<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: New to Palo Alto - Append Policy Question in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/new-to-palo-alto-append-policy-question/m-p/43425#M31856</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Sir,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You are correct, if you apply CLI command&amp;nbsp; # &lt;SPAN style="color: #0000ff; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 12px; background-color: #f6f6f6;"&gt;set &lt;/SPAN&gt;&lt;SPAN class="GINGER_SOFTWARE_mark" style="font-weight: inherit; font-style: inherit; font-size: 12px; font-family: inherit; color: #0000ff;"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark" style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;rulebase&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="color: #0000ff; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 12px; background-color: #f6f6f6;"&gt; security rules "to NG Sites" destination location3 &amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; This w&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;ill add the &lt;STRONG&gt;location3&lt;/STRONG&gt; to the destination and leave the current destinations there as well. Please find below example from my test PA firewall:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;admin@DADA# show &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;rulebase&lt;/SPAN&gt; security rules LAN-ISP&lt;/P&gt;&lt;P&gt;LAN-ISP {&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;option&lt;/SPAN&gt; {&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;disable&lt;/SPAN&gt;-server-response-inspection no;&lt;/P&gt;&lt;P&gt;&amp;nbsp; }&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;from&lt;/SPAN&gt; Trust-LAN;&amp;nbsp;&amp;nbsp; &amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;to&lt;/SPAN&gt; Untrust-ISP;&amp;nbsp; &amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;source&lt;/SPAN&gt; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;[ &lt;/SPAN&gt;any &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;1.1.1.1&lt;/SPAN&gt;/32];&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;destination&lt;/SPAN&gt; any;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;source&lt;/SPAN&gt;-user any;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;category&lt;/SPAN&gt; any;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;application&lt;/SPAN&gt; any;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;service&lt;/SPAN&gt; any;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;hip&lt;/SPAN&gt;-profiles any;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;action&lt;/SPAN&gt; allow;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;log&lt;/SPAN&gt;-start &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;no&lt;/SPAN&gt;;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;log&lt;/SPAN&gt;-&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;end&lt;/SPAN&gt; yes;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;negate&lt;/SPAN&gt;-source no;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;negate&lt;/SPAN&gt;-destination no;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;log&lt;/SPAN&gt;-setting SYSLOG-ALL;&lt;/P&gt;&lt;P&gt;}&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;admin@DADA# set &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;rulebase&lt;/SPAN&gt; security rules LAN-ISP from trust to &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;untrust&lt;/SPAN&gt;&amp;nbsp; &amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Adding new source and destination zone&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;edit&lt;/SPAN&gt;]&lt;/P&gt;&lt;P&gt;admin@DADA# show &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;rulebase&lt;/SPAN&gt; security rules LAN-ISP&lt;/P&gt;&lt;P&gt;LAN-ISP {&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;option&lt;/SPAN&gt; {&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;disable&lt;/SPAN&gt;-server-response-inspection no;&lt;/P&gt;&lt;P&gt;&amp;nbsp; }&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;from&lt;/SPAN&gt; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;[ &lt;/SPAN&gt;Trust-LAN trust];&amp;nbsp; &amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Added with the existing zone&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;to&lt;/SPAN&gt; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;[ &lt;/SPAN&gt;Untrust-ISP &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;untrust&lt;/SPAN&gt;]; &amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;source&lt;/SPAN&gt; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;[ &lt;/SPAN&gt;any &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;1.1.1.1&lt;/SPAN&gt;/32];&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;destination&lt;/SPAN&gt; any;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;source&lt;/SPAN&gt;-user