<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Re-evaluating current structure in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/re-evaluating-current-structure/m-p/26171#M19108</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If that's your policy, then go for it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I work the other way around - I do three rules, but the final one is an allow any/any - but email me a report about it so I can slowly close loopholes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I find that leads to less complaints when Fred Nerks favourite, business critical application suddenly stops working. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 07 Mar 2013 21:44:09 GMT</pubDate>
    <dc:creator>darren_g</dc:creator>
    <dc:date>2013-03-07T21:44:09Z</dc:date>
    <item>
      <title>Re-evaluating current structure</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/re-evaluating-current-structure/m-p/26168#M19105</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am currently managing users via AD groups but need a more granular approach.&amp;nbsp; I recently added a BYOD device manager to my network.&amp;nbsp; It divides my 2 main groups using a specific IP range.&amp;nbsp; If I use this method to manage users I will probably have to reset all my policies.&amp;nbsp; My question is should I start by blocking all processes then open just what we need.&amp;nbsp; Which rule should go first?&lt;/P&gt;&lt;P&gt;I have Students and faculy-Staff&lt;/P&gt;&lt;P&gt;Faculty-Staff can have network access, printers etc.&amp;nbsp;&amp;nbsp; social media, streaming media, Netflix etc&lt;/P&gt;&lt;P&gt;Students with Auth machines can have network share access&lt;/P&gt;&lt;P&gt;No Social Media, games, (all the usual blocks)&amp;nbsp; limited (QOS) streaming media, no Netflix, Hulu TV. &lt;/P&gt;&lt;P&gt;What rules should I start with&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Mar 2013 03:04:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/re-evaluating-current-structure/m-p/26168#M19105</guid>
      <dc:creator>MemphisBrothers</dc:creator>
      <dc:date>2013-03-06T03:04:21Z</dc:date>
    </item>
    <item>
      <title>Re: Re-evaluating current structure</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/re-evaluating-current-structure/m-p/26169#M19106</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Depends on how savage you want to be.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to work up from a "deny everything" scenario, I would start with two rules for each affected zone (facility &amp;amp; students) or IP range.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;First rule - allow selected applications. Remember, you need to start with the most OPEN rule first, because rules are processed sequentially, and if you make your first rule "deny everything", then all traffic will hit this rule, match, and nothing else will be processed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Actually, you can do it with three rules - I'd do something like this&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Source: Facility zone/IP range - Allow : required apps&lt;/P&gt;&lt;P&gt;Source : Student zone/IP range - Allow : required apps&lt;/P&gt;&lt;P&gt;Source : Any - Deny : Any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That way, anything which doesn't match the first two rules rull fall through to the "deny" rule and be blocked. The most open rule (the faculty one) should be the first security rule in your list, then the next most restrictive one (the student rule), then the complete deny rule.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to be more open, it's a little more complex.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Mar 2013 00:35:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/re-evaluating-current-structure/m-p/26169#M19106</guid>
      <dc:creator>darren_g</dc:creator>
      <dc:date>2013-03-07T00:35:36Z</dc:date>
    </item>
    <item>
      <title>Re: Re-evaluating current structure</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/re-evaluating-current-structure/m-p/26170#M19107</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It is a step.&amp;nbsp; We have Spring Break coming up.&amp;nbsp; Perfect time to re design the policies.&amp;nbsp; I'll start with the Scorched earth policy and open from there.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Mar 2013 15:01:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/re-evaluating-current-structure/m-p/26170#M19107</guid>
      <dc:creator>MemphisBrothers</dc:creator>
      <dc:date>2013-03-07T15:01:23Z</dc:date>
    </item>
    <item>
      <title>Re: Re-evaluating current structure</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/re-evaluating-current-structure/m-p/26171#M19108</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If that's your policy, then go for it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I work the other way around - I do three rules, but the final one is an allow any/any - but email me a report about it so I can slowly close loopholes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I find that leads to less complaints when Fred Nerks favourite, business critical application suddenly stops working. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Mar 2013 21:44:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/re-evaluating-current-structure/m-p/26171#M19108</guid>
      <dc:creator>darren_g</dc:creator>
      <dc:date>2013-03-07T21:44:09Z</dc:date>
    </item>
  </channel>
</rss>

