<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: block interne in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/block-interne/m-p/34791#M25539</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi satish,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By default In-coming Internet traffic is blocked for any Host behind the firewall. You may want to find out, why its allowed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That would be a good first troubleshooting step.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 01 Jul 2014 01:22:42 GMT</pubDate>
    <dc:creator>hshah</dc:creator>
    <dc:date>2014-07-01T01:22:42Z</dc:date>
    <item>
      <title>block interne</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-interne/m-p/34788#M25536</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi friends,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How to block internet on our DB servers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Satish&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Jun 2014 10:50:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-interne/m-p/34788#M25536</guid>
      <dc:creator>Satish</dc:creator>
      <dc:date>2014-06-30T10:50:15Z</dc:date>
    </item>
    <item>
      <title>Re: block interne</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-interne/m-p/34789#M25537</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You would create an address group that contains all of the db servers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;then create a deny policy from this group to your internet zone as a block.&amp;nbsp; Use log on session initiation to see what hits this&amp;nbsp; rule.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Jun 2014 12:18:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-interne/m-p/34789#M25537</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2014-06-30T12:18:44Z</dc:date>
    </item>
    <item>
      <title>Re: block interne</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-interne/m-p/34790#M25538</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Another alternative is to open your Source NAT policy that broadly enables your network to gain internet access, and add the IP Addresses (or the Address Group as Steven Puluka suggested) to the Source Address group. You then check the box underneath that indicates "Negate". This will say: - "Do a Source NAT to enable internal network to gain internet access "except" if the source address is with these source addresses".&lt;/P&gt;&lt;P&gt;The Security Policy alternative mentioned by Steven is a better practice, and it will write access attempts to the traffic logs.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Jul 2014 00:54:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-interne/m-p/34790#M25538</guid>
      <dc:creator>mivaldi</dc:creator>
      <dc:date>2014-07-01T00:54:54Z</dc:date>
    </item>
    <item>
      <title>Re: block interne</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-interne/m-p/34791#M25539</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi satish,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By default In-coming Internet traffic is blocked for any Host behind the firewall. You may want to find out, why its allowed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That would be a good first troubleshooting step.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Jul 2014 01:22:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-interne/m-p/34791#M25539</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-07-01T01:22:42Z</dc:date>
    </item>
    <item>
      <title>Re: block interne</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-interne/m-p/34792#M25540</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Dud...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Jul 2014 11:30:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-interne/m-p/34792#M25540</guid>
      <dc:creator>Satish</dc:creator>
      <dc:date>2014-07-02T11:30:53Z</dc:date>
    </item>
  </channel>
</rss>

