<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Security policy: exception question in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-exception-question/m-p/148870#M49670</link>
    <description>&lt;P&gt;Sorry, should have elaborated on that part. By critical traffic I meant critical threats. Planning on doing that in the profiles.&lt;/P&gt;</description>
    <pubDate>Wed, 22 Mar 2017 13:53:22 GMT</pubDate>
    <dc:creator>TLineberry</dc:creator>
    <dc:date>2017-03-22T13:53:22Z</dc:date>
    <item>
      <title>Security policy: exception question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-exception-question/m-p/148843#M49662</link>
      <description>&lt;P&gt;Hi, I'm trying to create a security policy that would block all critical traffic from source zone&amp;nbsp;"A", to destination zone "B". However, I want to allow traffic from a specific IP in zone "A". How can I make an exception to allow that IP? I assume I could create a policy to allow that IP and then one below it block traffic from that zone but I would prefer not to do that- feel like it could be error prone, etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Wed, 22 Mar 2017 13:28:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-exception-question/m-p/148843#M49662</guid>
      <dc:creator>TLineberry</dc:creator>
      <dc:date>2017-03-22T13:28:47Z</dc:date>
    </item>
    <item>
      <title>Re: Security policy: exception question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-exception-question/m-p/148868#M49669</link>
      <description>&lt;P&gt;Hmm, define 'critical traffic'. Applications with high risk? Critical events from some security profile?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Mar 2017 13:51:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-exception-question/m-p/148868#M49669</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2017-03-22T13:51:01Z</dc:date>
    </item>
    <item>
      <title>Re: Security policy: exception question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-exception-question/m-p/148870#M49670</link>
      <description>&lt;P&gt;Sorry, should have elaborated on that part. By critical traffic I meant critical threats. Planning on doing that in the profiles.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Mar 2017 13:53:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-exception-question/m-p/148870#M49670</guid>
      <dc:creator>TLineberry</dc:creator>
      <dc:date>2017-03-22T13:53:22Z</dc:date>
    </item>
    <item>
      <title>Re: Security policy: exception question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-exception-question/m-p/148874#M49671</link>
      <description>&lt;P&gt;I would suggest blocking at least critical events on all traffic, but ok.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yeah, you have to make a rule for that specific IP first with security profile set to alert (or no security profile).&lt;/P&gt;&lt;P&gt;After that rule you make a rule from zone A to B with blocking security profile.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Mar 2017 14:07:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-exception-question/m-p/148874#M49671</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2017-03-22T14:07:35Z</dc:date>
    </item>
    <item>
      <title>Re: Security policy: exception question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-exception-question/m-p/148879#M49673</link>
      <description>&lt;P&gt;for a single or a few threats you can add an IP exception in the vulnerability protection profile in the exceptions tab, but if you want to exclude an ip from all scanning it's better to create a new rule with a different (alert all) profile&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="exception.png"&gt;&lt;img src="https://live.paloaltonetworks.com/skins/images/EAF30C9A5814E020FF754681AA726920/responsive_peak/images/image_not_found.png" alt="exception.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Mar 2017 14:22:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-exception-question/m-p/148879#M49673</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-03-22T14:22:27Z</dc:date>
    </item>
    <item>
      <title>Re: Security policy: exception question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-exception-question/m-p/148885#M49678</link>
      <description>&lt;P&gt;Ohh, didn't know about 'ip exemptions' query so far.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Mar 2017 14:29:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-exception-question/m-p/148885#M49678</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2017-03-22T14:29:48Z</dc:date>
    </item>
    <item>
      <title>Re: Security policy: exception question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-exception-question/m-p/148887#M49679</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/10238"&gt;@santonic&lt;/a&gt; wrote:&lt;BR /&gt;
&lt;P&gt;Ohh, didn't know about 'ip exemptions' query so far.&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;bonus: you can also add IP exceptions (or policy exceptions) directly from the threat log:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="exception log.png"&gt;&lt;img src="https://live.paloaltonetworks.com/skins/images/EAF30C9A5814E020FF754681AA726920/responsive_peak/images/image_not_found.png" alt="exception log.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Mar 2017 14:33:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-exception-question/m-p/148887#M49679</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-03-22T14:33:19Z</dc:date>
    </item>
    <item>
      <title>Re: Security policy: exception question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-exception-question/m-p/148989#M49707</link>
      <description>&lt;P&gt;We do block all critical events already, just trying to get a better idea of some things and using a policy for it. I appreciate the help. I think my only option is creating two separate rules.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Mar 2017 18:58:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-exception-question/m-p/148989#M49707</guid>
      <dc:creator>TLineberry</dc:creator>
      <dc:date>2017-03-22T18:58:07Z</dc:date>
    </item>
    <item>
      <title>Re: Security policy: exception question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-exception-question/m-p/149304#M49769</link>
      <description>&lt;P&gt;Hi TLineberry,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Use the 'Negate' option.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Create a rule which allows the traffic rule like this:&lt;/P&gt;&lt;P&gt;Source Zone = A&lt;/P&gt;&lt;P&gt;Source address = the ones you want to allow AND check the box for 'Negate'&lt;/P&gt;&lt;P&gt;Destination Zone = B&lt;/P&gt;&lt;P&gt;Destination Zone = Allow&lt;/P&gt;&lt;P&gt;Application/Service/Security profile = your choice&lt;/P&gt;&lt;P&gt;Action = Allow&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The unwanted IPs would hit the interzone rule, IFF they don't happen to match some other rule.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Anurag&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2017 06:11:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-exception-question/m-p/149304#M49769</guid>
      <dc:creator>ansharma</dc:creator>
      <dc:date>2017-03-24T06:11:58Z</dc:date>
    </item>
    <item>
      <title>Re: Security policy: exception question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-exception-question/m-p/149678#M49822</link>
      <description>&lt;P&gt;This is exactly what I'm looking for. Thank you!!&lt;/P&gt;</description>
      <pubDate>Mon, 27 Mar 2017 14:55:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-exception-question/m-p/149678#M49822</guid>
      <dc:creator>TLineberry</dc:creator>
      <dc:date>2017-03-27T14:55:57Z</dc:date>
    </item>
  </channel>
</rss>

