<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Strange behavior in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/strange-behavior/m-p/571603#M115081</link>
    <description>&lt;P&gt;Hi there,&lt;/P&gt;
&lt;P&gt;Have you confirmed that traffic flows from DMZ -&amp;gt; Servers actually matches the expected security policy rule?&amp;nbsp;&lt;BR /&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/policy/test-policy-rule-traffic-matches" target="_blank"&gt;Test Policy Rules (paloaltonetworks.com)&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the traffic logs do you see the DMZ -&amp;gt; Server flows hitting any Deny rules?&lt;BR /&gt;&lt;BR /&gt;For the devices in the Server security zone, do they have just a default route directing traffic to the firewall interface?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;cheers,&lt;/P&gt;
&lt;P&gt;Seb.&lt;/P&gt;</description>
    <pubDate>Wed, 03 Jan 2024 14:11:30 GMT</pubDate>
    <dc:creator>seb_rupik</dc:creator>
    <dc:date>2024-01-03T14:11:30Z</dc:date>
    <item>
      <title>Strange behavior</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/strange-behavior/m-p/571572#M115078</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;facing issue where directed interfaces traffic is not working (from DMZ zone to Servers zone) , while from Inside ZONE to SERVERS is working fine despite inside users SVI is core switch then static route from core switch to paloalto while for users inside DMZ zone their gateway is FW itself (also DHCP ) and no routing is needed to reach SERVERS zone which also their gateway is FW.&amp;nbsp; policy same as&amp;nbsp;&amp;nbsp; Inside ZONE to SERVERS, no NAT.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Note: pic attached&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jan 2024 11:11:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/strange-behavior/m-p/571572#M115078</guid>
      <dc:creator>mhmameen</dc:creator>
      <dc:date>2024-01-03T11:11:35Z</dc:date>
    </item>
    <item>
      <title>Re: Strange behavior</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/strange-behavior/m-p/571603#M115081</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;
&lt;P&gt;Have you confirmed that traffic flows from DMZ -&amp;gt; Servers actually matches the expected security policy rule?&amp;nbsp;&lt;BR /&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/policy/test-policy-rule-traffic-matches" target="_blank"&gt;Test Policy Rules (paloaltonetworks.com)&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the traffic logs do you see the DMZ -&amp;gt; Server flows hitting any Deny rules?&lt;BR /&gt;&lt;BR /&gt;For the devices in the Server security zone, do they have just a default route directing traffic to the firewall interface?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;cheers,&lt;/P&gt;
&lt;P&gt;Seb.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jan 2024 14:11:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/strange-behavior/m-p/571603#M115081</guid>
      <dc:creator>seb_rupik</dc:creator>
      <dc:date>2024-01-03T14:11:30Z</dc:date>
    </item>
  </channel>
</rss>

