<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What am I doing wrong? This policy to block unknown traffic to countries outside the US. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/what-am-i-doing-wrong-this-policy-to-block-unknown-traffic-to/m-p/2295#M1695</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What if you did an allow rule to the US above the rule that's not working, and then do your negate rule directly after it?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 16 May 2013 14:17:20 GMT</pubDate>
    <dc:creator>ericgearhart</dc:creator>
    <dc:date>2013-05-16T14:17:20Z</dc:date>
    <item>
      <title>What am I doing wrong? This policy to block unknown traffic to countries outside the US.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-am-i-doing-wrong-this-policy-to-block-unknown-traffic-to/m-p/2294#M1694</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a new policy that I pushed yesterday that was a total failure and any help you can offer would be appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a policy that looks like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Source &amp;lt;Internal IP addresses&amp;gt;&lt;/P&gt;&lt;P&gt;Destination &amp;lt;Negate Region US&amp;gt;&lt;/P&gt;&lt;P&gt;Application &amp;lt;unknown-tcp, unknown-udp&amp;gt;&lt;/P&gt;&lt;P&gt;DENY&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, it is catching and DENYing all unknown-tcp and unknown-udp regardless of Destination Country. We have some internal applications used by our customers that this blocks as I haven't been able to classify all applications we use in house as of yet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This logic seems like it should be working, am I doing something wrong?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Benc&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 May 2013 13:14:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-am-i-doing-wrong-this-policy-to-block-unknown-traffic-to/m-p/2294#M1694</guid>
      <dc:creator>bgranholm</dc:creator>
      <dc:date>2013-05-16T13:14:32Z</dc:date>
    </item>
    <item>
      <title>Re: What am I doing wrong? This policy to block unknown traffic to countries outside the US.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-am-i-doing-wrong-this-policy-to-block-unknown-traffic-to/m-p/2295#M1695</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What if you did an allow rule to the US above the rule that's not working, and then do your negate rule directly after it?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 May 2013 14:17:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-am-i-doing-wrong-this-policy-to-block-unknown-traffic-to/m-p/2295#M1695</guid>
      <dc:creator>ericgearhart</dc:creator>
      <dc:date>2013-05-16T14:17:20Z</dc:date>
    </item>
    <item>
      <title>Re: What am I doing wrong? This policy to block unknown traffic to countries outside the US.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-am-i-doing-wrong-this-policy-to-block-unknown-traffic-to/m-p/2296#M1696</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don't want to create policy sprawl, I would rather keep it in one rule.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 May 2013 15:13:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-am-i-doing-wrong-this-policy-to-block-unknown-traffic-to/m-p/2296#M1696</guid>
      <dc:creator>bgranholm</dc:creator>
      <dc:date>2013-05-16T15:13:42Z</dc:date>
    </item>
    <item>
      <title>Re: What am I doing wrong? This policy to block unknown traffic to countries outside the US.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-am-i-doing-wrong-this-policy-to-block-unknown-traffic-to/m-p/2297#M1697</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did you check the destination country from IP address you want to pass through?&lt;/P&gt;&lt;P&gt;You can check it as follow.&lt;/P&gt;&lt;P&gt;&amp;gt; show location ip 1.1.1.1&lt;/P&gt;&lt;P&gt;If your customer's IP address is not US, I think that's expected behavior.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 May 2013 15:25:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-am-i-doing-wrong-this-policy-to-block-unknown-traffic-to/m-p/2297#M1697</guid>
      <dc:creator>emr_1</dc:creator>
      <dc:date>2013-05-16T15:25:32Z</dc:date>
    </item>
    <item>
