<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: mail/dns/www/ftp server in DMZ - need advice in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/mail-dns-www-ftp-server-in-dmz-need-advice/m-p/20222#M14717</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Slv,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to answer to the question about using apps or services. The advantages of using Apps is that the PAN would inspect the traffic at application layer and allows only those ports required by that application. ( We should select the service as "App-default" to allow only those ports what the app needs ).&amp;nbsp; I see your security policy with apps and app default and that is the right way.&lt;/P&gt;&lt;P&gt;In regards to the group of profiles, that is used when there is a need to have same set of profiles for multiple security rules making configuration simpler and is completely fine. Rather than individually selecting the profiles for each security rule we can use a group. If needed to customize profiles then we can use profiles selectively.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 04 Oct 2013 16:00:20 GMT</pubDate>
    <dc:creator>Phoenix</dc:creator>
    <dc:date>2013-10-04T16:00:20Z</dc:date>
    <item>
      <title>mail/dns/www/ftp server in DMZ - need advice</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/mail-dns-www-ftp-server-in-dmz-need-advice/m-p/20221#M14716</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm preparing to move my server that is mail/dns/www&amp;nbsp; into DMZ zone. I did some tests and it seems to be working - but as good as I can test...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do I should use application (dns,smtp,pop3,imap,ftp,web-browsing) or use a services on ports 53,25,110,21,80,465,993,995)? &lt;/P&gt;&lt;P&gt;What are you using and why?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My NAT rule:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="2013-10-04_173538.png" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/8857_2013-10-04_173538.png" style="width: 620px; height: 59px;" /&gt;&lt;/P&gt;&lt;P&gt;My security policy:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="2013-10-04_173652.png" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/8858_2013-10-04_173652.png" style="width: 620px; height: 44px;" /&gt;&lt;/P&gt;&lt;P&gt;I have of course U-turn policy to allow acces to this server from my local zones.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What about profiles?&lt;/P&gt;&lt;P&gt;I did one group for servers:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="2013-10-04_174102.png" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/8859_2013-10-04_174102.png" style="width: 620px; height: 48px;" /&gt;&lt;/P&gt;&lt;P&gt;Is it make sens to scan trafficwith this all profiles?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could someone share their policies - please?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I didn't see such topic in this forum and it could be very useful for every new PA user.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With regards&lt;/P&gt;&lt;P&gt;SLawek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Oct 2013 15:49:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/mail-dns-www-ftp-server-in-dmz-need-advice/m-p/20221#M14716</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2013-10-04T15:49:43Z</dc:date>
    </item>
    <item>
      <title>Re: mail/dns/www/ftp server in DMZ - need advice</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/mail-dns-www-ftp-server-in-dmz-need-advice/m-p/20222#M14717</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Slv,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to answer to the question about using apps or services. The advantages of using Apps is that the PAN would inspect the traffic at application layer and allows only those ports required by that application. ( We should select the service as "App-default" to allow only those ports what the app needs ).&amp;nbsp; I see your security policy with apps and app default and that is the right way.&lt;/P&gt;&lt;P&gt;In regards to the group of profiles, that is used when there is a need to have same set of profiles for multiple security rules making configuration simpler and is completely fine. Rather than individually selecting the profiles for each security rule we can use a group. If needed to customize profiles then we can use profiles selectively.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Oct 2013 16:00:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/mail-dns-www-ftp-server-in-dmz-need-advice/m-p/20222#M14717</guid>
      <dc:creator>Phoenix</dc:creator>
      <dc:date>2013-10-04T16:00:20Z</dc:date>
    </item>
    <item>
      <title>Re: mail/dns/www/ftp server in DMZ - need advice</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/mail-dns-www-ftp-server-in-dmz-need-advice/m-p/20223#M14718</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thats good that my polices are OK. But I scared that I missed some aplication ...&lt;/P&gt;&lt;P&gt;ie - I moved www server to DMZ few days ago, and I see that I have to add also new appliocations: rss, web-crawler. Until now I think that it should be in web-browing, but after I checked few times traffic logs for denied applications I realized that I'm wrong.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I agree with you about group of profiles. But is is correct to scan traffic using antivirus/anti-spyware/volnerability/data filtering? or maybe one of them is enought? every profile is taking some resources of PAN, and I'd like to use only that are nessasary.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;p.s. - sorry for my bad english&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;SLawek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Oct 2013 18:00:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/mail-dns-www-ftp-server-in-dmz-need-advice/m-p/20223#M14718</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2013-10-07T18:00:45Z</dc:date>
    </item>
    <item>
      <title>Re: mail/dns/www/ftp server in DMZ - need advice</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/mail-dns-www-ftp-server-in-dmz-need-advice/m-p/20224#M14719</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi SLV,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since you're dealing with new policy, you might want to have a "lose deny" rule below the new one, that way you can verify that the traffic you want is matching and you can tune the deny rule as you see how it's going.&amp;nbsp; So if you are certain you do not what to host FTP or SSH, add those to the deny rule, watch the monitor and add additional service to the allow or deny rule as needed.&amp;nbsp; Once you think you have a stable policy, make the deny a 'deny all' rule and that should do it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Oct 2013 22:02:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/mail-dns-www-ftp-server-in-dmz-need-advice/m-p/20224#M14719</guid>
      <dc:creator>msullivan</dc:creator>
      <dc:date>2013-10-08T22:02:09Z</dc:date>
    </item>
  </channel>
</rss>

