<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cleaning obsolete firewall rules in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/cleaning-obsolete-firewall-rules/m-p/4011#M2963</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,You should wait for some time after migration to allow firewall analyze ununsed rules.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;The show unused rules are tied to the Monitor Logs&lt;/STRONG&gt;&lt;/SPAN&gt;, so if you are not having good history of logs, then all the rules will be marked as unused rules.&lt;/P&gt;&lt;P&gt;I believe that is why you see inconsistent results.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FYI only&lt;/P&gt;&lt;P&gt;Below is command to pull a list&lt;/P&gt;&lt;P&gt;&amp;gt;show running rule-use rule-base security type un&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;used vsys vsys1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Please mark it as correct answer or helpful if appropriate.&lt;/EM&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 07 Oct 2013 22:33:39 GMT</pubDate>
    <dc:creator>ukhapre</dc:creator>
    <dc:date>2013-10-07T22:33:39Z</dc:date>
    <item>
      <title>Cleaning obsolete firewall rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cleaning-obsolete-firewall-rules/m-p/4010#M2962</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have recently migrated from Juniper to Palo Alto firewall and there are numerous firewall rules that are obsolete and potentially a security risk to me. I tried to use "highlight unused rules" button but it does not seem consistent to me. Are the highlighted rules unused since the firewalls start running or simply not currently used at the moment now? (There is a big difference between the two).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Oct 2013 21:34:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cleaning-obsolete-firewall-rules/m-p/4010#M2962</guid>
      <dc:creator>peterpan13888</dc:creator>
      <dc:date>2013-10-07T21:34:04Z</dc:date>
    </item>
    <item>
      <title>Re: Cleaning obsolete firewall rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cleaning-obsolete-firewall-rules/m-p/4011#M2963</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,You should wait for some time after migration to allow firewall analyze ununsed rules.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;The show unused rules are tied to the Monitor Logs&lt;/STRONG&gt;&lt;/SPAN&gt;, so if you are not having good history of logs, then all the rules will be marked as unused rules.&lt;/P&gt;&lt;P&gt;I believe that is why you see inconsistent results.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FYI only&lt;/P&gt;&lt;P&gt;Below is command to pull a list&lt;/P&gt;&lt;P&gt;&amp;gt;show running rule-use rule-base security type un&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;used vsys vsys1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Please mark it as correct answer or helpful if appropriate.&lt;/EM&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Oct 2013 22:33:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cleaning-obsolete-firewall-rules/m-p/4011#M2963</guid>
      <dc:creator>ukhapre</dc:creator>
      <dc:date>2013-10-07T22:33:39Z</dc:date>
    </item>
    <item>
      <title>Re: Cleaning obsolete firewall rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cleaning-obsolete-firewall-rules/m-p/4012#M2964</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt; "highlight unused rules" shows the rules that are not used by the device since the start of the dataplane. &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Oct 2013 21:35:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cleaning-obsolete-firewall-rules/m-p/4012#M2964</guid>
      <dc:creator>zarina</dc:creator>
      <dc:date>2013-10-08T21:35:33Z</dc:date>
    </item>
    <item>
      <title>Re: Cleaning obsolete firewall rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cleaning-obsolete-firewall-rules/m-p/4013#M2965</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks the replies. It is crystal clear to me know.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Oct 2013 14:21:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cleaning-obsolete-firewall-rules/m-p/4013#M2965</guid>
      <dc:creator>peterpan13888</dc:creator>
      <dc:date>2013-10-10T14:21:44Z</dc:date>
    </item>
  </channel>
</rss>

