<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Panorama Device groups and pre and post policies in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-device-groups-and-pre-and-post-policies/m-p/162880#M52785</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks, wish you would have told me these best practise a few weeks ago &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As for device groups not exaclty what i was using for. but did an experiment&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;again if I have&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;tier1&lt;/P&gt;&lt;P&gt;tier2&lt;/P&gt;&lt;P&gt;tier3&lt;/P&gt;&lt;P&gt;pa&lt;/P&gt;&lt;P&gt;&amp;lt;device&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and I have in pre&amp;nbsp;&lt;/P&gt;&lt;P&gt;tier1&lt;/P&gt;&lt;P&gt;&amp;nbsp; policy 1&lt;/P&gt;&lt;P&gt;tier2&lt;/P&gt;&lt;P&gt;&amp;nbsp; policy 2&lt;/P&gt;&lt;P&gt;tier3&lt;/P&gt;&lt;P&gt;&amp;nbsp; policy 3&lt;/P&gt;&lt;P&gt;pa&lt;/P&gt;&lt;P&gt;&amp;nbsp; policy 4&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;when I look on &amp;lt;device&amp;gt; they show up as&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; policy 1&lt;/P&gt;&lt;P&gt;&amp;nbsp; policy 2&lt;/P&gt;&lt;P&gt;&amp;nbsp; policy 3&lt;/P&gt;&lt;P&gt;&amp;nbsp; policy 4&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;from my read, tier 1 gets processes first and then teir2&amp;nbsp;etc etc &amp;nbsp;which i sort of understand.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;as for the migration tool, Im doing loading it, but would be able to give an example of how to do a partial import of full config use the command line / XML tools, think that would be &amp;nbsp;better to learn.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 23 Jun 2017 04:21:03 GMT</pubDate>
    <dc:creator>asamad_1</dc:creator>
    <dc:date>2017-06-23T04:21:03Z</dc:date>
    <item>
      <title>Panorama Device groups and pre and post policies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-device-groups-and-pre-and-post-policies/m-p/162843#M52778</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Okay just to under stand&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if I have a device group&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Top&lt;/P&gt;&lt;P&gt;Middle&lt;/P&gt;&lt;P&gt;pa&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and I place my device in pa group&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and i have rules security&amp;nbsp;&lt;/P&gt;&lt;P&gt;in the pre section&lt;/P&gt;&lt;P&gt;top -&amp;gt; Rule 1&lt;/P&gt;&lt;P&gt;middle -&amp;gt; rule 2&lt;/P&gt;&lt;P&gt;pa -&amp;gt; rule 3&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;how does that look on the actual PA. &amp;nbsp;if I look at my device security&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;will the policies be&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;rule 1&lt;/P&gt;&lt;P&gt;rule 2&lt;/P&gt;&lt;P&gt;rule 3&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;or&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;rule 3&lt;/P&gt;&lt;P&gt;rule 2&lt;/P&gt;&lt;P&gt;rule 1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and i presume its&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;lt;pre rules&amp;gt;&lt;/P&gt;&lt;P&gt;any device rules&lt;/P&gt;&lt;P&gt;&amp;lt;post rules&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;last question on panorama how can i move a rule from pre to post ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jun 2017 21:19:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-device-groups-and-pre-and-post-policies/m-p/162843#M52778</guid>
      <dc:creator>Alex_Samad</dc:creator>
      <dc:date>2017-06-22T21:19:54Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama Device groups and pre and post policies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-device-groups-and-pre-and-post-policies/m-p/162872#M52783</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/62286"&gt;@Alex_Samad&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;A device group enables grouping based on network segmentation, geographic location, organizational function, or any other common aspect of firewalls that require similar policy configurations. Using device groups, you can configure policy rules and the objects they reference.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;To your first question, according to your example, if you have a device placed in the device group PA, with rules 1, 2, 3 and in the pre-rule section, that's the order they will be showed in the actual device; however, the processing of the rules will depend if you create it as pre-rule or post-rule.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Pre Rules:&lt;/STRONG&gt; Pre rules are inserted at the top of the rule order and are checked first in the configuration in the pre-rulebase, before the post or locally defined rules. Examples on the use of pre rules are to insert global use rules such as blocking peer-to-peer traffic for all users, or allowing DNS traffic for all users.