<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Policy Rules order in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/policy-rules-order/m-p/128447#M46703</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For the security and NAT it is will go in order. My guess for rest of the sub tabs as well.&amp;nbsp;&lt;/P&gt;&lt;P&gt;So security policy from top &amp;gt; bottom until first match. If the NAT is configured same from&amp;nbsp;top&lt;SPAN&gt; &amp;gt; bottom. Traffic will be scanned from top&amp;gt;bottom for every sub tabs if configured.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 23 Nov 2016 14:05:21 GMT</pubDate>
    <dc:creator>TranceforLife</dc:creator>
    <dc:date>2016-11-23T14:05:21Z</dc:date>
    <item>
      <title>Policy Rules order</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/policy-rules-order/m-p/128435#M46701</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if we are going to the tab "Policy" we will see 7 different sub tabs. The tabs are:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Security&lt;/P&gt;&lt;P&gt;NAT&lt;/P&gt;&lt;P&gt;QoS&lt;/P&gt;&lt;P&gt;PBF&lt;/P&gt;&lt;P&gt;App Override&lt;/P&gt;&lt;P&gt;Captive Portal&lt;/P&gt;&lt;P&gt;DoS Protection&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I know for example that Security rules are always checked before NAT rules but whats about the rest? I spent planty of time google for this information but without success.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Nov 2016 13:49:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/policy-rules-order/m-p/128435#M46701</guid>
      <dc:creator>Rboehme</dc:creator>
      <dc:date>2016-11-23T13:49:18Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Rules order</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/policy-rules-order/m-p/128447#M46703</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For the security and NAT it is will go in order. My guess for rest of the sub tabs as well.&amp;nbsp;&lt;/P&gt;&lt;P&gt;So security policy from top &amp;gt; bottom until first match. If the NAT is configured same from&amp;nbsp;top&lt;SPAN&gt; &amp;gt; bottom. Traffic will be scanned from top&amp;gt;bottom for every sub tabs if configured.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Nov 2016 14:05:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/policy-rules-order/m-p/128447#M46703</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2016-11-23T14:05:21Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Rules order</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/policy-rules-order/m-p/128452#M46704</link>
      <description>&lt;P&gt;Maybe this would help:&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/Learning-Articles/Packet-Flow-Sequence-in-PAN-OS/ta-p/56081" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Learning-Articles/Packet-Flow-Sequence-in-PAN-OS/ta-p/56081&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Nov 2016 14:08:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/policy-rules-order/m-p/128452#M46704</guid>
      <dc:creator>FJU-ITCS</dc:creator>
      <dc:date>2016-11-23T14:08:48Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Rules order</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/policy-rules-order/m-p/128805#M46730</link>
      <description>&lt;P&gt;Do look at the packet flow process noted above. The general flow is:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Routing lookup - &amp;nbsp;This is needed to assign zones and know the egress interface&lt;/P&gt;&lt;P&gt;NAT - This occurs then to get the final ip addresses after NAT&lt;/P&gt;&lt;P&gt;Security policy check - now we have all the information to confirm if the flow is permitted&lt;/P&gt;&lt;P&gt;Deeper inspections - if permitted, we perform any deep inspections applied to the policy&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Learning-Articles/Packet-Flow-Sequence-in-PAN-OS/ta-p/56081" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Learning-Articles/Packet-Flow-Sequence-in-PAN-OS/ta-p/56081&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Nov 2016 16:58:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/policy-rules-order/m-p/128805#M46730</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2016-11-24T16:58:27Z</dc:date>
    </item>
  </channel>
</rss>