any;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;category&lt;/SPAN&gt; any;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;application&lt;/SPAN&gt; any;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;service&lt;/SPAN&gt; any;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;hip&lt;/SPAN&gt;-profiles any;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;action&lt;/SPAN&gt; allow;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;log&lt;/SPAN&gt;-start &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;no&lt;/SPAN&gt;;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;log&lt;/SPAN&gt;-&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;end&lt;/SPAN&gt; yes;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;negate&lt;/SPAN&gt;-source no;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;negate&lt;/SPAN&gt;-destination no;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;log&lt;/SPAN&gt;-setting SYSLOG-ALL;&lt;/P&gt;&lt;P&gt;}&lt;/P&gt;&lt;P&gt;[&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;edit&lt;/SPAN&gt;]&lt;/P&gt;&lt;P&gt;admin@DADA#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 27 Feb 2014 18:55:59 GMT</pubDate>
    <dc:creator>HULK</dc:creator>
    <dc:date>2014-02-27T18:55:59Z</dc:date>
    <item>
      <title>New to Palo Alto - Append Policy Question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/new-to-palo-alto-append-policy-question/m-p/43422#M31853</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Good day all,&lt;/P&gt;&lt;P&gt; I am new to Palo Alto so this question might actually seem rather trivial.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Most of my peers configure from the GUI and are not very familiar with the Command line.&amp;nbsp; I am more comfortable with the command line so I am trying to do configurations that way.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I want to add a source entity to an existing rulebase security rule do I just recreate the rule with the appended information and then when I commit, it will overwrite the existing rule?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;when I do a &lt;STRONG&gt;show rulebase security rules existing_policy&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;I get the following output:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;&lt;EM&gt;"existing_policy" {&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;&lt;EM&gt;&amp;nbsp; from dmz;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;&lt;EM&gt;&amp;nbsp; to trust;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;&lt;EM&gt;&amp;nbsp; source [ serverA serverB serverC ];&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;&lt;EM&gt;&amp;nbsp; destination any;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;&lt;EM&gt;&amp;nbsp; source-user any;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;&lt;EM&gt;&amp;nbsp; application any;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;&lt;EM&gt;&amp;nbsp; service any;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;&lt;EM&gt;&amp;nbsp; hip-profiles any;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;&lt;EM&gt;&amp;nbsp; log-start no;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;&lt;EM&gt;&amp;nbsp; log-end yes;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;&lt;EM&gt;&amp;nbsp; negate-source no;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;&lt;EM&gt;&amp;nbsp; negate-destination no;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;&lt;EM&gt;&amp;nbsp; action allow;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff9900;"&gt;&lt;EM style="color: #0000ff;"&gt;}&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I wanted to add ServerD to the source would I do the following (I don't have a test box to test the commands that is why I am coming here):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;set rulebase security rules existing_policy from dmz to trust source [ serverA serverB serverC &lt;STRONG style="color: #ff0000;"&gt;ServerD&lt;/STRONG&gt; ] destination any action allow&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any assistance would be appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Wally&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Feb 2014 16:30:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/new-to-palo-alto-append-policy-question/m-p/43422#M31853</guid>
      <dc:creator>wsteadman</dc:creator>
      <dc:date>2014-02-27T16:30:45Z</dc:date>
    </item>
    <item>
