<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Policies - Security - Rule shadowed by 2nd rule in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/policies-security-rule-shadowed-by-2nd-rule/m-p/38567#M28261</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Much like an access list on a cisco router top to bottom. I recently created 2 rules for our 3rd party ISP to connect internet sticks via our firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1st rule - Allow all traffic via TELUS internet sticks from Trust Vpn, Source (telus), Destination (Any), Actions (Allow), No profile type.&lt;/P&gt;&lt;P&gt;2nd rule - Deny all traffic via TELUS internet sticks from Trust Vpn, Source (telus), Destination (Any), Actions (Deny)&amp;nbsp; Profiles Type "Profile", URL Filtering (VPN use only) which has allowed sites and blocked sites that I created.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, when I commit the rules, I get an message "Security Policy: Rule Telus Internet Allowed urls" shadows rule "Telus Internet disallowed urls".&lt;/P&gt;&lt;P&gt;I'm not certain which to change. Any ideas?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 13 Nov 2012 15:49:39 GMT</pubDate>
    <dc:creator>robert_smith</dc:creator>
    <dc:date>2012-11-13T15:49:39Z</dc:date>
    <item>
      <title>Policies - Security - Rule shadowed by 2nd rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/policies-security-rule-shadowed-by-2nd-rule/m-p/38567#M28261</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Much like an access list on a cisco router top to bottom. I recently created 2 rules for our 3rd party ISP to connect internet sticks via our firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1st rule - Allow all traffic via TELUS internet sticks from Trust Vpn, Source (telus), Destination (Any), Actions (Allow), No profile type.&lt;/P&gt;&lt;P&gt;2nd rule - Deny all traffic via TELUS internet sticks from Trust Vpn, Source (telus), Destination (Any), Actions (Deny)&amp;nbsp; Profiles Type "Profile", URL Filtering (VPN use only) which has allowed sites and blocked sites that I created.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, when I commit the rules, I get an message "Security Policy: Rule Telus Internet Allowed urls" shadows rule "Telus Internet disallowed urls".&lt;/P&gt;&lt;P&gt;I'm not certain which to change. Any ideas?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Nov 2012 15:49:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/policies-security-rule-shadowed-by-2nd-rule/m-p/38567#M28261</guid>
      <dc:creator>robert_smith</dc:creator>
      <dc:date>2012-11-13T15:49:39Z</dc:date>
    </item>
    <item>
      <title>Re: Policies - Security - Rule shadowed by 2nd rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/policies-security-rule-shadowed-by-2nd-rule/m-p/38568#M28262</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What about this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1)&lt;/P&gt;&lt;P&gt;srczone: Trust VPN&lt;/P&gt;&lt;P&gt;srcip: telus&lt;/P&gt;&lt;P&gt;dstzone: any&lt;/P&gt;&lt;P&gt;dstip: any&lt;/P&gt;&lt;P&gt;profile: URL Filtering (VPN use only)&lt;/P&gt;&lt;P&gt;options: log on session end&lt;/P&gt;&lt;P&gt;action: allow&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2)&lt;/P&gt;&lt;P&gt;srczone: any&lt;/P&gt;&lt;P&gt;srcip: any&lt;/P&gt;&lt;P&gt;dstzone: any&lt;/P&gt;&lt;P&gt;dstip: any&lt;/P&gt;&lt;P&gt;profile: none&lt;/P&gt;&lt;P&gt;options: log on session end&lt;/P&gt;&lt;P&gt;action: deny&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The thing is that your "allow" (which you see in the security policy) is based on ip header while url filtering profile takes care of what you will allow/block based on url.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, if I recall correctly, another method is to only have allowed urls in your URL filter profile and let the default deny in the bottom take care of the blocking.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Like so:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1)&lt;/P&gt;&lt;P&gt;srczone: Trust VPN&lt;/P&gt;&lt;P&gt;srcip: telus&lt;/P&gt;&lt;P&gt;dstzone: any&lt;/P&gt;&lt;P&gt;dstip: any&lt;/P&gt;&lt;P&gt;profile: URL Filtering (Allowed for VPN)&lt;/P&gt;&lt;P&gt;options: log on session end&lt;/P&gt;&lt;P&gt;action: allow&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2)&lt;/P&gt;&lt;P&gt;srczone: any&lt;/P&gt;&lt;P&gt;srcip: any&lt;/P&gt;&lt;P&gt;dstzone: any&lt;/P&gt;&lt;P&gt;dstip: any&lt;/P&gt;&lt;P&gt;profile: none&lt;/P&gt;&lt;P&gt;options: log on session end&lt;/P&gt;&lt;P&gt;action: deny&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Nov 2012 09:02:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/policies-security-rule-shadowed-by-2nd-rule/m-p/38568#M28262</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-11-14T09:02:17Z</dc:date>
    </item>
  </channel>
</rss>

