<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: intra-zone default in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/intra-zone-default/m-p/41588#M30582</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can add an explicit "deny any any" rule at the bottom of your security policy which will override the implicit permit intra-zone policy.&amp;nbsp; That doesn't disable that default policy, but no traffic will ever hit that implicit rule because the explicit deny any rule will get hit first.&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 03 Jan 2013 16:38:30 GMT</pubDate>
    <dc:creator>jvalentine</dc:creator>
    <dc:date>2013-01-03T16:38:30Z</dc:date>
    <item>
      <title>intra-zone default</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/intra-zone-default/m-p/41586#M30580</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do we have an option to disable default intrazone-allow policy which is hidden.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Jan 2013 15:21:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/intra-zone-default/m-p/41586#M30580</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-01-03T15:21:16Z</dc:date>
    </item>
    <item>
      <title>Re: intra-zone default</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/intra-zone-default/m-p/41587#M30581</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Not any as far as i know !!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Jan 2013 16:31:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/intra-zone-default/m-p/41587#M30581</guid>
      <dc:creator>sdurga</dc:creator>
      <dc:date>2013-01-03T16:31:08Z</dc:date>
    </item>
    <item>
      <title>Re: intra-zone default</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/intra-zone-default/m-p/41588#M30582</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can add an explicit "deny any any" rule at the bottom of your security policy which will override the implicit permit intra-zone policy.&amp;nbsp; That doesn't disable that default policy, but no traffic will ever hit that implicit rule because the explicit deny any rule will get hit first.&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Jan 2013 16:38:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/intra-zone-default/m-p/41588#M30582</guid>
      <dc:creator>jvalentine</dc:creator>
      <dc:date>2013-01-03T16:38:30Z</dc:date>
    </item>
    <item>
      <title>Re: intra-zone default</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/intra-zone-default/m-p/41589#M30583</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Bulent, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By default same zone traffic is allowed and different zone traffic is denied.&lt;/P&gt;&lt;P&gt;If you want to block the same zone traffic you and create a security rule and define it and that will block the traffic between the same zone.&lt;/P&gt;&lt;P&gt;Example&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Capture.JPG" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/5018_Capture.JPG" width="450" /&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;Numan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Jan 2013 16:48:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/intra-zone-default/m-p/41589#M30583</guid>
      <dc:creator>mbutt</dc:creator>
      <dc:date>2013-01-03T16:48:59Z</dc:date>
    </item>
    <item>
      <title>Re: intra-zone default</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/intra-zone-default/m-p/41590#M30584</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for all.I know how to block with a rule but I wonder if there is any cli command for changing default behaviour.For different vendors there is a choice to do this.I see that there is no choice for us.Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Jan 2013 16:56:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/intra-zone-default/m-p/41590#M30584</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-01-03T16:56:05Z</dc:date>
    </item>
    <item>
      <title>Re: intra-zone default</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/intra-zone-default/m-p/41591#M30585</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is no option available to disable the default behaviour but only way is to setup a 'any' 'any' block rule at the bottom to block same zone traffic.&lt;/P&gt;&lt;P&gt;The different zone traffic is not allowed by default. The zones are meant for same area traffic which needs to be allowed.&lt;/P&gt;&lt;P&gt;You may contact SE and request for a 'feature request' to have a configurable option instead of setting up a 'deny all' policy towards bottom.&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Please mark the answer as 'Correct answer or helpful' if appropriate.&lt;/EM&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Jan 2013 02:32:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/intra-zone-default/m-p/41591#M30585</guid>
      <dc:creator>ukhapre</dc:creator>
      <dc:date>2013-01-10T02:32:05Z</dc:date>
    </item>
  </channel>
</rss>

