<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Firewall rule optimization in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-rule-optimization/m-p/69029#M40130</link>
    <description>&lt;P&gt;Company called Firemon has a product that assists with this.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.firemon.com/" target="_blank"&gt;https://www.firemon.com/&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 04 Dec 2015 14:48:27 GMT</pubDate>
    <dc:creator>googol</dc:creator>
    <dc:date>2015-12-04T14:48:27Z</dc:date>
    <item>
      <title>Firewall rule optimization</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-rule-optimization/m-p/69027#M40129</link>
      <description>&lt;P&gt;Anyone know of any good firewall optimization software for PA. One that can review the rules and make good suggestion to improve the rule order, removal etc?&lt;/P&gt;</description>
      <pubDate>Fri, 04 Dec 2015 14:40:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-rule-optimization/m-p/69027#M40129</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2015-12-04T14:40:51Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall rule optimization</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-rule-optimization/m-p/69029#M40130</link>
      <description>&lt;P&gt;Company called Firemon has a product that assists with this.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.firemon.com/" target="_blank"&gt;https://www.firemon.com/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Dec 2015 14:48:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-rule-optimization/m-p/69029#M40130</guid>
      <dc:creator>googol</dc:creator>
      <dc:date>2015-12-04T14:48:27Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall rule optimization</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-rule-optimization/m-p/69032#M40132</link>
      <description>&lt;P&gt;I assume firemon has a price, anyone know of an open source version as well to look at?&lt;/P&gt;</description>
      <pubDate>Fri, 04 Dec 2015 16:28:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-rule-optimization/m-p/69032#M40132</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2015-12-04T16:28:09Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall rule optimization</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-rule-optimization/m-p/69107#M40170</link>
      <description>&lt;P&gt;I was in the same boat as you are; inherited about 850 lines of sec policies being migrated from other vendor's solution. My apporach to clean/optimize was to enable "Hightlight unused rules" and after a month i started disabling unused rules. Waited another month, documented disabled rules and scheduled rule removeal. And four more weekends like that. It took me about 2 months to reduce number of rules from 850 to 200. In the same time this excersise allowed me to get better understanding of the infrastructure. Out of all those disabled rules, i had 10 rules thate were&amp;nbsp;required&amp;nbsp;to put back; some legacy traffic users were not aware of.&lt;/P&gt;
&lt;P&gt;You might be able to use PAN migration tool to upload firewall config and see if any duplication is showing.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Dec 2015 22:01:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-rule-optimization/m-p/69107#M40170</guid>
      <dc:creator>Kalemegdan</dc:creator>
      <dc:date>2015-12-07T22:01:30Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall rule optimization</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-rule-optimization/m-p/69189#M40192</link>
      <description>&lt;P&gt;Well the migration was complete a couple of months ago and I have been using the method that you mentioned but I was also told there is software out there that would be able to do some of that work for me. So I just thought I would see waht people are using and how they like it. So far the only suggestion I have had is firemon, I am probably going to download a trial of that and see what it does, but would love more suggestions&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2015 15:40:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-rule-optimization/m-p/69189#M40192</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2015-12-08T15:40:02Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall rule optimization</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-rule-optimization/m-p/69218#M40208</link>
      <description>&lt;P&gt;If you dont mind, once you downlaod and test software could you post your findings?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2015 21:20:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-rule-optimization/m-p/69218#M40208</guid>
      <dc:creator>Kalemegdan</dc:creator>
      <dc:date>2015-12-08T21:20:37Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall rule optimization</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-rule-optimization/m-p/69226#M40215</link>
      <description>&lt;P&gt;I can try it may not be something that can easlily be posted verbatim and it may take quite some time to complete the testing&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2015 22:08:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-rule-optimization/m-p/69226#M40215</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2015-12-08T22:08:30Z</dc:date>
    </item>
  </channel>
</rss>

