<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Security rule says disabled no for an enabled policy in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/security-rule-says-disabled-no-for-an-enabled-policy/m-p/580151#M116221</link>
    <description>&lt;P&gt;Below is the config for policy in question. Only difference is 1 firewall has addtional last line.&lt;/P&gt;
&lt;P&gt;Policy is enabled on both the firewalls.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;set rulebase security rules "rule_name" profile-setting group group_name&lt;BR /&gt;set rulebase security rules "rule_name" to outside&lt;BR /&gt;set rulebase security rules "rule_name" from inside&lt;BR /&gt;set rulebase security rules "rule_name" source source_name&lt;BR /&gt;set rulebase security rules "rule_name" destination [ urls ]&lt;BR /&gt;set rulebase security rules "rule_name" source-user any&lt;BR /&gt;set rulebase security rules "rule_name" category any&lt;BR /&gt;set rulebase security rules "rule_name" application any&lt;BR /&gt;set rulebase security rules "rule_name" service [ https "tcp-8686" ]&lt;BR /&gt;set rulebase security rules "rule_name" source-hip any&lt;BR /&gt;set rulebase security rules "rule_name" destination-hip any&lt;BR /&gt;set rulebase security rules "rule_name" action allow&lt;BR /&gt;set rulebase security rules "rule_name" description *****&lt;BR /&gt;set rulebase security rules "rule_name" log-setting panorama&lt;BR /&gt;set rulebase security rules "rule_name" disabled no&lt;/P&gt;</description>
    <pubDate>Wed, 13 Mar 2024 05:33:19 GMT</pubDate>
    <dc:creator>inderjit21</dc:creator>
    <dc:date>2024-03-13T05:33:19Z</dc:date>
    <item>
      <title>Security rule says disabled no for an enabled policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-rule-says-disabled-no-for-an-enabled-policy/m-p/580144#M116218</link>
      <description>&lt;P&gt;I have 2 firewalls with identical config running same PANOS. The policy in question is enabled on both the firewalls.&lt;/P&gt;
&lt;P&gt;But one firewall has an extra line in cli( which is picked in daily diff)&lt;/P&gt;
&lt;P&gt;set rulebase security rules "rule name" disabled no - So it is saying policy is not disabled but enabled.&lt;/P&gt;
&lt;P&gt;Why is it showing only for 1 enabled policy and not for all other enabled policies or on 2nd firewall with identical config.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Mar 2024 01:35:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-rule-says-disabled-no-for-an-enabled-policy/m-p/580144#M116218</guid>
      <dc:creator>inderjit21</dc:creator>
      <dc:date>2024-03-13T01:35:35Z</dc:date>
    </item>
    <item>
      <title>Re: Security rule says disabled no for an enabled policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-rule-says-disabled-no-for-an-enabled-policy/m-p/580149#M116219</link>
      <description>&lt;P&gt;HI&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27715"&gt;@inderjit21&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you share a snippet of both CLI outputs?&lt;/P&gt;</description>
      <pubDate>Wed, 13 Mar 2024 05:19:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-rule-says-disabled-no-for-an-enabled-policy/m-p/580149#M116219</guid>
      <dc:creator>JayGolf</dc:creator>
      <dc:date>2024-03-13T05:19:52Z</dc:date>
    </item>
    <item>
      <title>Re: Security rule says disabled no for an enabled policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-rule-says-disabled-no-for-an-enabled-policy/m-p/580151#M116221</link>
      <description>&lt;P&gt;Below is the config for policy in question. Only difference is 1 firewall has addtional last line.&lt;/P&gt;
&lt;P&gt;Policy is enabled on both the firewalls.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;set rulebase security rules "rule_name" profile-setting group group_name&lt;BR /&gt;set rulebase security rules "rule_name" to outside&lt;BR /&gt;set rulebase security rules "rule_name" from inside&lt;BR /&gt;set rulebase security rules "rule_name" source source_name&lt;BR /&gt;set rulebase security rules "rule_name" destination [ urls ]&lt;BR /&gt;set rulebase security rules "rule_name" source-user any&lt;BR /&gt;set rulebase security rules "rule_name" category any&lt;BR /&gt;set rulebase security rules "rule_name" application any&lt;BR /&gt;set rulebase security rules "rule_name" service [ https "tcp-8686" ]&lt;BR /&gt;set rulebase security rules "rule_name" source-hip any&lt;BR /&gt;set rulebase security rules "rule_name" destination-hip any&lt;BR /&gt;set rulebase security rules "rule_name" action allow&lt;BR /&gt;set rulebase security rules "rule_name" description *****&lt;BR /&gt;set rulebase security rules "rule_name" log-setting panorama&lt;BR /&gt;set rulebase security rules "rule_name" disabled no&lt;/P&gt;</description>
      <pubDate>Wed, 13 Mar 2024 05:33:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-rule-says-disabled-no-for-an-enabled-policy/m-p/580151#M116221</guid>
      <dc:creator>inderjit21</dc:creator>
      <dc:date>2024-03-13T05:33:19Z</dc:date>
    </item>
    <item>
      <title>Re: Security rule says disabled no for an enabled policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-rule-says-disabled-no-for-an-enabled-policy/m-p/580163#M116222</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The value of "disabled" is set to "no" as a default value. You will only see the "disabled" keyword if you had disabled the rule (where the key-value pair "disabled" - "yes" was added). Re-enabling the rule changes the value to "no" (instead of removing the line).&lt;/P&gt;</description>
      <pubDate>Wed, 13 Mar 2024 07:41:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-rule-says-disabled-no-for-an-enabled-policy/m-p/580163#M116222</guid>
      <dc:creator>JoergSchuetter</dc:creator>
      <dc:date>2024-03-13T07:41:52Z</dc:date>
    </item>
    <item>
      <title>Re: Security rule says disabled no for an enabled policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-rule-says-disabled-no-for-an-enabled-policy/m-p/580214#M116230</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27715"&gt;@inderjit21&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Just to add on to the correct answer&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/83320"&gt;@JoergSchuetter&lt;/a&gt;&amp;nbsp;already gave, you&amp;nbsp;&lt;EM&gt;can&amp;nbsp;&lt;/EM&gt;safely remove it completely if it bugs you to have that difference between the two units. As mentioned, if not present in the configuration that is the default assumed value.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Mar 2024 13:06:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-rule-says-disabled-no-for-an-enabled-policy/m-p/580214#M116230</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2024-03-13T13:06:53Z</dc:date>
    </item>
  </channel>
</rss>

