<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic wrong traffic matching rule in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/wrong-traffic-matching-rule/m-p/1236543#M125017</link>
    <description>&lt;P&gt;Hi this maybe a simple or dumb question, but I have a rule shown below that has specific sources defined. I thought the rule would only match on those host listed in the source, but when looking at the logs, I can see other source IP's are matching on this rule. Can anyone explain why the other source IP's that are not listed in this rule match this rule?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;this is the rule&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="palo-rule.jpg" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/68977iA4F403A36EA85AE4/image-size/medium?v=v2&amp;amp;px=400" role="button" title="palo-rule.jpg" alt="palo-rule.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;When looking at the logs I am seeing IP's other than the listed source match on this rule.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="palo-logs.jpg" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/68978i52CC916E07ED4A8B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="palo-logs.jpg" alt="palo-logs.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
    <pubDate>Sat, 23 Aug 2025 19:25:23 GMT</pubDate>
    <dc:creator>E.Hinkle</dc:creator>
    <dc:date>2025-08-23T19:25:23Z</dc:date>
    <item>
      <title>wrong traffic matching rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wrong-traffic-matching-rule/m-p/1236543#M125017</link>
      <description>&lt;P&gt;Hi this maybe a simple or dumb question, but I have a rule shown below that has specific sources defined. I thought the rule would only match on those host listed in the source, but when looking at the logs, I can see other source IP's are matching on this rule. Can anyone explain why the other source IP's that are not listed in this rule match this rule?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;this is the rule&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="palo-rule.jpg" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/68977iA4F403A36EA85AE4/image-size/medium?v=v2&amp;amp;px=400" role="button" title="palo-rule.jpg" alt="palo-rule.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;When looking at the logs I am seeing IP's other than the listed source match on this rule.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="palo-logs.jpg" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/68978i52CC916E07ED4A8B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="palo-logs.jpg" alt="palo-logs.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Sat, 23 Aug 2025 19:25:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wrong-traffic-matching-rule/m-p/1236543#M125017</guid>
      <dc:creator>E.Hinkle</dc:creator>
      <dc:date>2025-08-23T19:25:23Z</dc:date>
    </item>
    <item>
      <title>Re: wrong traffic matching rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wrong-traffic-matching-rule/m-p/1236565#M125019</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/684046813"&gt;@E.Hinkle&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you click into the Security Policy and review the Source tab, can you confirm whether the entries are address objects or IP entries? It looks like at least one of them (ip-10.35.5.71) may be an object.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Please check the object definition and see if the object was created with a CIDR/netmask instead of it being a single host/32 which would explain why you're seeing other 10.35.5.x IPs in the traffic log.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Id also review the modified tab to see when it was last modified.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Aug 2025 00:56:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wrong-traffic-matching-rule/m-p/1236565#M125019</guid>
      <dc:creator>JayGolf</dc:creator>
      <dc:date>2025-08-25T00:56:18Z</dc:date>
    </item>
  </channel>
</rss>

