<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Same Zone Traffic to inside hitting different rules in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/same-zone-traffic-to-inside-hitting-different-rules/m-p/160449#M52300</link>
    <description>&lt;P&gt;Hey,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you post the screen shot&amp;nbsp;of your policy set-up, please? Who is the&amp;nbsp;source and who is the destination? Do you think destination(s) .141 and .2 are in the different zones?&amp;nbsp; &amp;nbsp;Usually, device will do exactly what you have asked it to do. Unfortunately, this is not always the same as what you want.&lt;/P&gt;</description>
    <pubDate>Fri, 09 Jun 2017 20:32:39 GMT</pubDate>
    <dc:creator>TranceforLife</dc:creator>
    <dc:date>2017-06-09T20:32:39Z</dc:date>
    <item>
      <title>Same Zone Traffic to inside hitting different rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/same-zone-traffic-to-inside-hitting-different-rules/m-p/160438#M52298</link>
      <description>&lt;P&gt;Howdy All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm running into an issue where traffic from "Colo-Voice" segment bound to Any on the inside is hittin an "Any L3" policy (shown below) that's in place as the last policy. During our capture, we can see there's another host from the same segment bound for the same segment however it is hitting the "Cisco Voice-to-Internal_Trust" policy (as it should be.) Below are the two rules configured on the PAN. We can't see to figure out why the host hitting the "Any L3" policy is not hitting the "Cisco Voice-to-Internal_Trust". For all sense and purposes, this traffic "should" hit the Cisco Voice...policy first.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our goal is to finally be able to remove the "Any L3" policy so that the PAN can be locked down.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any input on this is greatly appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;================================&lt;/P&gt;&lt;P&gt;}&lt;BR /&gt;"Cisco Voice-to-Internal_Trust" {&lt;BR /&gt;from Colo-Voice;&lt;BR /&gt;to Internal_Trust;&lt;BR /&gt;source 10.10.60.0/24;&lt;BR /&gt;destination any;&lt;BR /&gt;source-user any;&lt;BR /&gt;category any;&lt;BR /&gt;application [ cisco-rtmt informix ms-office365-base ntp outlook-web-online rmi-iiop rtcp rtp-base sccp sip ssh ssl tftp web-browsing];&lt;BR /&gt;service any;&lt;BR /&gt;hip-profiles any;&lt;BR /&gt;action allow;&lt;BR /&gt;}&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"Any L3" {&lt;BR /&gt;from [ Colo-Voice FW_110 Mgmt P2P SF-113 SF-114 SF-115 SF-116 Trust UCS-Mgmt Internal_Trust];&lt;BR /&gt;to [ Colo-Voice FW_110 Mgmt P2P SF-113 SF-114 SF-115 SF-116 Trust UCS-Mgmt Internal_Trust];&lt;BR /&gt;source any;&lt;BR /&gt;destination any;&lt;BR /&gt;source-user any;&lt;BR /&gt;category any;&lt;BR /&gt;application any;&lt;BR /&gt;service any;&lt;BR /&gt;hip-profiles any;&lt;BR /&gt;action allow;&lt;BR /&gt;profile-setting {&lt;BR /&gt;group Monitor;&lt;BR /&gt;}&lt;BR /&gt;disabled no;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;================================&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9614i337873048E2CBA31/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jun 2017 18:26:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/same-zone-traffic-to-inside-hitting-different-rules/m-p/160438#M52298</guid>
      <dc:creator>F.Ledesma</dc:creator>
      <dc:date>2017-06-09T18:26:41Z</dc:date>
    </item>
    <item>
      <title>Re: Same Zone Traffic to inside hitting different rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/same-zone-traffic-to-inside-hitting-different-rules/m-p/160449#M52300</link>
      <description>&lt;P&gt;Hey,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you post the screen shot&amp;nbsp;of your policy set-up, please? Who is the&amp;nbsp;source and who is the destination? Do you think destination(s) .141 and .2 are in the different zones?&amp;nbsp; &amp;nbsp;Usually, device will do exactly what you have asked it to do. Unfortunately, this is not always the same as what you want.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jun 2017 20:32:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/same-zone-traffic-to-inside-hitting-different-rules/m-p/160449#M52300</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-06-09T20:32:39Z</dc:date>
    </item>
    <item>
      <title>Re: Same Zone Traffic to inside hitting different rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/same-zone-traffic-to-inside-hitting-different-rules/m-p/160460#M52302</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cap11 shows some of the rules above the 'Any L3'. &amp;nbsp;Cap12 shows the 'Any L3' Rule. &amp;nbsp;I have screen cap of all the policies that precede the&amp;nbsp;&lt;SPAN&gt; "Cisco Voice-to-Internal_Trust".&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Please advise if anything else is needed.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks!&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Cap11" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9616iC8D46050707D4B3F/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Capture11.PNG" alt="Cap11" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Cap11&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Cap12" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9615i191A95135C693F83/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Capture12.PNG" alt="Cap12" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Cap12&lt;/span&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jun 2017 21:05:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/same-zone-traffic-to-inside-hitting-different-rules/m-p/160460#M52302</guid>
      <dc:creator>F.Ledesma</dc:creator>
      <dc:date>2017-06-09T21:05:46Z</dc:date>
    </item>
  </channel>
</rss>

