<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unused Rules in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/unused-rules/m-p/76423#M42315</link>
    <description>&lt;P&gt;You may want to look at the very bottom of this article:&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/API-Articles/rules-edit-php-to-manage-edit-export-rules-from-CLI/ta-p/53321" target="_blank"&gt;https://live.paloaltonetworks.com/t5/API-Articles/rules-edit-php-to-manage-edit-export-rules-from-CLI/ta-p/53321&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 14 Apr 2016 16:02:05 GMT</pubDate>
    <dc:creator>cpainchaud</dc:creator>
    <dc:date>2016-04-14T16:02:05Z</dc:date>
    <item>
      <title>Unused Rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unused-rules/m-p/66487#M39216</link>
      <description>&lt;P&gt;There is a feature to highlight unused rules. If a rule goes from used to unused does that feature show it as unused and if so how long does it take to show it as unused?&lt;/P&gt;</description>
      <pubDate>Tue, 13 Oct 2015 20:04:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unused-rules/m-p/66487#M39216</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2015-10-13T20:04:20Z</dc:date>
    </item>
    <item>
      <title>Re: Unused Rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unused-rules/m-p/66489#M39218</link>
      <description>&lt;P&gt;a quick search like&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/forums/searchpage/tab/message?filter=labels&amp;amp;q=unused+rules" target="_blank"&gt;https://live.paloaltonetworks.com/t5/forums/searchpage/tab/message?filter=labels&amp;amp;q=unused+rules&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the first 2 links say that Unused flag is reset when FW is rebooted. I think that answers your question.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Oct 2015 21:36:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unused-rules/m-p/66489#M39218</guid>
      <dc:creator>cpainchaud</dc:creator>
      <dc:date>2015-10-13T21:36:23Z</dc:date>
    </item>
    <item>
      <title>Re: Unused Rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unused-rules/m-p/66535#M39225</link>
      <description>&lt;P&gt;The unused rule are the security policy which are not used since last reboot. If a rule is used even once it will be&amp;nbsp;marked as used.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Oct 2015 12:12:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unused-rules/m-p/66535#M39225</guid>
      <dc:creator>pankaku</dc:creator>
      <dc:date>2015-10-14T12:12:10Z</dc:date>
    </item>
    <item>
      <title>Re: Unused Rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unused-rules/m-p/66560#M39233</link>
      <description>&lt;P&gt;To be more specific - this counter is reset when dataplane is restarted not full firewall.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Oct 2015 13:40:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unused-rules/m-p/66560#M39233</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2015-10-14T13:40:20Z</dc:date>
    </item>
    <item>
      <title>Re: Unused Rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unused-rules/m-p/66607#M39246</link>
      <description>&lt;P&gt;But if it never is used again will it always show are used? Based I what I read in other posts it will start showing used after the next reboot&lt;/P&gt;</description>
      <pubDate>Wed, 14 Oct 2015 19:54:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unused-rules/m-p/66607#M39246</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2015-10-14T19:54:43Z</dc:date>
    </item>
    <item>
      <title>Re: Unused Rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unused-rules/m-p/66608#M39247</link>
      <description>&lt;P&gt;I think it does answer my question.&amp;nbsp; So if a rule that was used at least once but never again, it won't show unsed till the next reboot&lt;/P&gt;</description>
      <pubDate>Wed, 14 Oct 2015 19:56:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unused-rules/m-p/66608#M39247</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2015-10-14T19:56:19Z</dc:date>
    </item>
    <item>
      <title>Re: Unused Rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unused-rules/m-p/66631#M39258</link>
      <description>&lt;P&gt;Firewall (or dataplane) restart will restart counter.&lt;/P&gt;
&lt;P&gt;When traffic matches rule at least once after reboot then it shows up as used rule.&lt;/P&gt;
&lt;P&gt;When rule has not matched starting from last reboot rule shows up as unmatched rule.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Oct 2015 09:54:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unused-rules/m-p/66631#M39258</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2015-10-15T09:54:48Z</dc:date>
    </item>
    <item>
      <title>Re: Unused Rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unused-rules/m-p/66639#M39266</link>
      <description>&lt;P&gt;Not exactly certain what you're looking for, but you might want to look into a tool called FireMon.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The UI of this tool replicates other product enviornments. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;FireMon has the ability to suggest rule combination changes. &amp;nbsp;Not only will it tell you when/last/how often a rule was used. &amp;nbsp;It gives you usage of objects within a specific rule. &amp;nbsp;(Something Palo UI won't do)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;FireMon works with ASAs, CheckPoint, Palo...a wide varitey of platforms.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Oct 2015 13:03:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unused-rules/m-p/66639#M39266</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2015-10-15T13:03:13Z</dc:date>
    </item>
    <item>
      <title>Re: Unused Rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unused-rules/m-p/66655#M39278</link>
      <description>&lt;P&gt;Here's what the report looks like:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/701i95E35127A4A86FAF/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="FireMon.JPG" title="FireMon.JPG" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can click each count and view specifics for each rule.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Oct 2015 14:44:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unused-rules/m-p/66655#M39278</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2015-10-15T14:44:19Z</dc:date>
    </item>
    <item>
      <title>Re: Unused Rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unused-rules/m-p/76415#M42310</link>
      <description>&lt;P&gt;So a rule can go unused and show as used until its rebooted. So that would make sense why I have a rule that shows used since the last time I rebooted the FW on March 15 &amp;nbsp;and&amp;nbsp;no longer appears&amp;nbsp;in the traffic monitor&amp;nbsp;after March 20. That can be a little hard to clean up the firewall since randomly rebooting the firewall is not a very viable option. LOL&lt;/P&gt;</description>
      <pubDate>Thu, 14 Apr 2016 13:24:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unused-rules/m-p/76415#M42310</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2016-04-14T13:24:02Z</dc:date>
    </item>
    <item>
      <title>Re: Unused Rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unused-rules/m-p/76419#M42312</link>
      <description>&lt;P&gt;I haved looked at firemon and I love it but the budget here does not love it LOL&lt;/P&gt;</description>
      <pubDate>Thu, 14 Apr 2016 14:03:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unused-rules/m-p/76419#M42312</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2016-04-14T14:03:26Z</dc:date>
    </item>
    <item>
      <title>Re: Unused Rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unused-rules/m-p/76423#M42315</link>
      <description>&lt;P&gt;You may want to look at the very bottom of this article:&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/API-Articles/rules-edit-php-to-manage-edit-export-rules-from-CLI/ta-p/53321" target="_blank"&gt;https://live.paloaltonetworks.com/t5/API-Articles/rules-edit-php-to-manage-edit-export-rules-from-CLI/ta-p/53321&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Apr 2016 16:02:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unused-rules/m-p/76423#M42315</guid>
      <dc:creator>cpainchaud</dc:creator>
      <dc:date>2016-04-14T16:02:05Z</dc:date>
    </item>
  </channel>
</rss>

