<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FW specific rules from the Panorama shared policy in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/fw-specific-rules-from-the-panorama-shared-policy/m-p/597169#M118778</link>
    <description>&lt;P&gt;If zone names are different then use source address.&lt;/P&gt;
&lt;P&gt;So assuming source zone that you want to block is&amp;nbsp;&lt;SPAN&gt;siteb_trust and subnet used is 10.5.5.0/24 then push policy to firewall with source zone any source address 10.5.5.0/24&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 06 Sep 2024 14:10:16 GMT</pubDate>
    <dc:creator>Raido_Rattameister</dc:creator>
    <dc:date>2024-09-06T14:10:16Z</dc:date>
    <item>
      <title>FW specific rules from the Panorama shared policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fw-specific-rules-from-the-panorama-shared-policy/m-p/597131#M118774</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;Using Panorama (10.1.x) with a number of managed FWs&lt;BR /&gt;we have a shared pre policy, parent pre policy and child policies with pre rules configured within.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;goal - in event of a security incident on a branch location we want to have a pre-defined deny rule in the parent pre-policy in place that we can just enable and push down to a specific FW that will invoke this deny rule on this FW only...example:&lt;/P&gt;
&lt;P&gt;"src zone: any &amp;gt; dst zone: untrust &amp;gt; action deny"&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;So i want to add a deny rule (will be disabled by default) on my parent pre policy that when enabled, will be targeted to a specific FW and committed.. so then it only applies and enables in on the target FW.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;however all the FWs managed has different naming conventions for zones ie sitea_zone_trust, siteb_zone_trust etc..&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;instead of creating multiple policies in the parent pre rule defining each zone name.. is there a way i can do the following..&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;when enabling the parent pre policy deny rule.. and selecting the target for it, then to commit it to the FW but then for the FW to automatically ingest the source zone as siteb_trust for instance when the parent pre rule has 'any' defined for this rule?&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;thanks in adv&lt;/P&gt;</description>
      <pubDate>Fri, 06 Sep 2024 09:24:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fw-specific-rules-from-the-panorama-shared-policy/m-p/597131#M118774</guid>
      <dc:creator>PA_nts</dc:creator>
      <dc:date>2024-09-06T09:24:59Z</dc:date>
    </item>
    <item>
      <title>Re: FW specific rules from the Panorama shared policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fw-specific-rules-from-the-panorama-shared-policy/m-p/597169#M118778</link>
      <description>&lt;P&gt;If zone names are different then use source address.&lt;/P&gt;
&lt;P&gt;So assuming source zone that you want to block is&amp;nbsp;&lt;SPAN&gt;siteb_trust and subnet used is 10.5.5.0/24 then push policy to firewall with source zone any source address 10.5.5.0/24&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Sep 2024 14:10:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fw-specific-rules-from-the-panorama-shared-policy/m-p/597169#M118778</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2024-09-06T14:10:16Z</dc:date>
    </item>
  </channel>
</rss>

