<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PA 3020 - new security rule isn't active. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-new-security-rule-isn-t-active/m-p/172854#M54493</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/50331"&gt;@MPI-AE&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;If I would have to guess you likely want to take a look at the below article. It sounds like you don't have session-rematch enabled and the session wasn't getting properly closed on the session table.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Learning-Articles/How-Session-Rematch-Works/ta-p/60326" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Learning-Articles/How-Session-Rematch-Works/ta-p/60326&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 23 Aug 2017 14:19:26 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2017-08-23T14:19:26Z</dc:date>
    <item>
      <title>PA 3020 - new security rule isn't active.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-new-security-rule-isn-t-active/m-p/172359#M54383</link>
      <description>&lt;P&gt;Hey all!&lt;/P&gt;&lt;P&gt;There is a strange problem with my PA 3020 7.1.7:&lt;/P&gt;&lt;P&gt;I need access from a client pc to a printer with many ports so for testing I set up a security rule with application any and service any.&lt;/P&gt;&lt;P&gt;The rule is enabled but it's not effective.&lt;/P&gt;&lt;P&gt;The firewall even doesn't have traffic logs for this connection.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I already had this problem in the past, I don't know anymore how I solved it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are there some things I can do?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Mon, 21 Aug 2017 08:28:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-new-security-rule-isn-t-active/m-p/172359#M54383</guid>
      <dc:creator>MPI-AE</dc:creator>
      <dc:date>2017-08-21T08:28:04Z</dc:date>
    </item>
    <item>
      <title>Re: PA 3020 - new security rule isn't active.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-new-security-rule-isn-t-active/m-p/172367#M54384</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Did you enable log in the new policy? Are you sure that the user's traffic is passing (or should pass) the firewall in order to reach the printer?&amp;nbsp;For the test create any to any zone with the source ip of the test pc going to the destination ip of the printer.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Aug 2017 08:43:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-new-security-rule-isn-t-active/m-p/172367#M54384</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-08-21T08:43:01Z</dc:date>
    </item>
    <item>
      <title>Re: PA 3020 - new security rule isn't active.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-new-security-rule-isn-t-active/m-p/172402#M54388</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/50331"&gt;@MPI-AE&lt;/a&gt;&lt;/P&gt;&lt;P&gt;In addition to &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/37163"&gt;@TranceforLife&lt;/a&gt;'s question: if you log the traffic, do you have no logs for that rule or effectively for that connection (src and dst IP as filter)?&lt;/P&gt;&lt;P&gt;Or is the printer may be not responding (or wrong/no default gateway?) And you have a rule above your any-any-allow rule with an application with default ports "tcp/udp/dynamic", so all connections never hit your test-rule?&lt;/P&gt;</description>
      <pubDate>Mon, 21 Aug 2017 13:37:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-new-security-rule-isn-t-active/m-p/172402#M54388</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2017-08-21T13:37:45Z</dc:date>
    </item>
    <item>
      <title>Re: PA 3020 - new security rule isn't active.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-new-security-rule-isn-t-active/m-p/172501#M54417</link>
      <description>&lt;P&gt;If pc sends traffic to printer but printer does not answer then Palo logs application as incomplete.&lt;/P&gt;&lt;P&gt;&lt;A title="https://live.paloaltonetworks.com/t5/Management-Articles/Not-Applicable-Incomplete-Insufficient-Data-in-the-Application/ta-p/65711" href="https://live.paloaltonetworks.com/t5/Management-Articles/Not-Applicable-Incomplete-Insufficient-Data-in-the-Application/ta-p/65711" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/Not-Applicable-Incomplete-Insufficient-Data-in-the-Application/ta-p/65711&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does traffic pass firewall? Even if PC and printer are in different subnet there might be Layer3 switch routing traffic between internal subnets.&lt;/P&gt;&lt;P&gt;Does traffic match this test rule? I mean are source/destination zones correct etc?&lt;/P&gt;</description>
      <pubDate>Tue, 22 Aug 2017 01:46:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-new-security-rule-isn-t-active/m-p/172501#M54417</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2017-08-22T01:46:00Z</dc:date>
    </item>
    <item>
      <title>Re: PA 3020 - new security rule isn't active.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-new-security-rule-isn-t-active/m-p/172768#M54471</link>
      <description>&lt;P&gt;Thanks for your answers!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm not sure what was the exact problem.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The connection is now working, but I didn't change anything.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That's very strange.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But thanks for your support, though!&lt;/P&gt;</description>
      <pubDate>Wed, 23 Aug 2017 07:34:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-new-security-rule-isn-t-active/m-p/172768#M54471</guid>
      <dc:creator>MPI-AE</dc:creator>
      <dc:date>2017-08-23T07:34:37Z</dc:date>
    </item>
    <item>
      <title>Re: PA 3020 - new security rule isn't active.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-new-security-rule-isn-t-active/m-p/172854#M54493</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/50331"&gt;@MPI-AE&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;If I would have to guess you likely want to take a look at the below article. It sounds like you don't have session-rematch enabled and the session wasn't getting properly closed on the session table.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Learning-Articles/How-Session-Rematch-Works/ta-p/60326" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Learning-Articles/How-Session-Rematch-Works/ta-p/60326&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Aug 2017 14:19:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-new-security-rule-isn-t-active/m-p/172854#M54493</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-08-23T14:19:26Z</dc:date>
    </item>
  </channel>
</rss>

