<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PA is Default Deny in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pa-is-default-deny/m-p/185305#M56707</link>
    <description>&lt;P&gt;Creating a Deny-All rule is bad practice, don't do it. If there is intrazone traffic (Trust to Trust for example) that has not been allowed by a previous rule, this will be denied because your Deny-All rule will be matching before the Intrazone-default rule.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You don't need to make a deny-all rule to see denied traffic, you can actually click the click the default intra/interzone-default rules, click "Override" next to the Clone button at the bottom to edit them, then you can enable the "Log at session end" options under the Action tab.&lt;/P&gt;</description>
    <pubDate>Fri, 03 Nov 2017 09:36:02 GMT</pubDate>
    <dc:creator>LukeBullimore</dc:creator>
    <dc:date>2017-11-03T09:36:02Z</dc:date>
    <item>
      <title>PA is Default Deny</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-is-default-deny/m-p/31004#M22690</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Stupid question. Just need confirmation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PA (42020) devices are default deny correct?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If a packet is not specifically allowed or denied by a rule; when it gets to the bottom of the rules the default action is to deny, correct?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;--CH&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Apr 2013 17:09:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-is-default-deny/m-p/31004#M22690</guid>
      <dc:creator>choff123</dc:creator>
      <dc:date>2013-04-17T17:09:27Z</dc:date>
    </item>
    <item>
      <title>Re: PA is Default Deny</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-is-default-deny/m-p/31005#M22691</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes its denied but not logged.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In order to get denied packets logged you need to manually put a security policy in the end that says:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;srczone: any&lt;/P&gt;&lt;P&gt;dstzone: any&lt;/P&gt;&lt;P&gt;srcip: any&lt;/P&gt;&lt;P&gt;dstip: any&lt;/P&gt;&lt;P&gt;user: any&lt;/P&gt;&lt;P&gt;appid: any&lt;/P&gt;&lt;P&gt;service: any&lt;/P&gt;&lt;P&gt;options: log on session end&lt;/P&gt;&lt;P&gt;action: deny&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Apr 2013 17:11:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-is-default-deny/m-p/31005#M22691</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2013-04-17T17:11:43Z</dc:date>
    </item>
    <item>
      <title>Re: PA is Default Deny</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-is-default-deny/m-p/31006#M22692</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;just be careful with such an "deny all" rule since it will break intrazone traffic (traffic ingress and egress the same zone, this also includes e.g. ping to a data interface when enabled).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can temporarily enable logging of the default deny rule on the CLI: set system setting logging default-policy-logging&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Apr 2013 20:09:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-is-default-deny/m-p/31006#M22692</guid>
      <dc:creator>Anon1</dc:creator>
      <dc:date>2013-04-17T20:09:32Z</dc:date>
    </item>
    <item>
      <title>Re: PA is Default Deny</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-is-default-deny/m-p/184814#M56637</link>
      <description>&lt;P&gt;With an intrazone rule created before it, is there a good reason (security purposes ot other) not to have the Deny All rule in place at the end? Or is it more of personal preference?&lt;/P&gt;</description>
      <pubDate>Tue, 31 Oct 2017 21:29:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-is-default-deny/m-p/184814#M56637</guid>
      <dc:creator>Jermaine_Scott</dc:creator>
      <dc:date>2017-10-31T21:29:05Z</dc:date>
    </item>
    <item>
      <title>Re: PA is Default Deny</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-is-default-deny/m-p/185305#M56707</link>
      <description>&lt;P&gt;Creating a Deny-All rule is bad practice, don't do it. If there is intrazone traffic (Trust to Trust for example) that has not been allowed by a previous rule, this will be denied because your Deny-All rule will be matching before the Intrazone-default rule.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You don't need to make a deny-all rule to see denied traffic, you can actually click the click the default intra/interzone-default rules, click "Override" next to the Clone button at the bottom to edit them, then you can enable the "Log at session end" options under the Action tab.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Nov 2017 09:36:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-is-default-deny/m-p/185305#M56707</guid>
      <dc:creator>LukeBullimore</dc:creator>
      <dc:date>2017-11-03T09:36:02Z</dc:date>
    </item>
  </channel>
</rss>

