<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Flowcharting rules in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/flowcharting-rules/m-p/26387#M19242</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Wow - and I thought our 240+ policies were bad! Glad to see someone else white-lists more than we do. PA should do more to help organize rules.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 13 Mar 2013 20:56:15 GMT</pubDate>
    <dc:creator>craymond</dc:creator>
    <dc:date>2013-03-13T20:56:15Z</dc:date>
    <item>
      <title>Flowcharting rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/flowcharting-rules/m-p/26382#M19237</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It sounds as if my situation is a bit different than most as from what I gather most people do not use the scheduling feature of the firewall.&amp;nbsp; I am at a pre-K-12 boarding school with dorm students, dorm parents, etc. which means I use the scheduling piece in almost every rule!&amp;nbsp;&amp;nbsp; As part of this I am struggling a bit of following the logic of my rule set (I pity the person who takes this it over of I leave!).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am curious if anyone has been using some sort of third party mind mapping/flow charting software to draw out the logic of their rules?&amp;nbsp; I am not a big fan of Visio.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;OR&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do people use the PA on it's own and just keep adding to it without mapping it out?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Bob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 09 Mar 2013 16:04:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/flowcharting-rules/m-p/26382#M19237</guid>
      <dc:creator>BobW</dc:creator>
      <dc:date>2013-03-09T16:04:10Z</dc:date>
    </item>
    <item>
      <title>Re: Flowcharting rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/flowcharting-rules/m-p/26383#M19238</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;PA on its own with rule comments, or a "simple" Excel spreadsheet with a couple macros and bonus fields :smileysilly:&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 09 Mar 2013 18:44:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/flowcharting-rules/m-p/26383#M19238</guid>
      <dc:creator>BCH</dc:creator>
      <dc:date>2013-03-09T18:44:37Z</dc:date>
    </item>
    <item>
      <title>Re: Flowcharting rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/flowcharting-rules/m-p/26384#M19239</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That is one area that the PAs are really lacking. There are no visualization tools like Cisco ASAs and Netscalers, and no grouping of rules based on zones or policy type like the MS ISA. It also does not even have a numbering column, which is very strange!&amp;nbsp; It would be nice to see some of these introduced. We use the TAG field and the description field to try to keep track of things. There is also an API to export all of the rules to an excel spreadsheet which might be a help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Mar 2013 15:09:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/flowcharting-rules/m-p/26384#M19239</guid>
      <dc:creator>craymond</dc:creator>
      <dc:date>2013-03-11T15:09:45Z</dc:date>
    </item>
    <item>
      <title>Re: Flowcharting rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/flowcharting-rules/m-p/26385#M19240</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is the link to the user DOC on importing to Excel: &lt;A __default_attr="1617" __jive_macro_name="document" class="jive_macro jive_macro_document" href="https://live.paloaltonetworks.com/"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Here is the DOC on using the REST API for more info: - &lt;A __default_attr="4126" __jive_macro_name="document" class="jive_macro jive_macro_document" href="https://live.paloaltonetworks.com/"&gt;&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Mar 2013 16:02:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/flowcharting-rules/m-p/26385#M19240</guid>
      <dc:creator>craymond</dc:creator>
      <dc:date>2013-03-11T16:02:15Z</dc:date>
    </item>
    <item>
      <title>Re: Flowcharting rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/flowcharting-rules/m-p/26386#M19241</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For my sanity, I group the rules by zone. But, that was back when you could sort the rules by zone easily back in PAN-OS 2.0. :smileysilly: I'm starting to use the tags as we've grown to 500+ rules. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Mar 2013 22:27:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/flowcharting-rules/m-p/26386#M19241</guid>
      <dc:creator>mharding</dc:creator>
      <dc:date>2013-03-12T22:27:35Z</dc:date>
    </item>
    <item>
      <title>Re: Flowcharting rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/flowcharting-rules/m-p/26387#M19242</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Wow - and I thought our 240+ policies were bad! Glad to see someone else white-lists more than we do. PA should do more to help organize rules.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Mar 2013 20:56:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/flowcharting-rules/m-p/26387#M19242</guid>
      <dc:creator>craymond</dc:creator>
      <dc:date>2013-03-13T20:56:15Z</dc:date>
    </item>
    <item>
      <title>Re: Flowcharting rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/flowcharting-rules/m-p/26388#M19243</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Absolutely, I remember to have requested such a feature about two years ago in order to organise large rulebases. I am coming from Check Point Firewalls and I really liked their management and still do.&lt;/P&gt;&lt;P&gt;They have a section feature in the rulebase where it&amp;nbsp; allows you to divide the rulebase into different sections with section titles and also to collapse/expand sections.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I constantly get complains by customers regarding the rulebase becoming a mess. I believe a proper firewall management is key to success and here it has a lot to be done by PAN.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Mar 2013 07:00:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/flowcharting-rules/m-p/26388#M19243</guid>
      <dc:creator>gafrol</dc:creator>
      <dc:date>2013-03-14T07:00:21Z</dc:date>
    </item>
    <item>
      <title>Re: Flowcharting rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/flowcharting-rules/m-p/26389#M19244</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This has been a feature request for a long time supposedly from many people.I talked to several people with PA and they have said that it is supposed to be included in a "future release". This was over a year ago! &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Mar 2013 13:13:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/flowcharting-rules/m-p/26389#M19244</guid>
      <dc:creator>craymond</dc:creator>
      <dc:date>2013-03-14T13:13:51Z</dc:date>
    </item>
    <item>
      <title>Re: Flowcharting rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/flowcharting-rules/m-p/26390#M19245</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To me this seems a rather easy addition since it only affects the WebUI and does not need any FW engine related changes.&lt;/P&gt;&lt;P&gt;At the same time this improvement would really help a lot of people.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maybe someone from PAN could share some input here...?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Mar 2013 13:21:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/flowcharting-rules/m-p/26390#M19245</guid>
      <dc:creator>gafrol</dc:creator>
      <dc:date>2013-03-14T13:21:17Z</dc:date>
    </item>
    <item>
      <title>Re: Flowcharting rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/flowcharting-rules/m-p/26391#M19246</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If someone is "friends" with a Palo rep. that has an account,&amp;nbsp; they can share this thread with them using the share button. That might get a quicker response!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Mar 2013 13:42:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/flowcharting-rules/m-p/26391#M19246</guid>
      <dc:creator>craymond</dc:creator>
      <dc:date>2013-03-14T13:42:42Z</dc:date>
    </item>
    <item>
      <title>Re: Flowcharting rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/flowcharting-rules/m-p/26392#M19247</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;done.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Mar 2013 13:46:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/flowcharting-rules/m-p/26392#M19247</guid>
      <dc:creator>gafrol</dc:creator>
      <dc:date>2013-03-14T13:46:04Z</dc:date>
    </item>
  </channel>
</rss>

