep 2025 16:24:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-need-for-a-book-on-pan-os-quot-policy-as-code-quot/m-p/1237770#M125105</guid>
      <dc:creator>Nikolay_M</dc:creator>
      <dc:date>2025-09-11T16:24:51Z</dc:date>
    </item>
  </channel>
</rss>

