<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Security policies &amp;amp; Schedules. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/security-policies-amp-schedules/m-p/173068#M54528</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/37537"&gt;@mtizani&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For a feature request, you can reach out to your local SE.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;He/She should be able to create a new FR for you or add your vote to an already existing one.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I was able to find some&amp;nbsp;existing FRs that could be of interest for you :&amp;nbsp;&lt;SPAN&gt;Related FRs: 4454, 4669, 4670, 5612&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;4454 : FR&amp;nbsp;for “graying” out a policy after a schedule has expired.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;4669 : FR for generating a system log upon rule schedule end.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;4670 : FR for a proactive notification of rules within a configurable threshold that are about to expire or reach the end of their schedule.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;5612 : FR so that&amp;nbsp;after the expiration date the policy is disabled and removed automatically.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Seeing that there is currently no system log upon expiration I see no way to use snmptrap/email to inform security admins about this.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Cheers !&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-Kiwi.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 24 Aug 2017 12:48:37 GMT</pubDate>
    <dc:creator>kiwi</dc:creator>
    <dc:date>2017-08-24T12:48:37Z</dc:date>
    <item>
      <title>Security policies &amp; Schedules.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policies-amp-schedules/m-p/172978#M54516</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just a quick question.&amp;nbsp; Unsure if this has been asked previously.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When applying a non-reoccuring schedule to a security policy,&amp;nbsp; I have noticed in pan 8.0.x, once the schedule has expired, the policy in the security policy view does not identify it as expired.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I am trying avoid the obvious scenario of temporary policies being applied either due to a fault, project or change scenario.&amp;nbsp; Generally project teams would not advise the security team of their completion and fail to raise requests to remove such scheduled policies.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Was hoping that the webui would identify it somehow similar to when disabling a rule.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also is there the possibility of adding a row within the security policy view to identify or segregate policies, similar to checkpoints webui? A divider with a description?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 24 Aug 2017 04:10:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policies-amp-schedules/m-p/172978#M54516</guid>
      <dc:creator>mtizani</dc:creator>
      <dc:date>2017-08-24T04:10:55Z</dc:date>
    </item>
    <item>
      <title>Re: Security policies &amp; Schedules.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policies-amp-schedules/m-p/173014#M54517</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/37537"&gt;@mtizani&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You are correct. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;The rule is still identified as 'Active' ... however it will never match seeing that the configured timeframe has expired.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That said, PAN-OS doesn't have dividers for the security policy. &amp;nbsp;Instead I'd recommend using tags to identify/segregate policies :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Tutorials/Tag-Browser/ta-p/96781" target="_blank"&gt;Tag Browser&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers !&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Aug 2017 06:55:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policies-amp-schedules/m-p/173014#M54517</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2017-08-24T06:55:08Z</dc:date>
    </item>
    <item>
      <title>Re: Security policies &amp; Schedules.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policies-amp-schedules/m-p/173061#M54523</link>
      <description>&lt;P&gt;Thanks Kiwi.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;That is unfortunate and possibly a feature request I can put through somewhere if you can guide me..&amp;nbsp; In an environment with over 100+sec policies, would be good to clearly identify the expired scheduled rule by displaying the rule as disabled.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You mentioning tags though might have triggered something here.&amp;nbsp; I can possibly create a tag called 'Scheduled', tag relevant rules with expiry information etc in the description field and filter based on this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Was also wondering in terms of notifications if it was possible to fire an email/snmptrap etc to advise security admins of the expired rule?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Aug 2017 11:23:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policies-amp-schedules/m-p/173061#M54523</guid>
      <dc:creator>mtizani</dc:creator>
      <dc:date>2017-08-24T11:23:17Z</dc:date>
    </item>
    <item>
      <title>Re: Security policies &amp; Schedules.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policies-amp-schedules/m-p/173068#M54528</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/37537"&gt;@mtizani&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For a feature request, you can reach out to your local SE.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;He/She should be able to create a new FR for you or add your vote to an already existing one.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I was able to find some&amp;nbsp;existing FRs that could be of interest for you :&amp;nbsp;&lt;SPAN&gt;Related FRs: 4454, 4669, 4670, 5612&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;4454 : FR&amp;nbsp;for “graying” out a policy after a schedule has expired.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;4669 : FR for generating a system log upon rule schedule end.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;4670 : FR for a proactive notification of rules within a configurable threshold that are about to expire or reach the end of their schedule.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;5612 : FR so that&amp;nbsp;after the expiration date the policy is disabled and removed automatically.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Seeing that there is currently no system log upon expiration I see no way to use snmptrap/email to inform security admins about this.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Cheers !&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-Kiwi.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Aug 2017 12:48:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policies-amp-schedules/m-p/173068#M54528</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2017-08-24T12:48:37Z</dc:date>
    </item>
  </channel>
</rss>

