<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Clean Firewall Policies in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/clean-firewall-policies/m-p/614727#M121480</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/132521"&gt;@SutareMayur&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Thanks for your advices.&amp;nbsp;After the cleaning my rules, I want to order them and I want to collect my rules in subfields. Such as, SSL VPN rules will be in part, LAN-WAN rules in a part. How can I organize my rule base ?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 25 Oct 2024 08:16:25 GMT</pubDate>
    <dc:creator>tombombadil</dc:creator>
    <dc:date>2024-10-25T08:16:25Z</dc:date>
    <item>
      <title>Clean Firewall Policies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/clean-firewall-policies/m-p/614691#M121466</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am thinking of how can i clean/organize my firewall policies.&amp;nbsp;Many rules seem to be mixed up within each other. Do you have any suggestions to make it more appealing to the eye? How should I organize my rules?&lt;/P&gt;</description>
      <pubDate>Fri, 25 Oct 2024 07:15:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/clean-firewall-policies/m-p/614691#M121466</guid>
      <dc:creator>tombombadil</dc:creator>
      <dc:date>2024-10-25T07:15:27Z</dc:date>
    </item>
    <item>
      <title>Re: Clean Firewall Policies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/clean-firewall-policies/m-p/614701#M121472</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/309212"&gt;@tombombadil&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Firewall security policies is a bit complex and lengthy process because you can't delete/update any rules right away. This might create an issue or outages at times. Though it is a lengthy process, if you follow right process, eventually you can optimize the ruleset.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would recommend you to look for below rules first and see if you really need those rules. At times, you might need to monitor the rules for some time period to see if is it really being used.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also, when you find any rule to be clean up as not used since long or never used at all, &lt;EM&gt;&lt;STRONG&gt;DO NOT DELETE SUCH RULE/S RIGHT AWAY. BEST PRACTICE IS TO DISABLE IT FOR SOME PERIOD AND SEE IF ANYONE REPORTS ANY ISSUES. IF NOTHING COMES THEN YOU CAN DELETE IT.&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. Check for Over permissive rules. E.g. rules with ANY ports/apps and/or source/destinations.&lt;/P&gt;
&lt;P&gt;2. Check for unused or not used in recent time rules based on the hit counts on the rule.&lt;/P&gt;
&lt;P data-unlink="true"&gt;3. Check and try to use Security Policy Optimizer. &amp;nbsp;This will help you to optimize your rule base efficiently.&lt;/P&gt;
&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PMThCAO" target="_self"&gt;Security Policy Optimizer&lt;/A&gt;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/app-id/security-policy-rule-optimization#:~:text=Policy%20Optimizer%20provides%20a%20simple,you%20can%20safely%20enable%20them." target="_self"&gt;Security Policy Optimization&lt;/A&gt;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-unlink="true"&gt;Hope it helps!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Oct 2024 07:49:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/clean-firewall-policies/m-p/614701#M121472</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2024-10-25T07:49:34Z</dc:date>
    </item>
    <item>
      <title>Re: Clean Firewall Policies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/clean-firewall-policies/m-p/614727#M121480</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/132521"&gt;@SutareMayur&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Thanks for your advices.&amp;nbsp;After the cleaning my rules, I want to order them and I want to collect my rules in subfields. Such as, SSL VPN rules will be in part, LAN-WAN rules in a part. How can I organize my rule base ?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Oct 2024 08:16:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/clean-firewall-policies/m-p/614727#M121480</guid>
      <dc:creator>tombombadil</dc:creator>
      <dc:date>2024-10-25T08:16:25Z</dc:date>
    </item>
    <item>
      <title>Re: Clean Firewall Policies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/clean-firewall-policies/m-p/615604#M121828</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;This is a question a lot of people have. The answer is it depends. Lots of ways doing this but the main thing to remember is that the firewall reads the rules from top to bottom left to right. Meaning once a policy is matched, it gets applied. I do the following:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Main blocking policies - i.e. block IP's by geolocation, countries, then dynamic block lists that are built into the firewall. Block applications I know we dont want, ie TOR. This is for both inbound and outbound traffic.&lt;/LI&gt;
&lt;LI&gt;Traffic I know I want to allow, ie VPN tunnels, client VPN etc.&lt;/LI&gt;
&lt;LI&gt;Then I create a policy at the botton, for DENY ALL&lt;/LI&gt;
&lt;LI&gt;Then create policies for traffic I want as an exception for the DENY ALL&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;I know its pretty general but grouping policies can become cumbersome and complicated. Also can inadvertently allow bad traffic or block legit traffic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Oct 2024 16:58:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/clean-firewall-policies/m-p/615604#M121828</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2024-10-29T16:58:05Z</dc:date>
    </item>
  </channel>
</rss>

