<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Unused rules showing used in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/unused-rules-showing-used/m-p/147662#M49415</link>
    <description>&lt;P&gt;I just upgraded and rebooted my firewall. When I choose to highlight unused rules it is showing rules that I can not find any traffic for in the traffic monitor as used. I thought the reboot would reset everything but I have no idea why a rule that appears to be unused is showing used - any ideas?&lt;/P&gt;</description>
    <pubDate>Tue, 14 Mar 2017 16:00:23 GMT</pubDate>
    <dc:creator>jdprovine</dc:creator>
    <dc:date>2017-03-14T16:00:23Z</dc:date>
    <item>
      <title>Unused rules showing used</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unused-rules-showing-used/m-p/147662#M49415</link>
      <description>&lt;P&gt;I just upgraded and rebooted my firewall. When I choose to highlight unused rules it is showing rules that I can not find any traffic for in the traffic monitor as used. I thought the reboot would reset everything but I have no idea why a rule that appears to be unused is showing used - any ideas?&lt;/P&gt;</description>
      <pubDate>Tue, 14 Mar 2017 16:00:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unused-rules-showing-used/m-p/147662#M49415</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-03-14T16:00:23Z</dc:date>
    </item>
    <item>
      <title>Re: Unused rules showing used</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unused-rules-showing-used/m-p/147718#M49419</link>
      <description>&lt;P&gt;It isn't a rule required by a following rule is it. For example when traffic originally gets mated to an 'SSL' rule and only then switches over to say 'bittorrent' or something like that?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Mar 2017 19:20:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unused-rules-showing-used/m-p/147718#M49419</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-03-14T19:20:50Z</dc:date>
    </item>
    <item>
      <title>Re: Unused rules showing used</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unused-rules-showing-used/m-p/147719#M49420</link>
      <description>&lt;P&gt;I am not sure what you mean by required by a following rule, I thought rules either passed the traffic or didn't&lt;/P&gt;</description>
      <pubDate>Tue, 14 Mar 2017 19:22:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unused-rules-showing-used/m-p/147719#M49420</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-03-14T19:22:14Z</dc:date>
    </item>
    <item>
      <title>Re: Unused rules showing used</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unused-rules-showing-used/m-p/147822#M49451</link>
      <description>&lt;P&gt;Some applications do not get identified right away, or an admin has reasons to split the rule up into a few different pieces instead of enabling all the required applications in one rule. In this case you could have traffic need to hit something like your 'ssl' rule before the app is identified and it switches over to say your 'skype' or 'bittorrent' rule.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Mar 2017 13:27:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unused-rules-showing-used/m-p/147822#M49451</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-03-15T13:27:45Z</dc:date>
    </item>
    <item>
      <title>Re: Unused rules showing used</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unused-rules-showing-used/m-p/147825#M49454</link>
      <description>&lt;P&gt;I don't really follow that explaination, all I know is that I have rule that is set up to be used for smtp traffic and even after I rebooted the firewall it is showing as used but not showing any traffic passing through it on the traffic monitor even now&lt;/P&gt;</description>
      <pubDate>Wed, 15 Mar 2017 13:38:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unused-rules-showing-used/m-p/147825#M49454</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-03-15T13:38:26Z</dc:date>
    </item>
    <item>
      <title>Re: Unused rules showing used</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unused-rules-showing-used/m-p/150723#M50008</link>
      <description>&lt;P&gt;Can you confirm that the rule in question has the log action turned on in the action tab?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The unused rules function is a simple flag, as soon as the rule processes any match the flag will turn off and the rule shows as having been used since the reboot.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Logging is a choice on a per policy basis for session start, session end or both.&lt;/P&gt;&lt;P&gt;If logging is at session end, and the application involved keeps the session open for hours or days then there will be not log. &amp;nbsp;But with your case this is not likely.&lt;/P&gt;&lt;P&gt;So when doing this type of testing we sometimes add log at session start to be sure to see the log as soon as possible in the logs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;so if your rule is showing used and your rule is configured to log and you see no logs this would be an possible bug to take up with a support ticket.&lt;/P&gt;</description>
      <pubDate>Sun, 02 Apr 2017 12:22:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unused-rules-showing-used/m-p/150723#M50008</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2017-04-02T12:22:43Z</dc:date>
    </item>
    <item>
      <title>Re: Unused rules showing used</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unused-rules-showing-used/m-p/150844#M50031</link>
      <description>&lt;P&gt;Yes it is set to log at session end and it also has a security profile attached to it. I have rebooted the firewall it show unused before the reboot and unused after the reboot. I tried changing the names a couple times and I have scoured the logs for any evidence of use.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Apr 2017 13:06:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unused-rules-showing-used/m-p/150844#M50031</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-04-03T13:06:51Z</dc:date>
    </item>
    <item>
      <title>Re: Unused rules showing used</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unused-rules-showing-used/m-p/150845#M50032</link>
      <description>&lt;P&gt;My rule is showing unused and has shown unused for several months even after a reboot. &amp;nbsp;I guess it is possible that it really is unused I just want confirmation before disabling it&lt;/P&gt;</description>
      <pubDate>Mon, 03 Apr 2017 13:10:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unused-rules-showing-used/m-p/150845#M50032</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-04-03T13:10:06Z</dc:date>
    </item>
    <item>
      <title>Re: Unused rules showing used</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unused-rules-showing-used/m-p/150847#M50034</link>
      <description>&lt;P&gt;depending on how specific (or generic) your rule is, have you tried the test security-policy-match command to see which rule your traffic expected based on the policy is actually hitting? it may be shadowed, tho it should report that as a warning when committing.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Apr 2017 14:03:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unused-rules-showing-used/m-p/150847#M50034</guid>
      <dc:creator>bradk14</dc:creator>
      <dc:date>2017-04-03T14:03:27Z</dc:date>
    </item>
    <item>
      <title>Re: Unused rules showing used</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unused-rules-showing-used/m-p/150848#M50035</link>
      <description>&lt;P&gt;So I would run this on the command line&amp;nbsp;&lt;SPAN&gt;test security-policy-match name of policy?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Apr 2017 14:15:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unused-rules-showing-used/m-p/150848#M50035</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-04-03T14:15:32Z</dc:date>
    </item>
    <item>
      <title>Re: Unused rules showing used</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unused-rules-showing-used/m-p/150857#M50036</link>
      <description>&lt;P&gt;well appears I looked at the rule when I was checking for log at session end, but I did find the rule that was showing used but nothing in the log to have that issues &lt;span class="lia-unicode-emoji" title=":face_with_tongue:"&gt;😛&lt;/span&gt; Thanks LOL&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Apr 2017 14:47:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unused-rules-showing-used/m-p/150857#M50036</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-04-03T14:47:54Z</dc:date>
    </item>
  </channel>
</rss>

