<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Apply zone protection - to which zone? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/apply-zone-protection-to-which-zone/m-p/36113#M26541</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am wondering where and how zone protection profiles are applied to. I figure if I attach a zone protection profile to a zone, all resources behind that zone are under protection. But let's take the following example:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;* one interface connected to internet (zone: untrust)&lt;/P&gt;&lt;P&gt;* one interface connected to internal LAN (zone: trust)&lt;/P&gt;&lt;P&gt;* several interfaces for different DMZs (zone: dmz)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now if I want to protect my DMZ, do I apply the zone protection to the DMZ zone or to the untrust zone? There are actually no resources connected directly to the untrust zone, but I would believe that protecting the untrust zone would automatically protect all zones behind the untrust zone, including DMZ and trust. Am I right with this assumption?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In this scenario, why would I still apply different zone protection profiles to DMZ and trust? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How does traffic flow relate to zone protection?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;zone&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 26 May 2013 22:20:03 GMT</pubDate>
    <dc:creator>cryptochrome</dc:creator>
    <dc:date>2013-05-26T22:20:03Z</dc:date>
    <item>
      <title>Apply zone protection - to which zone?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/apply-zone-protection-to-which-zone/m-p/36113#M26541</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am wondering where and how zone protection profiles are applied to. I figure if I attach a zone protection profile to a zone, all resources behind that zone are under protection. But let's take the following example:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;* one interface connected to internet (zone: untrust)&lt;/P&gt;&lt;P&gt;* one interface connected to internal LAN (zone: trust)&lt;/P&gt;&lt;P&gt;* several interfaces for different DMZs (zone: dmz)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now if I want to protect my DMZ, do I apply the zone protection to the DMZ zone or to the untrust zone? There are actually no resources connected directly to the untrust zone, but I would believe that protecting the untrust zone would automatically protect all zones behind the untrust zone, including DMZ and trust. Am I right with this assumption?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In this scenario, why would I still apply different zone protection profiles to DMZ and trust? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How does traffic flow relate to zone protection?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;zone&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 26 May 2013 22:20:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/apply-zone-protection-to-which-zone/m-p/36113#M26541</guid>
      <dc:creator>cryptochrome</dc:creator>
      <dc:date>2013-05-26T22:20:03Z</dc:date>
    </item>
    <item>
      <title>Re: Apply zone protection - to which zone?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/apply-zone-protection-to-which-zone/m-p/36114#M26542</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As I understand the zone protection is for incoming traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That is if you want to protect DMZ then you should apply your zone-protection on the Untrust zone (facing Internet) and the Trust zone (facing your LAN - if you wish to protect from inside threats aswell (for example an overtaken client is being used to DDoS/DoS your DMZ devices)).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 May 2013 06:48:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/apply-zone-protection-to-which-zone/m-p/36114#M26542</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2013-05-27T06:48:08Z</dc:date>
    </item>
    <item>
      <title>Re: Apply zone protection - to which zone?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/apply-zone-protection-to-which-zone/m-p/36115#M26543</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Explanation from Understanding DoS Protection&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;These settings apply to the ingress zone (i.e. the zone where traffic enters the firewall). Zone protection settings apply to all interfaces within the zone for which the profile is configured.&lt;/P&gt;&lt;P&gt;Note: Zone protection is only enforced when there is no session match for the packet. If the packet matches an existing&lt;/P&gt;&lt;P&gt;session, it will bypass the zone protection setting.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Refer:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-3094"&gt;Threat Prevention Deployment Tech Note&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A __default_attr="5078" __jive_macro_name="document" class="jive_macro jive_macro_document" href="https://live.paloaltonetworks.com/"&gt;&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 May 2013 05:02:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/apply-zone-protection-to-which-zone/m-p/36115#M26543</guid>
      <dc:creator>UhMayYeah</dc:creator>
      <dc:date>2013-05-28T05:02:57Z</dc:date>
    </item>
    <item>
      <title>Re: Apply zone protection - to which zone?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/apply-zone-protection-to-which-zone/m-p/36116#M26544</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks &lt;A __default_attr="11199" __jive_macro_name="user" class="jive_macro jive_macro_user" data-objecttype="3" href="https://live.paloaltonetworks.com/"&gt;&lt;/A&gt;, that helps. So in other words:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Attaching a zone protection profile to my Untrust zone will *npt* protect my DMZ zone because it's a different zone and has different interfaces. Did I get that right? So an untrust protection would only really protect the firewall itself and separate profiles should be attached to DMZ and other zones.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, good point about protection only being applied to new sessions, not existing ones. It seems it makes more sense to use DOS protection.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 May 2013 07:05:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/apply-zone-protection-to-which-zone/m-p/36116#M26544</guid>
      <dc:creator>cryptochrome</dc:creator>
      <dc:date>2013-05-28T07:05:14Z</dc:date>
    </item>
    <item>
      <title>Re: Apply zone protection - to which zone?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/apply-zone-protection-to-which-zone/m-p/36117#M26545</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ZP is applied on the ingress zone,so if the traffic for destination&amp;nbsp; DMZ zone enters from Untrust zone,apply ZP on the Untrust zone, hence adding ZP to Untrust zone would definitely help DMZ&amp;nbsp; and Trust both as most of the malicious traffic generally originates from the Internet.&lt;/P&gt;&lt;P&gt;As &lt;A __default_attr="3245" __jive_macro_name="user" class="jive_macro jive_macro_user" href="https://live.paloaltonetworks.com/"&gt;&lt;/A&gt; said,you can additionally apply the ZP to the Trust interface to protect DMZ from the bad traffic initiated from Trust zone.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 May 2013 07:25:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/apply-zone-protection-to-which-zone/m-p/36117#M26545</guid>
      <dc:creator>UhMayYeah</dc:creator>
      <dc:date>2013-05-28T07:25:11Z</dc:date>
    </item>
  </channel>
</rss>

