<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Rule shadowing in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/rule-shadowing/m-p/17166#M12532</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;
&lt;P&gt;jprovine wrote:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;so the rule needs to be moved above the rule that it shadows to be affective if there are any differences in the rule to start with&lt;/P&gt;
&lt;/PRE&gt;&lt;P&gt;Correct, firewall rules are processed from the top of the list down.&amp;nbsp; And they stop processing on the FIRST match of criteria.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thus you need your most specific rules to appear in the rule base before the least specific rules.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 03 Apr 2015 10:37:18 GMT</pubDate>
    <dc:creator>pulukas</dc:creator>
    <dc:date>2015-04-03T10:37:18Z</dc:date>
    <item>
      <title>Rule shadowing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rule-shadowing/m-p/17163#M12529</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;does that basically mean you have more than one rule doing the same thing?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Apr 2015 18:26:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rule-shadowing/m-p/17163#M12529</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2015-04-02T18:26:48Z</dc:date>
    </item>
    <item>
      <title>Re: Rule shadowing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rule-shadowing/m-p/17164#M12530</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes.&amp;nbsp; It means that traffic will never hit the rule you just added because there is a rule above it that matches (at least) all of the criteria of the one you just created.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-1624"&gt;https://live.paloaltonetworks.com/docs/DOC-1624&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Apr 2015 19:20:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rule-shadowing/m-p/17164#M12530</guid>
      <dc:creator>Bradley_Melton</dc:creator>
      <dc:date>2015-04-02T19:20:53Z</dc:date>
    </item>
    <item>
      <title>Re: Rule shadowing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rule-shadowing/m-p/17165#M12531</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;so the rule needs to be moved above the rule that it shadows to be affective if there are any differences in the rule to start with&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Apr 2015 21:38:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rule-shadowing/m-p/17165#M12531</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2015-04-02T21:38:13Z</dc:date>
    </item>
    <item>
      <title>Re: Rule shadowing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rule-shadowing/m-p/17166#M12532</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;
&lt;P&gt;jprovine wrote:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;so the rule needs to be moved above the rule that it shadows to be affective if there are any differences in the rule to start with&lt;/P&gt;
&lt;/PRE&gt;&lt;P&gt;Correct, firewall rules are processed from the top of the list down.&amp;nbsp; And they stop processing on the FIRST match of criteria.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thus you need your most specific rules to appear in the rule base before the least specific rules.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Apr 2015 10:37:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rule-shadowing/m-p/17166#M12532</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2015-04-03T10:37:18Z</dc:date>
    </item>
  </channel>
</rss>