&amp;nbsp;Additional factors used to decide to use pre only rules are administrative restrictions that do not allow rules to be created locally on the firewalls. In other words, if you have many remote firewalls, and you do not want to allow other administrators to perform changes locally in each firewall, then pre-rule is the way to go. When you configure pre-rules, any policies pushed from Panorama to the device cannot be altered locally on the firewall, instead it has to be always done through Panorama.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Post Rules:&lt;/STRONG&gt; Post rules are inserted at the bottom of the rule order and are checked in their configuration order in the post-rulebase, after the pre and locally defined rules. Examples of post&amp;nbsp;rule use are global deny rules, either by appID/service/user/IP based or a combination of, or to create default zone to zone deny rules to use for logging of all blocked traffic. Unlike pre-rules, if &amp;nbsp;you are&amp;nbsp;planning for rule management, it is recommended that Panorama is used to manage a post rule database if admins will be configuring rules locally on the firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Best Practices from Palo Alto are:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Local Rules in Panorama:&lt;/STRONG&gt; &amp;nbsp;Unless there is a business requirement, create all policies through Panorama&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Use Post-Rules in Panorama:&lt;/STRONG&gt; If there is an issue either with the communication to Panorama or Panorama itself, having most of your policy rules in the Post-Rules section allows you to create local policy to override if required.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As for your last question, about moving rules from Pre-Rules to Post-Rules, it is not supported. My recommendation in this case is to use the Palo Alto Migration tool in order to do that. With the Migration Tool, you can connect to the firewall via XML API, and pull all rules into the migration tool. From that point forward, you can select the rules you want to transform in post-rules, and generate an API call to the firewall.&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Migration-Tool/ct-p/migration_tool" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Migration-Tool/ct-p/migration_tool&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Migration-Tool-Articles/Migration-Tool-3-Info-and-Guide/ta-p/55294?attachment-id=1060" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Migration-Tool-Articles/Migration-Tool-3-Info-and-Guide/ta-p/55294?attachment-id=1060&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this helps.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jun 2017 03:45:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-device-groups-and-pre-and-post-policies/m-p/162872#M52783</guid>
      <dc:creator>acc6d0b3610eec313831f7900fdbd235</dc:creator>
      <dc:date>2017-06-23T03:45:17Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama Device groups and pre and post policies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-device-groups-and-pre-and-post-policies/m-p/162880#M52785</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks, wish you would have told me these best practise a few weeks ago &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As for device groups not exaclty what i was using for. but did an experiment&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;again if I have&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;tier1&lt;/P&gt;&lt;P&gt;tier2&lt;/P&gt;&lt;P&gt;tier3&lt;/P&gt;&lt;P&gt;pa&lt;/P&gt;&lt;P&gt;&amp;lt;device&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and I have in pre&amp;nbsp;&lt;/P&gt;&lt;P&gt;tier1&lt;/P&gt;&lt;P&gt;&amp;nbsp; policy 1&lt;/P&gt;&lt;P&gt;tier2&lt;/P&gt;&lt;P&gt;&amp;nbsp; policy 2&lt;/P&gt;&lt;P&gt;tier3&lt;/P&gt;&lt;P&gt;&amp;nbsp; policy 3&lt;/P&gt;&lt;P&gt;pa&lt;/P&gt;&lt;P&gt;&amp;nbsp; policy 4&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;when I look on &amp;lt;device&amp;gt; they show up as&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; policy 1&lt;/P&gt;&lt;P&gt;&amp;nbsp; policy 2&lt;/P&gt;&lt;P&gt;&amp;nbsp; policy 3&lt;/P&gt;&lt;P&gt;&amp;nbsp; policy 4&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;from my read, tier 1 gets processes first and then teir2&amp;nbsp;etc etc &amp;nbsp;which i sort of understand.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;as for the migration tool, Im doing loading it, but would be able to give an example of how to do a partial import of full config use the command line / XML tools, think that would be &amp;nbsp;better to learn.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jun 2017 04:21:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-device-groups-and-pre-and-post-policies/m-p/162880#M52785</guid>
      <dc:creator>asamad_1</dc:creator>
      <dc:date>2017-06-23T04:21:03Z</dc:date>
    </item>
  </channel>
</rss>