      <title>Re: What am I doing wrong? This policy to block unknown traffic to countries outside the US.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-am-i-doing-wrong-this-policy-to-block-unknown-traffic-to/m-p/2298#M1698</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Our customer's IP space was internal space, they are the source. The destination was definitely an IP in the US and it still got blocked.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 May 2013 15:27:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-am-i-doing-wrong-this-policy-to-block-unknown-traffic-to/m-p/2298#M1698</guid>
      <dc:creator>bgranholm</dc:creator>
      <dc:date>2013-05-16T15:27:32Z</dc:date>
    </item>
    <item>
      <title>Re: What am I doing wrong? This policy to block unknown traffic to countries outside the US.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-am-i-doing-wrong-this-policy-to-block-unknown-traffic-to/m-p/2299#M1699</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Honestly it's frustrating to even make suggestions here because you won't even just try some of the suggestions. Do the 'show location ip' command and let us see what the PA thinks the destination country is. Try tossing in the "policy sprawl" rule just to see if it works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you won't at least just try some things to see if they make a difference or reveal the problem, then there's no point in asking for help, right?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 May 2013 15:31:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-am-i-doing-wrong-this-policy-to-block-unknown-traffic-to/m-p/2299#M1699</guid>
      <dc:creator>ericgearhart</dc:creator>
      <dc:date>2013-05-16T15:31:16Z</dc:date>
    </item>
    <item>
      <title>Re: What am I doing wrong? This policy to block unknown traffic to countries outside the US.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-am-i-doing-wrong-this-policy-to-block-unknown-traffic-to/m-p/2300#M1700</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If it is internal space (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) it will not be seen as the United States. The location is seen as "Reserved", as seen by the command given by egearhart.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the destination address is an IPv6 address, it may not yet be supported.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When you look at the traffic logs for that traffic, how many packets are seen in the c2s and s2c flows? You can also check the session id (CLI command: show session id 123456) that is present in the logs to see what application it is identified as and which rule it is hitting.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps,&lt;/P&gt;&lt;P&gt;Greg Wesson &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 May 2013 16:22:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-am-i-doing-wrong-this-policy-to-block-unknown-traffic-to/m-p/2300#M1700</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2013-05-16T16:22:31Z</dc:date>
    </item>
    <item>
      <title>Re: What am I doing wrong? This policy to block unknown traffic to countries outside the US.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-am-i-doing-wrong-this-policy-to-block-unknown-traffic-to/m-p/2301#M1701</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I apologize as apparently I was not being clear enough.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the traffic logs, this rule is blocking ALL unknown-tcp and udp traffic, even the traffic that has a Destination Country of US.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is my rule with the non-public bits removed in set notation. It is in our security post-rules for our Internet traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"Block unknown to non-US" from any&lt;/P&gt;&lt;P&gt;"Block unknown to non-US" to any&lt;/P&gt;&lt;P&gt;"Block unknown to non-US" source "&amp;lt;Internal Private Address Space&amp;gt;"&lt;/P&gt;&lt;P&gt;"Block unknown to non-US" destination US&lt;/P&gt;&lt;P&gt;"Block unknown to non-US" source-user any&lt;/P&gt;&lt;P&gt;"Block unknown to non-US" category any&lt;/P&gt;&lt;P&gt;"Block unknown to non-US" application unknown-tcp&lt;/P&gt;&lt;P&gt;"Block unknown to non-US" application unknown-udp&lt;/P&gt;&lt;P&gt;"Block unknown to non-US" service any&lt;/P&gt;&lt;P&gt;"Block unknown to non-US" hip-profiles any&lt;/P&gt;&lt;P&gt;"Block unknown to non-US" negate-source no&lt;/P&gt;&lt;P&gt;"Block unknown to non-US" negate-destination yes&lt;/P&gt;&lt;P&gt;"Block unknown to non-US" action deny&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 May 2013 17:43:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-am-i-doing-wrong-this-policy-to-block-unknown-traffic-to/m-p/2301#M1701</guid>
      <dc:creator>bgranholm</dc:creator>
      <dc:date>2013-05-16T17:43:27Z</dc:date>
    </item>
  </channel>
</rss>

