<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: security policies in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/security-policies/m-p/1256371#M126596</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1468908427"&gt;@mostafa.abdelhakem&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-path-to-node="0"&gt;To accomplish this on a PA-460, you have two distinct approaches depending on whether you want a &lt;STRONG data-index-in-node="130" data-path-to-node="0"&gt;push&lt;/STRONG&gt; method (scheduling automated email reports) or a &lt;STRONG data-index-in-node="184" data-path-to-node="0"&gt;pull&lt;/STRONG&gt; method (granting direct, read-only access to an external auditor).&lt;/P&gt;
&lt;P data-path-to-node="0"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-path-to-node="0"&gt;Because "Security Policies" are part of the firewall's XML configuration file rather than dynamic traffic data, standard PDF custom reports won't show the exact rule geometry. However, for auditing Palo Alto policies you can configure notifications for configuration changes under &lt;STRONG&gt;Device &amp;gt; Log Settings &amp;gt; Configurations.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P data-path-to-node="3"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-path-to-node="3"&gt;As for granting Read-Only Access to an Auditor,&amp;nbsp;&amp;nbsp;you can create a customized &lt;STRONG data-index-in-node="180" data-path-to-node="4"&gt;Admin Role Profile:&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL start="1" data-path-to-node="6"&gt;
&lt;LI&gt;
&lt;P data-path-to-node="6,0,0"&gt;Navigate to &lt;STRONG data-index-in-node="12" data-path-to-node="6,0,0"&gt;Device &amp;gt; Admin Role&lt;/STRONG&gt;&amp;nbsp;and click &lt;STRONG data-index-in-node="51" data-path-to-node="6,0,0"&gt;Add&lt;/STRONG&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P data-path-to-node="6,1,0"&gt;Name the profile something clear (e.g., &lt;CODE data-index-in-node="40" data-path-to-node="6,1,0"&gt;Auditor-Read-Only&lt;/CODE&gt;).&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P data-path-to-node="6,2,0"&gt;Under the &lt;STRONG data-index-in-node="10" data-path-to-node="6,2,0"&gt;Web UI&lt;/STRONG&gt; tab, set the rules for the tabs you want them to see.&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P data-path-to-node="7"&gt;Then you can create the actual auditor account.&amp;nbsp; Go to &lt;STRONG data-index-in-node="6" data-path-to-node="8,0,0"&gt;Device &amp;gt; Administrators&lt;/STRONG&gt; and click create a role based admin using the profile you just created earlier.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps,&lt;/P&gt;</description>
    <pubDate>Mon, 15 Jun 2026 14:36:20 GMT</pubDate>
    <dc:creator>kiwi</dc:creator>
    <dc:date>2026-06-15T14:36:20Z</dc:date>
    <item>
      <title>security policies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policies/m-p/1256370#M126595</link>
      <description>&lt;P&gt;hello , i need to extract security policies from palo alto appliance&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Model (PA-460)&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;is there a way to schedule the report or grant read only access to audit function ?&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jun 2026 13:36:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policies/m-p/1256370#M126595</guid>
      <dc:creator>mostafa.abdelhakem</dc:creator>
      <dc:date>2026-06-15T13:36:12Z</dc:date>
    </item>
    <item>
      <title>Re: security policies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policies/m-p/1256371#M126596</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1468908427"&gt;@mostafa.abdelhakem&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-path-to-node="0"&gt;To accomplish this on a PA-460, you have two distinct approaches depending on whether you want a &lt;STRONG data-index-in-node="130" data-path-to-node="0"&gt;push&lt;/STRONG&gt; method (scheduling automated email reports) or a &lt;STRONG data-index-in-node="184" data-path-to-node="0"&gt;pull&lt;/STRONG&gt; method (granting direct, read-only access to an external auditor).&lt;/P&gt;
&lt;P data-path-to-node="0"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-path-to-node="0"&gt;Because "Security Policies" are part of the firewall's XML configuration file rather than dynamic traffic data, standard PDF custom reports won't show the exact rule geometry. However, for auditing Palo Alto policies you can configure notifications for configuration changes under &lt;STRONG&gt;Device &amp;gt; Log Settings &amp;gt; Configurations.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P data-path-to-node="3"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-path-to-node="3"&gt;As for granting Read-Only Access to an Auditor,&amp;nbsp;&amp;nbsp;you can create a customized &lt;STRONG data-index-in-node="180" data-path-to-node="4"&gt;Admin Role Profile:&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL start="1" data-path-to-node="6"&gt;
&lt;LI&gt;
&lt;P data-path-to-node="6,0,0"&gt;Navigate to &lt;STRONG data-index-in-node="12" data-path-to-node="6,0,0"&gt;Device &amp;gt; Admin Role&lt;/STRONG&gt;&amp;nbsp;and click &lt;STRONG data-index-in-node="51" data-path-to-node="6,0,0"&gt;Add&lt;/STRONG&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P data-path-to-node="6,1,0"&gt;Name the profile something clear (e.g., &lt;CODE data-index-in-node="40" data-path-to-node="6,1,0"&gt;Auditor-Read-Only&lt;/CODE&gt;).&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P data-path-to-node="6,2,0"&gt;Under the &lt;STRONG data-index-in-node="10" data-path-to-node="6,2,0"&gt;Web UI&lt;/STRONG&gt; tab, set the rules for the tabs you want them to see.&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P data-path-to-node="7"&gt;Then you can create the actual auditor account.&amp;nbsp; Go to &lt;STRONG data-index-in-node="6" data-path-to-node="8,0,0"&gt;Device &amp;gt; Administrators&lt;/STRONG&gt; and click create a role based admin using the profile you just created earlier.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps,&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jun 2026 14:36:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policies/m-p/1256371#M126596</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2026-06-15T14:36:20Z</dc:date>
    </item>
  </channel>
</rss>