      <title>Re: New to Palo Alto - Append Policy Question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/new-to-palo-alto-append-policy-question/m-p/43423#M31854</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Sir,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;if&lt;/SPAN&gt; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;youapply&lt;/SPAN&gt; # &lt;SPAN style="color: #0000ff; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;set &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;rulebase&lt;/SPAN&gt;&lt;/SPAN&gt; security rules existing_policy from &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;dmz&lt;/SPAN&gt;&lt;/SPAN&gt; to trust source server-D&lt;/SPAN&gt;&lt;SPAN style="color: #0000ff; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt; destination any action &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;allow &amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; it&lt;/SPAN&gt; will only add &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;with&lt;/SPAN&gt; the existing &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;rule&lt;/SPAN&gt;&lt;SPAN style="color: #0000ff; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;[ &lt;/SPAN&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;serverA&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;serverB&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;serverC&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #ff0000;"&gt;&lt;STRONG&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;ServerD&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN style="color: #0000ff; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt; ]&lt;/SPAN&gt;&lt;/SPAN&gt;,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example:&lt;/P&gt;&lt;P&gt;admin@DADA# show &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;rulebase&lt;/SPAN&gt;&lt;/SPAN&gt; security rules LAN-ISP&lt;/P&gt;&lt;P&gt;LAN-ISP {&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;option&lt;/SPAN&gt;&lt;/SPAN&gt; {&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;disable&lt;/SPAN&gt;&lt;/SPAN&gt;-server-response-inspection no;&lt;/P&gt;&lt;P&gt;&amp;nbsp; }&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;from&lt;/SPAN&gt;&lt;/SPAN&gt; Trust-LAN;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;to&lt;/SPAN&gt;&lt;/SPAN&gt; Untrust-ISP;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;source&lt;/SPAN&gt;&lt;/SPAN&gt; any;&amp;nbsp; &amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; before the change&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;destination&lt;/SPAN&gt;&lt;/SPAN&gt; any;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;source&lt;/SPAN&gt;&lt;/SPAN&gt;-user any;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;category&lt;/SPAN&gt;&lt;/SPAN&gt; any;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;application&lt;/SPAN&gt;&lt;/SPAN&gt; any;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;service&lt;/SPAN&gt;&lt;/SPAN&gt; any;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;hip&lt;/SPAN&gt;&lt;/SPAN&gt;-profiles any;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;action&lt;/SPAN&gt;&lt;/SPAN&gt; allow;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;log&lt;/SPAN&gt;&lt;/SPAN&gt;-start &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;no&lt;/SPAN&gt;&lt;/SPAN&gt;;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;log&lt;/SPAN&gt;&lt;/SPAN&gt;-&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;end&lt;/SPAN&gt;&lt;/SPAN&gt; yes;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;negate&lt;/SPAN&gt;&lt;/SPAN&gt;-source no;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;negate&lt;/SPAN&gt;&lt;/SPAN&gt;-destination no;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;log&lt;/SPAN&gt;&lt;/SPAN&gt;-setting SYSLOG-ALL;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;# set &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;rulebase&lt;/SPAN&gt;&lt;/SPAN&gt; security rules LAN-ISP from Trust-LAN to Untrust-ISP source &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;1.1.1.1&lt;/SPAN&gt;&lt;/SPAN&gt;/32 destination any action &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;allow&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;admin@DADA# show &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;rulebase&lt;/SPAN&gt;&lt;/SPAN&gt; security rules LAN-ISP&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; LAN-ISP {&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;option&lt;/SPAN&gt;&lt;/SPAN&gt; {&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;disable&lt;/SPAN&gt;&lt;/SPAN&gt;-server-response-inspection no;&lt;/P&gt;&lt;P&gt;&amp;nbsp; }&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;from&lt;/SPAN&gt;&lt;/SPAN&gt; Trust-LAN;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;to&lt;/SPAN&gt;&lt;/SPAN&gt; Untrust-ISP;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;source&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;[ &lt;/SPAN&gt;&lt;/SPAN&gt;any &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;1.1.1.1&lt;/SPAN&gt;&lt;/SPAN&gt;/32]; &amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; added here&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;destination&lt;/SPAN&gt;&lt;/SPAN&gt; any;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;source&lt;/SPAN&gt;&lt;/SPAN&gt;-user