<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Logging query - Missing logs from implicit deny rule in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/logging-query-missing-logs-from-implicit-deny-rule/m-p/72074#M40994</link>
    <description>&lt;P&gt;Hey there,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On version 6, there is no option to override and log the default rule. In order to have this logged, just simply create a new any to any deny all rule, set it to log at session end and place it at the bottom of your ruleset.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you upgrade to 6.1 or higher you can override the 'interzone-default' rule which is now visible in the ruleset and set it to log.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;hope this helps,&lt;/P&gt;
&lt;P&gt;Ben&lt;/P&gt;</description>
    <pubDate>Wed, 03 Feb 2016 14:38:48 GMT</pubDate>
    <dc:creator>bmorris1</dc:creator>
    <dc:date>2016-02-03T14:38:48Z</dc:date>
    <item>
      <title>Logging query - Missing logs from implicit deny rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/logging-query-missing-logs-from-implicit-deny-rule/m-p/72062#M40991</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Doing some testing with a PAN-OS v6.0.0 VM-100. The command ‘set system setting logging default-policy-logging 300’ is configured so I am seeing log entries for traffic that is being blocked by the implicit deny rule for inter-zone traffic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If I enable a security policy that permits any application I’m able to play a&amp;nbsp;video on webpage:&amp;nbsp;&lt;STRONG&gt;&lt;A href="http://www.bbc.co.uk/news/uk-england-nottinghamshire-35472617" target="_blank"&gt;http://www.bbc.co.uk/news/uk-england-nottinghamshire-35472617&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If I enable a policy with some application filtering I am now unble to play the video (which I expect) however I am not seeing anything being denied in the log.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is a problem for me as I need to be able to see what exactly is being blocked in order to permit the appropriate application(s).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can anyone suggest why I might be having this issue?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Wed, 03 Feb 2016 13:30:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/logging-query-missing-logs-from-implicit-deny-rule/m-p/72062#M40991</guid>
      <dc:creator>GNS_Support</dc:creator>
      <dc:date>2016-02-03T13:30:44Z</dc:date>
    </item>
    <item>
      <title>Re: Logging query - Missing logs from implicit deny rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/logging-query-missing-logs-from-implicit-deny-rule/m-p/72074#M40994</link>
      <description>&lt;P&gt;Hey there,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On version 6, there is no option to override and log the default rule. In order to have this logged, just simply create a new any to any deny all rule, set it to log at session end and place it at the bottom of your ruleset.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you upgrade to 6.1 or higher you can override the 'interzone-default' rule which is now visible in the ruleset and set it to log.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;hope this helps,&lt;/P&gt;
&lt;P&gt;Ben&lt;/P&gt;</description>
      <pubDate>Wed, 03 Feb 2016 14:38:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/logging-query-missing-logs-from-implicit-deny-rule/m-p/72074#M40994</guid>
      <dc:creator>bmorris1</dc:creator>
      <dc:date>2016-02-03T14:38:48Z</dc:date>
    </item>
  </channel>
</rss>

