<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Security Policy for Anti-virus blocks or allows all in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-for-anti-virus-blocks-or-allows-all/m-p/15760#M11521</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Marcel,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the reply. I believe I understand most of what you said. I do have a few more questions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If what you say is true, then why if I have a rule that is for checking for virus's only and I set the security policy action to allow; then why does the log say that that rule is allowing traffic through instead of the rule following it?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I guess I'm coming from my old firewall's perspective. I want to create a rule for each profile I have created, have the traffic go through each rule, until it's reached the last rule and then allow the traffic to go to it's final destination.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope I'm making sense.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Daniel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 09 Jul 2010 16:54:17 GMT</pubDate>
    <dc:creator>numberall</dc:creator>
    <dc:date>2010-07-09T16:54:17Z</dc:date>
    <item>
      <title>Security Policy for Anti-virus blocks or allows all</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-for-anti-virus-blocks-or-allows-all/m-p/15758#M11519</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've watched the video on how to setup a URL filter security policy. It shows the action selected to be allow. When I created an Anti-virus Profile I set it up to block anything on http.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I then went and created the Security policy selecting that anti-virus profile. If I leave the action set to allowed, this Policy is then shown as letting all traffic through in the logs. If I set the action to Block, then the logs show this Policy as blocking all http traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anyone please tell me what step I'm missing?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Daniel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Jul 2010 22:12:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-for-anti-virus-blocks-or-allows-all/m-p/15758#M11519</guid>
      <dc:creator>numberall</dc:creator>
      <dc:date>2010-07-07T22:12:44Z</dc:date>
    </item>
    <item>
      <title>Re: Security Policy for Anti-virus blocks or allows all</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-for-anti-virus-blocks-or-allows-all/m-p/15759#M11520</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Daniel,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are a couple of actions that you can specify:&lt;/P&gt;&lt;P&gt;-&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; If you set an action in the URL profile it will only take effect on the category you set the action on. So for example if you do not want people to search for another job you can set the action to block on the category job-search.&lt;/P&gt;&lt;P&gt;-&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; If you set an action in the antivirus profile it will only take affect when we find a virus. If we find one we will take the action you have applied on the profile.&lt;/P&gt;&lt;P&gt;-&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; If you set an action in the security policy it will take effect if the traffic matches the policy. So if you setup a policy that includes service 80 and set the action to block it will block all traffic on port 80.&lt;/P&gt;&lt;P&gt;-&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; The different actions do not overrule each other. So the security policy action does not overrule the profile actions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Marcel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Jul 2010 17:59:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-for-anti-virus-blocks-or-allows-all/m-p/15759#M11520</guid>
      <dc:creator>mderksen</dc:creator>
      <dc:date>2010-07-08T17:59:52Z</dc:date>
    </item>
    <item>
      <title>Re: Security Policy for Anti-virus blocks or allows all</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-for-anti-virus-blocks-or-allows-all/m-p/15760#M11521</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Marcel,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the reply. I believe I understand most of what you said. I do have a few more questions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If what you say is true, then why if I have a rule that is for checking for virus's only and I set the security policy action to allow; then why does the log say that that rule is allowing traffic through instead of the rule following it?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I guess I'm coming from my old firewall's perspective. I want to create a rule for each profile I have created, have the traffic go through each rule, until it's reached the last rule and then allow the traffic to go to it's final destination.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope I'm making sense.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Daniel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Jul 2010 16:54:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-for-anti-virus-blocks-or-allows-all/m-p/15760#M11521</guid>
      <dc:creator>numberall</dc:creator>
      <dc:date>2010-07-09T16:54:17Z</dc:date>
    </item>
    <item>
      <title>Re: Security Policy for Anti-virus blocks or allows all</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-for-anti-virus-blocks-or-allows-all/m-p/15761#M11522</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Daniel,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The key to understanding the rulebase is to understand that it is always "first match". If there is a rule that matches (i.e. all the columns to the left of the action column match the traffic) that is the rule that will be used to allow or deny the traffic. Once a match is found, the action is taken. If the action is allow, any profiles applied are then used to scan the traffic. If the application changes midstream, the rulebase is rescanned with the new application to be sure that application should also be allowed. The information in the profile is not used as part of the match criteria.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 10 Jul 2010 01:16:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-for-anti-virus-blocks-or-allows-all/m-p/15761#M11522</guid>
      <dc:creator>mjacobsen</dc:creator>
      <dc:date>2010-07-10T01:16:55Z</dc:date>
    </item>
    <item>
      <title>Re: Security Policy for Anti-virus blocks or allows all</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-for-anti-virus-blocks-or-allows-all/m-p/15762#M11523</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mike,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your last sentence cleared it up for me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The information in the profile is not used as part of the match criteria.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That is what was holding up my understanding of how to apply policies!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Daniel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Jul 2010 19:31:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-for-anti-virus-blocks-or-allows-all/m-p/15762#M11523</guid>
      <dc:creator>numberall</dc:creator>
      <dc:date>2010-07-13T19:31:15Z</dc:date>
    </item>
  </channel>
</rss>