any;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;category&lt;/SPAN&gt;&lt;/SPAN&gt; any;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;application&lt;/SPAN&gt;&lt;/SPAN&gt; any;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;service&lt;/SPAN&gt;&lt;/SPAN&gt; any;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;hip&lt;/SPAN&gt;&lt;/SPAN&gt;-profiles any;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;action&lt;/SPAN&gt;&lt;/SPAN&gt; allow;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;log&lt;/SPAN&gt;&lt;/SPAN&gt;-start &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;no&lt;/SPAN&gt;&lt;/SPAN&gt;;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;log&lt;/SPAN&gt;&lt;/SPAN&gt;-&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;end&lt;/SPAN&gt;&lt;/SPAN&gt; yes;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;negate&lt;/SPAN&gt;&lt;/SPAN&gt;-source no;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;negate&lt;/SPAN&gt;&lt;/SPAN&gt;-destination no;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;log&lt;/SPAN&gt;&lt;/SPAN&gt;-setting SYSLOG-ALL;&lt;/P&gt;&lt;P&gt;}&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Feb 2014 17:48:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/new-to-palo-alto-append-policy-question/m-p/43423#M31854</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-02-27T17:48:52Z</dc:date>
    </item>
    <item>
      <title>Re: New to Palo Alto - Append Policy Question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/new-to-palo-alto-append-policy-question/m-p/43424#M31855</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks so much for your reply.&amp;nbsp; So what I should have put in my initial post was that I am actually just adding a destination.&amp;nbsp; So from the code below the destination is to two objects, but I want to add a third, so can I simply say&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; background-color: #f6f6f6; color: #0000ff;"&gt;set &lt;SPAN class="GINGER_SOFTWARE_mark" style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark" style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;rulebase&lt;/SPAN&gt;&lt;/SPAN&gt; security rules "to NG Sites" destination location3&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Will that add the location3 to the destination and leave the current destinations there as well?&amp;nbsp; I don't want to remove any of the current destinations or configurations so want to make sure my syntax is correct.&amp;nbsp; Sorry for my earlier post, I thought I was just showing a general example but should have been more specific.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"to NG Sites" {&lt;/P&gt;&lt;P&gt;&amp;nbsp; option {&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; disable-server-response-inspection no;&lt;/P&gt;&lt;P&gt;&amp;nbsp; }&lt;/P&gt;&lt;P&gt;&amp;nbsp; from [ DMZ1 DMZ2];&lt;/P&gt;&lt;P&gt;&amp;nbsp; to [ Internal];&lt;/P&gt;&lt;P&gt;&amp;nbsp; source any;&lt;/P&gt;&lt;P&gt;&amp;nbsp; destination [ location1 location2];&lt;/P&gt;&lt;P&gt;&amp;nbsp; source-user any;&lt;/P&gt;&lt;P&gt;&amp;nbsp; application [ dns http-audio soap ssl web-browsing];&lt;/P&gt;&lt;P&gt;&amp;nbsp; service application-default;&lt;/P&gt;&lt;P&gt;&amp;nbsp; hip-profiles any;&lt;/P&gt;&lt;P&gt;&amp;nbsp; log-start no;&lt;/P&gt;&lt;P&gt;&amp;nbsp; log-end yes;&lt;/P&gt;&lt;P&gt;&amp;nbsp; negate-source no;&lt;/P&gt;&lt;P&gt;&amp;nbsp; negate-destination no;&lt;/P&gt;&lt;P&gt;&amp;nbsp; action allow;&lt;/P&gt;&lt;P&gt;}&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Feb 2014 18:00:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/new-to-palo-alto-append-policy-question/m-p/43424#M31855</guid>
      <dc:creator>wsteadman</dc:creator>
      <dc:date>2014-02-27T18:00:58Z</dc:date>
    </item>
    <item>
      <title>Re: New to Palo Alto - Append Policy Question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/new-to-palo-alto-append-policy-question/m-p/43425#M31856</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Sir,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You are correct, if you apply CLI command&amp;nbsp; # &lt;SPAN style="color: #0000ff; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 12px; background-color: #f6f6f6;"&gt;set &lt;/SPAN&gt;&lt;SPAN class="GINGER_SOFTWARE_mark" style="font-weight: inherit; font-style: inherit; font-size: 12px; font-family: inherit; color: #0000ff;"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark" style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;rulebase&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="color: #0000ff; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 12px; background-color: #f6f6f6;"&gt; security rules "to NG Sites" destination location3 &amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; This w&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;ill add the &lt;STRONG&gt;location3&lt;/STRONG&gt; to the destination and leave the current destinations there as well. Please find below example from my test PA firewall:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;admin@DADA# show &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;rulebase&lt;/SPAN&gt; security rules LAN-ISP&lt;/P&gt;&lt;P&gt;LAN-ISP {&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;option&lt;/SPAN&gt; {&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;disable&lt;/SPAN&gt;-server-response-inspection no;&lt;/P&gt;&lt;P&gt;&amp;nbsp; }&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;from&lt;/SPAN&gt; Trust-LAN;&amp;nbsp;&amp;nbsp; &amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;to&lt;/SPAN&gt; Untrust-ISP;&amp;nbsp; &amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;source&lt;/SPAN&gt; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;[ &lt;/SPAN&gt;any &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;1.1.1.1&lt;/SPAN&gt;/32];&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;destination&lt;/SPAN&gt; any;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;source&lt;/SPAN&gt;-user any;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;category&lt;/SPAN&gt; any;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;application&lt;/SPAN&gt; any;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;service&lt;/SPAN&gt; any;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;hip&lt;/SPAN&gt;-profiles any;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;action&lt;/SPAN&gt; allow;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;log&lt;/SPAN&gt;-start &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;no&lt;/SPAN&gt;;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;log&lt;/SPAN&gt;-&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;end&lt;/SPAN&gt; yes;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;negate&lt;/SPAN&gt;-source no;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;negate&lt;/SPAN&gt;-destination no;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;log&lt;/SPAN&gt;-setting SYSLOG-ALL;&lt;/P&gt;&lt;P&gt;}&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;admin@DADA# set &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;rulebase&lt;/SPAN&gt; security rules LAN-ISP from trust to &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;untrust&lt;/SPAN&gt;&amp;nbsp; &amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Adding new source and destination zone&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;edit&lt;/SPAN&gt;]&lt;/P&gt;&lt;P&gt;admin@DADA# show &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;rulebase&lt;/SPAN&gt; security rules LAN-ISP&lt;/P&gt;&lt;P&gt;LAN-ISP {&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;option&lt;/SPAN&gt; {&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;disable&lt;/SPAN&gt;-server-response-inspection no;&lt;/P&gt;&lt;P&gt;&amp;nbsp; }&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;from&lt;/SPAN&gt; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;[ &lt;/SPAN&gt;Trust-LAN trust];&amp;nbsp; &amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Added with the existing zone&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;to&lt;/SPAN&gt; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;[ &lt;/SPAN&gt;Untrust-ISP &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;untrust&lt;/SPAN&gt;]; &amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;source&lt;/SPAN&gt; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;[ &lt;/SPAN&gt;any &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;1.1.1.1&lt;/SPAN&gt;/32];&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;destination&lt;/SPAN&gt; any;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;source&lt;/SPAN&gt;-user any;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;category&lt;/SPAN&gt; any;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;application&lt;/SPAN&gt; any;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;service&lt;/SPAN&gt; any;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;hip&lt;/SPAN&gt;-profiles any;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;action&lt;/SPAN&gt; allow;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;log&lt;/SPAN&gt;-start &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;no&lt;/SPAN&gt;;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;log&lt;/SPAN&gt;-&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;end&lt;/SPAN&gt; yes;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;negate&lt;/SPAN&gt;-source no;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;negate&lt;/SPAN&gt;-destination no;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;log&lt;/SPAN&gt;-setting SYSLOG-ALL;&lt;/P&gt;&lt;P&gt;}&lt;/P&gt;&lt;P&gt;[&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;edit&lt;/SPAN&gt;]&lt;/P&gt;&lt;P&gt;admin@DADA#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Feb 2014 18:55:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/new-to-palo-alto-append-policy-question/m-p/43425#M31856</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-02-27T18:55:59Z</dc:date>
    </item>
  </channel>
</rss>

