<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CLI find security rule, known IP address in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/cli-find-security-rule-known-ip-address/m-p/43185#M31676</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;domain group ?&lt;/P&gt;&lt;P&gt;there is no option for group with that command&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 18 Oct 2013 08:24:53 GMT</pubDate>
    <dc:creator>Retired Member</dc:creator>
    <dc:date>2013-10-18T08:24:53Z</dc:date>
    <item>
      <title>CLI find security rule, known IP address</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cli-find-security-rule-known-ip-address/m-p/43180#M31671</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have one question to engineers Paloalto, why from CLI can't find security rules which include example IP address. What is to difficult create that function? &lt;/P&gt;&lt;P&gt;Why such an advanced device does not have such a simple search. Another thing lack this function in CLI is big problem because i must used GUI.&lt;/P&gt;&lt;P&gt;What for is CLI?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Oct 2013 18:14:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cli-find-security-rule-known-ip-address/m-p/43180#M31671</guid>
      <dc:creator>Wbm</dc:creator>
      <dc:date>2013-10-16T18:14:41Z</dc:date>
    </item>
    <item>
      <title>Re: CLI find security rule, known IP address</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cli-find-security-rule-known-ip-address/m-p/43181#M31672</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;you can use &lt;/P&gt;&lt;P&gt; test security-policy-match&lt;/P&gt;&lt;P&gt;to find the security rule if you know source ip.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Oct 2013 18:50:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cli-find-security-rule-known-ip-address/m-p/43181#M31672</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-10-16T18:50:04Z</dc:date>
    </item>
    <item>
      <title>Re: CLI find security rule, known IP address</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cli-find-security-rule-known-ip-address/m-p/43182#M31673</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;it doesn't work if your security rule contain field "user"&lt;BR /&gt;example:&lt;BR /&gt;user cn=net_server ,ou=paloalto,dc=paloalto.org&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Oct 2013 07:44:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cli-find-security-rule-known-ip-address/m-p/43182#M31673</guid>
      <dc:creator>Wbm</dc:creator>
      <dc:date>2013-10-18T07:44:03Z</dc:date>
    </item>
    <item>
      <title>Re: CLI find security rule, known IP address</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cli-find-security-rule-known-ip-address/m-p/43183#M31674</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;it is working in my lab&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; test security-policy-match source-user dc\student1 source 192.168.10.17 destination 0.0.0.0&amp;nbsp; protocol 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;testrule {&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; from any;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; source 192.168.10.17;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; source-region none;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; to any;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; destination any;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; destination-region none;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; user dc\student1;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; category any;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; application/service [ youtube-base/any/any/any youtube-safety-m/any/any/&lt;/P&gt;&lt;P&gt;any youtube-uploadin/any/any/any youtube-posting/any/any/any ];&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; action deny;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; terminal no;&lt;/P&gt;&lt;P&gt;}&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Oct 2013 08:04:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cli-find-security-rule-known-ip-address/m-p/43183#M31674</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-10-18T08:04:58Z</dc:date>
    </item>
    <item>
      <title>Re: CLI find security rule, known IP address</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cli-find-security-rule-known-ip-address/m-p/43184#M31675</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes i know it's working if use dc\nameuser.&lt;/P&gt;&lt;P&gt;Please use domain group Active Directory&lt;/P&gt;&lt;P&gt;example:&lt;/P&gt;&lt;P&gt;user cn=net_server ,ou=paloalto,dc=paloalto.org&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Oct 2013 08:20:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cli-find-security-rule-known-ip-address/m-p/43184#M31675</guid>
      <dc:creator>Wbm</dc:creator>
      <dc:date>2013-10-18T08:20:01Z</dc:date>
    </item>
    <item>
      <title>Re: CLI find security rule, known IP address</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cli-find-security-rule-known-ip-address/m-p/43185#M31676</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;domain group ?&lt;/P&gt;&lt;P&gt;there is no option for group with that command&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Oct 2013 08:24:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cli-find-security-rule-known-ip-address/m-p/43185#M31676</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-10-18T08:24:53Z</dc:date>
    </item>
    <item>
      <title>Re: CLI find security rule, known IP address</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cli-find-security-rule-known-ip-address/m-p/43186#M31677</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;let me try with group&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Oct 2013 08:27:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cli-find-security-rule-known-ip-address/m-p/43186#M31677</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-10-18T08:27:15Z</dc:date>
    </item>
    <item>
      <title>Re: CLI find security rule, known IP address</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cli-find-security-rule-known-ip-address/m-p/43187#M31678</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;seems group is not supported.&lt;/P&gt;&lt;P&gt;but maybe there is a way with writing in another format but I don't know that.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Oct 2013 08:40:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cli-find-security-rule-known-ip-address/m-p/43187#M31678</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-10-18T08:40:32Z</dc:date>
    </item>
    <item>
      <title>Re: CLI find security rule, known IP address</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cli-find-security-rule-known-ip-address/m-p/43188#M31679</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have about 400 rules which use domain group. domaing group match to security rules.&lt;/P&gt;&lt;P&gt;Example&lt;/P&gt;&lt;P&gt;RED {&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; from zone-lan;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; source any;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; source-region none;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; to zone-dmz ;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; destination 192.168.83.105;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; destination-region none;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; user cn=red,ou=paloalto,dc=paloalto.org;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; category any;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; application/service&amp;nbsp; any/tcp/any/3000;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; action allow;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; terminal yes;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It work's.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Oct 2013 09:08:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cli-find-security-rule-known-ip-address/m-p/43188#M31679</guid>
      <dc:creator>Wbm</dc:creator>
      <dc:date>2013-10-18T09:08:42Z</dc:date>
    </item>
    <item>
      <title>Re: CLI find security rule, known IP address</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cli-find-security-rule-known-ip-address/m-p/43189#M31680</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have different way to get the rule, this not answer your question directly - but maybe will be helpfull.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;from CLI:&lt;/P&gt;&lt;P&gt;show session all filter source 192.168.1.35&lt;/P&gt;&lt;P&gt;or if you know aplication:&lt;/P&gt;&lt;P&gt; show session all filter application ssh source 192.168.1.35&lt;/P&gt;&lt;P&gt;and next:&lt;/P&gt;&lt;P&gt;show session id XXXXX&lt;/P&gt;&lt;P&gt;you will see in "rule" parametr name of security policy what are you looking for.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Slawek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Oct 2013 09:14:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cli-find-security-rule-known-ip-address/m-p/43189#M31680</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2013-10-18T09:14:34Z</dc:date>
    </item>
    <item>
      <title>Re: CLI find security rule, known IP address</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cli-find-security-rule-known-ip-address/m-p/43190#M31681</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;it gave error with 2 different typing option&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Server error : Error: Unknown source-user: 'dc\112'&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Server error : Error: Unknown source-user: 'cn=112,cn=users,DN=dc,DC=palo,DC=edu'&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is a rule written for group 112.but it did not work.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Oct 2013 09:16:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cli-find-security-rule-known-ip-address/m-p/43190#M31681</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-10-18T09:16:40Z</dc:date>
    </item>
    <item>
      <title>Re: CLI find security rule, known IP address</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cli-find-security-rule-known-ip-address/m-p/43191#M31682</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;But you know it is workaround because rule exist in configuration but it is not now used. I see nothing.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Oct 2013 12:09:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cli-find-security-rule-known-ip-address/m-p/43191#M31682</guid>
      <dc:creator>Wbm</dc:creator>
      <dc:date>2013-10-18T12:09:17Z</dc:date>
    </item>
  </channel>
</rss>

