<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Rule syntax/ordering question in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/rule-syntax-ordering-question/m-p/23236#M16933</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;PA uses top-down first-match (like most FW's do nowadays) which gives that your "Alerting" rule will never be hit since its shadowed by "Block URL for everyone".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you paste the output you get from the commit-window when you commits?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There should be warnings about the shadowing I mentioned above aswell as lack of dependencies (which what I guess is why your user never hits that allow rule).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To test if your userid is correct you could as a test (if possible) set application to "any" to verify that its application related and not userid related.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By the way - your service-column should NEVER be set to any (in my opinion) - you should use "application-default" OR set this manually (like TCP80, TCP443 if you only want browsing to occur on these ports).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 31 May 2012 07:27:54 GMT</pubDate>
    <dc:creator>mikand</dc:creator>
    <dc:date>2012-05-31T07:27:54Z</dc:date>
    <item>
      <title>Rule syntax/ordering question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rule-syntax-ordering-question/m-p/23232#M16929</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We've just installed a PA-2050 in our school and I'm trying to get it configured with some basic rules but I'm not quite sure I have the syntax or ordering of my rules right to achieve the outcome I want.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The simple side of things that I want to do is allow access to Facebook to members of the Active Directory group Staff Users while denying access to everyone else.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here are the two rules that are causing me issues&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="pa rules.jpg" class="jive-image-thumbnail jive-image" onclick="" src="https://live.paloaltonetworks.com/legacyfs/online/3027_pa rules.jpg" width="450" /&gt;&lt;/P&gt;&lt;P&gt;A complicating factor here is that a large number of my students who I'm trying to block here are using their own devices on the wireless and as yet I am unable to identify their AD username which is why I have an "any" in the user field of the deny rule.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any suggestions as to how I can structure my rules to get this outcome.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The next step will be allowing Facebook and Tumblr to those same blocked users on a schedule but for now, I'm happy with just blocking them outright.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 May 2012 22:58:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rule-syntax-ordering-question/m-p/23232#M16929</guid>
      <dc:creator>rangiruru</dc:creator>
      <dc:date>2012-05-30T22:58:21Z</dc:date>
    </item>
    <item>
      <title>Re: Rule syntax/ordering question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rule-syntax-ordering-question/m-p/23233#M16930</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To allow facebook and tumblr, you need to allow web browsing and ssl if you have not already done so. The rule set you have should allow facebook and tumblr access to the staff users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to have control over the users who are not identified by AD, I would suggest using Captive Portal which will provide an authentication page before they can access any resources. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 May 2012 23:54:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rule-syntax-ordering-question/m-p/23233#M16930</guid>
      <dc:creator>zarina</dc:creator>
      <dc:date>2012-05-30T23:54:46Z</dc:date>
    </item>
    <item>
      <title>Re: Rule syntax/ordering question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rule-syntax-ordering-question/m-p/23234#M16931</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here's my full rule set&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="pa rules2.jpg" class="jive-image-thumbnail jive-image" onclick="" src="https://live.paloaltonetworks.com/legacyfs/online/3028_pa rules2.jpg" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Even when I explicitly put my user name in the Staff_Allow rule, the rule below it continues to override it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 May 2012 01:19:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rule-syntax-ordering-question/m-p/23234#M16931</guid>
      <dc:creator>rangiruru</dc:creator>
      <dc:date>2012-05-31T01:19:59Z</dc:date>
    </item>
    <item>
      <title>Re: Rule syntax/ordering question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rule-syntax-ordering-question/m-p/23235#M16932</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Captive portal is one of the user identification methods available on the Palo Alto Networks firewall. Unknown users sending HTTP or HTTPS1 traffic will be authenticated, as specified bythe captive portal rulebase.Attached Tech-Note explains configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A __default_attr="1159" __jive_macro_name="document" class="jive_macro jive_macro_document default_title"&gt;&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 May 2012 06:17:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rule-syntax-ordering-question/m-p/23235#M16932</guid>
      <dc:creator>UhMayYeah</dc:creator>
      <dc:date>2012-05-31T06:17:36Z</dc:date>
    </item>
    <item>
      <title>Re: Rule syntax/ordering question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rule-syntax-ordering-question/m-p/23236#M16933</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;PA uses top-down first-match (like most FW's do nowadays) which gives that your "Alerting" rule will never be hit since its shadowed by "Block URL for everyone".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you paste the output you get from the commit-window when you commits?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There should be warnings about the shadowing I mentioned above aswell as lack of dependencies (which what I guess is why your user never hits that allow rule).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To test if your userid is correct you could as a test (if possible) set application to "any" to verify that its application related and not userid related.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By the way - your service-column should NEVER be set to any (in my opinion) - you should use "application-default" OR set this manually (like TCP80, TCP443 if you only want browsing to occur on these ports).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 May 2012 07:27:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rule-syntax-ordering-question/m-p/23236#M16933</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-05-31T07:27:54Z</dc:date>
    </item>
    <item>
      <title>Re: Rule syntax/ordering question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rule-syntax-ordering-question/m-p/23237#M16934</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you see any activity on that rule in the Traffic Logs on the Monitor page?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try this from the command line…&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;test security-policy-match application facebook-base source-user 'staff username here' source x.x.x.x destination y.y.y.y destination-port XX protocol 6&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From: rangiruru &amp;lt;live@paloaltonetworks.com&amp;lt;mailto:live@paloaltonetworks.com&amp;gt;&amp;gt; &lt;/P&gt;&lt;P&gt;Reply-To: live &amp;lt;live@paloaltonetworks.com&amp;lt;mailto:live@paloaltonetworks.com&amp;gt;&amp;gt; &lt;/P&gt;&lt;P&gt;To: Brad Spilde &amp;lt;brad.spilde@daktronics.com&amp;lt;mailto:brad.spilde@daktronics.com&amp;gt;&amp;gt; &lt;/P&gt;&lt;P&gt;Subject: &lt;A href="https://live.paloaltonetworks.com/DevCenter"&gt;&lt;/A&gt; Rule syntax/ordering question &lt;A href="https://live.paloaltonetworks.com/cbm5s2-1mh-cdq"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We've just installed a PA-2050 in our school and I'm trying to get it configured with some basic rules but I'm not quite sure I have the syntax or ordering of my rules right to achieve the outcome I want.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The simple side of things that I want to do is allow access to Facebook to members of the Active Directory group Staff Users while denying access to everyone else.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here are the two rules that are causing me issues&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Image:pa rules.jpg  (https://live.paloaltonetworks.com/servlet/JiveServlet/showImage/3027/pa+rules.jpg)&lt;/P&gt;&lt;P&gt;A complicating factor here is that a large number of my students who I'm trying to block here are using their own devices on the wireless and as yet I am unable to identify their AD username which is why I have an "any" in the user field of the deny rule.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any suggestions as to how I can structure my rules to get this outcome.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The next step will be allowing Facebook and Tumblr to those same blocked users on a schedule but for now, I'm happy with just blocking them outright.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Jun 2012 15:31:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rule-syntax-ordering-question/m-p/23237#M16934</guid>
      <dc:creator>bspilde</dc:creator>
      <dc:date>2012-06-04T15:31:14Z</dc:date>
    </item>
  </channel>
</rss>

