<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Specify policy by machine name/workgroup? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/specify-policy-by-machine-name-workgroup/m-p/48551#M35746</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for the reply..&amp;nbsp; and that seems to work..&amp;nbsp;&amp;nbsp; should I be concerned about the commit warning that the "Non-domainUsers shadows LimitedInternet"?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The policies are ordered as:&lt;/P&gt;&lt;P&gt;OpenInternet&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; sourceuser:&amp;nbsp; domain\openinternetgroup&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; LooseFiltering&lt;/P&gt;&lt;P&gt;Non-domainUsers&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; sourceuser: unknown&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; LooseFiltering&lt;/P&gt;&lt;P&gt;LimitedInternet&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; sourceuser: any&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; StrictFiltering&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And is there any way to include both the domain group and unknown user in the same policy?&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 15 Jan 2014 18:41:16 GMT</pubDate>
    <dc:creator>thatguy</dc:creator>
    <dc:date>2014-01-15T18:41:16Z</dc:date>
    <item>
      <title>Specify policy by machine name/workgroup?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/specify-policy-by-machine-name-workgroup/m-p/48549#M35744</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey there --&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So this is an odd thing that's probably it simple fix..&amp;nbsp; hoping anyway.&amp;nbsp; We have 99% of our PCs on the same subnet and domain, however several of these machines are owned by an outside company and are "borrowing" our internet link.&amp;nbsp; They are in their own workgroup (not on our domain), but share our address space (192.168.1.x/24).&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have an OpenInternet policy that allows users in a specific domain security group full access to the internet;&amp;nbsp; and I have another policy (LimitedInternet) that has strict URL filtering for users not in that group.&amp;nbsp;&amp;nbsp; My question -- is there a way to allow those workgroup computers (either by workgroup or machine name) access to the OpenInternet policy?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;-- michael~&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Jan 2014 21:54:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/specify-policy-by-machine-name-workgroup/m-p/48549#M35744</guid>
      <dc:creator>thatguy</dc:creator>
      <dc:date>2014-01-14T21:54:03Z</dc:date>
    </item>
    <item>
      <title>Re: Specify policy by machine name/workgroup?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/specify-policy-by-machine-name-workgroup/m-p/48550#M35745</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Hello Sir,&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;As you have 99% of the traffic from domain users, So, any non-domain traffic the PA will not be unable to correlate user &amp;lt;-&amp;gt; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;ip&lt;/SPAN&gt;, then it will treated as "unknown" in the user field.&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;You can use the "unknown" user as an object for a Deny/strict policy rule.&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;IMG alt="unknown-user.png" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/10981_unknown-user.png" style="width: 620px; height: 325px;" /&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Jan 2014 22:17:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/specify-policy-by-machine-name-workgroup/m-p/48550#M35745</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-01-14T22:17:50Z</dc:date>
    </item>
    <item>
      <title>Re: Specify policy by machine name/workgroup?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/specify-policy-by-machine-name-workgroup/m-p/48551#M35746</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for the reply..&amp;nbsp; and that seems to work..&amp;nbsp;&amp;nbsp; should I be concerned about the commit warning that the "Non-domainUsers shadows LimitedInternet"?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The policies are ordered as:&lt;/P&gt;&lt;P&gt;OpenInternet&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; sourceuser:&amp;nbsp; domain\openinternetgroup&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; LooseFiltering&lt;/P&gt;&lt;P&gt;Non-domainUsers&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; sourceuser: unknown&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; LooseFiltering&lt;/P&gt;&lt;P&gt;LimitedInternet&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; sourceuser: any&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; StrictFiltering&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And is there any way to include both the domain group and unknown user in the same policy?&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Jan 2014 18:41:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/specify-policy-by-machine-name-workgroup/m-p/48551#M35746</guid>
      <dc:creator>thatguy</dc:creator>
      <dc:date>2014-01-15T18:41:16Z</dc:date>
    </item>
    <item>
      <title>Re: Specify policy by machine name/workgroup?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/specify-policy-by-machine-name-workgroup/m-p/48552#M35747</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;commit warning is not important.(if it is fixed by the support will be better )&lt;/P&gt;&lt;P&gt;to include domain group , there is no way except cloning the rule and select each.(as you did)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Jan 2014 09:43:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/specify-policy-by-machine-name-workgroup/m-p/48552#M35747</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2014-01-16T09:43:59Z</dc:date>
    </item>
    <item>
      <title>Re: Specify policy by machine name/workgroup?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/specify-policy-by-machine-name-workgroup/m-p/48553#M35748</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;"Non-domainUsers shadows LimitedInternet"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;Shadow means that your new rule for Non-domainUsers has match criteria that the rule LimitedInternet will never be used.&amp;nbsp; You have essentially replaced LimitedInternet with Non-domainUsers.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;If this situation is acceptable then you should delete LimitedInternet.&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;If this is not acceptable, then we need to look more closely at the match conditions for the two rules to determine how to separate the desired traffic and block what you wish to block.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 18 Jan 2014 12:20:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/specify-policy-by-machine-name-workgroup/m-p/48553#M35748</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2014-01-18T12:20:17Z</dc:date>
    </item>
    <item>
      <title>Re: Specify policy by machine name/workgroup?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/specify-policy-by-machine-name-workgroup/m-p/48554#M35749</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;when you look for that 3 rule, if a user is in a domain group named abc, then it's session will match to Limitedİnternet.So shadow error is a bug.it does not have the same/much ciriteria.if you change the order of 2nd and 3rd rule.Than yes there will be a shadow situation there.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 18 Jan 2014 13:18:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/specify-policy-by-machine-name-workgroup/m-p/48554#M35749</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2014-01-18T13:18:24Z</dc:date>
    </item>
    <item>
      <title>Re: Specify policy by machine name/workgroup?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/specify-policy-by-machine-name-workgroup/m-p/48555#M35750</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I for some reason didn't realize unknown was an available option. Thanks for the info!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 19 Jan 2014 07:08:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/specify-policy-by-machine-name-workgroup/m-p/48555#M35750</guid>
      <dc:creator>SDorsey</dc:creator>
      <dc:date>2014-01-19T07:08:41Z</dc:date>
    </item>
  </channel>
</rss>

