<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Best practice for setting up address groups in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/best-practice-for-setting-up-address-groups/m-p/155684#M51172</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/62286"&gt;@Alex_Samad&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Personally I don't see a big advantage of user an actual address entry for a whole network. Generally you are going to know that anything within 10.1.0.0/16 is dc1 and when you start to create rules you'll inadvertably enter that in a few times without actually clicking on the address object or address group. Then you have a mixture of statically defined addresses, and then other policies that actually mention the address object. Maybe some instances have you updating whole subnets for different things but I've found these to be highly static and you'll likely never change dc1 from 10.1.0.0/16 unless you go all ipv6.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The dc1_servers dynamic address group is really where I would&amp;nbsp;create things like this because it makes it generally easier to manage. So if you limit the objects in this group for anything tagged dc1_servers when you decomission or add a server you simply need to worry about create the address object and tagging it correctly instead of updating all of the security policies. This also comes in handy for things like printers and things like that.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Really this is all going to depend on how you actually build out your rules. I would imagine that you'll have more rules destined to secure your servers then you will with your actuall entire network address for dc1 or so on. Generally speaking though I will manually type in the network addresses instead of using my set address groups for entire networks; but when it comes to things like servers or printers I'll always use dynamic address groups simply due to the fact that they change pretty often in all of my enviroments.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 09 May 2017 12:50:15 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2017-05-09T12:50:15Z</dc:date>
    <item>
      <title>Best practice for setting up address groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-practice-for-setting-up-address-groups/m-p/155647#M51162</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Newbie to PA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want to create a address group dynamic (think that might be best. &amp;nbsp;made up from a group of network addresses in each DC.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So for example if I have 3 DC&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;dc1 - 10.1.0.0/16&lt;/P&gt;&lt;P&gt;dc2 - 10.2.0.0/16&lt;/P&gt;&lt;P&gt;dc3 - 10.3.0.0/16&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I could tag them with "dc_network"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Looking at dc3 I could make that a dynamic group&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;say&amp;nbsp;&lt;/P&gt;&lt;P&gt;10.3.1.0/24&lt;/P&gt;&lt;P&gt;10.3.10.0/24&lt;/P&gt;&lt;P&gt;10.3.100.0/24&lt;/P&gt;&lt;P&gt;10.3.110.0/24&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;with tag say dc1_networks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is where i was going to leave it but then I thought &amp;nbsp;why not enter into the address object each server for example&lt;/P&gt;&lt;P&gt;10.3.1.50&lt;/P&gt;&lt;P&gt;10.3.10.50&lt;/P&gt;&lt;P&gt;10.3.100.50&lt;/P&gt;&lt;P&gt;10.3.110.50&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and I could tag it as dc1_servers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;should I be doing it this way&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;server -&amp;gt; network -&amp;gt; dc -&amp;gt; company network&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;or should I stick just to network level ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 May 2017 05:21:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-practice-for-setting-up-address-groups/m-p/155647#M51162</guid>
      <dc:creator>Alex_Samad</dc:creator>
      <dc:date>2017-05-09T05:21:26Z</dc:date>
    </item>
    <item>
      <title>Re: Best practice for setting up address groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-practice-for-setting-up-address-groups/m-p/155684#M51172</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/62286"&gt;@Alex_Samad&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Personally I don't see a big advantage of user an actual address entry for a whole network. Generally you are going to know that anything within 10.1.0.0/16 is dc1 and when you start to create rules you'll inadvertably enter that in a few times without actually clicking on the address object or address group. Then you have a mixture of statically defined addresses, and then other policies that actually mention the address object. Maybe some instances have you updating whole subnets for different things but I've found these to be highly static and you'll likely never change dc1 from 10.1.0.0/16 unless you go all ipv6.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The dc1_servers dynamic address group is really where I would&amp;nbsp;create things like this because it makes it generally easier to manage. So if you limit the objects in this group for anything tagged dc1_servers when you decomission or add a server you simply need to worry about create the address object and tagging it correctly instead of updating all of the security policies. This also comes in handy for things like printers and things like that.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Really this is all going to depend on how you actually build out your rules. I would imagine that you'll have more rules destined to secure your servers then you will with your actuall entire network address for dc1 or so on. Generally speaking though I will manually type in the network addresses instead of using my set address groups for entire networks; but when it comes to things like servers or printers I'll always use dynamic address groups simply due to the fact that they change pretty often in all of my enviroments.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 May 2017 12:50:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-practice-for-setting-up-address-groups/m-p/155684#M51172</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-05-09T12:50:15Z</dc:date>
    </item>
    <item>
      <title>Re: Best practice for setting up address groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-practice-for-setting-up-address-groups/m-p/155899#M51210</link>
      <description>&lt;P&gt;For now I think I am going to do both ... doing a trial..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Trying to figure out best approach to building profiles&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have multi env prod , sim , uat , test, demo, dev ... all with similiar security set, &amp;nbsp;I was going to use tags which would sets which would define port/protocols, so app1 can talk to app2 &amp;nbsp;but only for the same environment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 May 2017 05:10:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-practice-for-setting-up-address-groups/m-p/155899#M51210</guid>
      <dc:creator>Alex_Samad</dc:creator>
      <dc:date>2017-05-10T05:10:35Z</dc:date>
    </item>
    <item>
      <title>Re: Best practice for setting up address groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-practice-for-setting-up-address-groups/m-p/156524#M51389</link>
      <description>&lt;P&gt;Your organization model and tagging can work. &amp;nbsp;But you will need to be very careful in how you construct the actual security policy order of rules. &amp;nbsp;Since you are going to have address objects at three levels each more specific than the previous, you will need to insure that any rules are in your policy from most specific address tags to the least specific. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Otherwise the more specific rules will never get used and unanticipated permits or denies will occur.&lt;/P&gt;</description>
      <pubDate>Sat, 13 May 2017 12:36:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-practice-for-setting-up-address-groups/m-p/156524#M51389</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2017-05-13T12:36:39Z</dc:date>
    </item>
  </channel>
</rss>

