<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is Zone Protection on Shared Gateways Supported in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/is-zone-protection-on-shared-gateways-supported/m-p/188773#M57250</link>
    <description>&lt;P&gt;Thanks for the response.&amp;nbsp; The link at least clears up the question of External Zone Support in VSYS, however are you able to confirm the qestion of if Zone protection profiles are supported on Layer3 Zones assigned to Shared Gateways?&amp;nbsp; If so where would you find the logs?&lt;/P&gt;</description>
    <pubDate>Mon, 27 Nov 2017 11:20:19 GMT</pubDate>
    <dc:creator>CHammock</dc:creator>
    <dc:date>2017-11-27T11:20:19Z</dc:date>
    <item>
      <title>Is Zone Protection on Shared Gateways Supported</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-zone-protection-on-shared-gateways-supported/m-p/188672#M57225</link>
      <description>&lt;P&gt;I have a question regarding Zone Protection on Zones in a shared gateway. &amp;nbsp;Is it supported. &amp;nbsp;When I try and configure it it seems to be valid configuration. &amp;nbsp;However as a shared gateway does not generate logs where do the the ZP logs go? &amp;nbsp;Also when I run the command "show zone-protection zone ?" the SG zones do no show in the list so I can't collect stats for the zone protection.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I did try applying zone protection to the external zone which connects to the SG but this gave a commit warning saying something about syn-cookie not supported. &amp;nbsp;Also in my mind this would apply zone protection too late for it to be affective.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Nov 2017 17:03:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-zone-protection-on-shared-gateways-supported/m-p/188672#M57225</guid>
      <dc:creator>CHammock</dc:creator>
      <dc:date>2017-11-24T17:03:02Z</dc:date>
    </item>
    <item>
      <title>Re: Is Zone Protection on Shared Gateways Supported</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-zone-protection-on-shared-gateways-supported/m-p/188709#M57232</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/28914"&gt;@CHammock&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It is supported ... with some limitations (as you already saw in the commit warning)&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/80/pan-os/web-interface-help/network/network-network-profiles-zone-protection/building-blocks-of-zone-protection-profiles#id463e1210-c858-4712-8d34-66b5fb587c2e" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/80/pan-os/web-interface-help/network/network-network-profiles-zone-protection/building-blocks-of-zone-protection-profiles#id463e1210-c858-4712-8d34-66b5fb587c2e&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 26 Nov 2017 12:55:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-zone-protection-on-shared-gateways-supported/m-p/188709#M57232</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2017-11-26T12:55:37Z</dc:date>
    </item>
    <item>
      <title>Re: Is Zone Protection on Shared Gateways Supported</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-zone-protection-on-shared-gateways-supported/m-p/188773#M57250</link>
      <description>&lt;P&gt;Thanks for the response.&amp;nbsp; The link at least clears up the question of External Zone Support in VSYS, however are you able to confirm the qestion of if Zone protection profiles are supported on Layer3 Zones assigned to Shared Gateways?&amp;nbsp; If so where would you find the logs?&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2017 11:20:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-zone-protection-on-shared-gateways-supported/m-p/188773#M57250</guid>
      <dc:creator>CHammock</dc:creator>
      <dc:date>2017-11-27T11:20:19Z</dc:date>
    </item>
    <item>
      <title>Re: Is Zone Protection on Shared Gateways Supported</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-zone-protection-on-shared-gateways-supported/m-p/188774#M57251</link>
      <description>&lt;P&gt;I haven't any shared gateway configured on our firewalls. But the logs should be in the thread log if you have assigned a Log forwarding profile to the zone.&lt;/P&gt;&lt;P&gt;And in the Monitor tab you probably have to select all virtual systems to view these logs, as they are not assigned to specific vsys&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2017 11:43:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-zone-protection-on-shared-gateways-supported/m-p/188774#M57251</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2017-11-27T11:43:25Z</dc:date>
    </item>
    <item>
      <title>Re: Is Zone Protection on Shared Gateways Supported</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-zone-protection-on-shared-gateways-supported/m-p/188914#M57268</link>
      <description>&lt;P&gt;Just to clarify my questions were based on a design I am putting forward but in the end I decide to lab the functionality to be sure.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have just tested this in the lab and have found the below&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. &amp;nbsp;As&lt;SPAN&gt;&amp;nbsp;vsys_remo&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;suggested when you assign a zone protection profile to a zone in an SG it will log to the threat log if you change the Virtual System drop down to all. &amp;nbsp;I have to say I didn't expect this but it is a pleasent suprise. &amp;nbsp;Obviously a Log Forwarding profile is only needed if you wish to forward those logs to an external log device like syslog.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;2. &amp;nbsp;The other thing I discovered regarding my point of the "show zone-protection" command. &amp;nbsp;If you use&amp;nbsp;"&lt;SPAN&gt;show zone-protection zone {zonename}" you will only be able to filter based on zones which belong to a VSYS not an SG, however if you just run the command&amp;nbsp;"show zone-protection" it will list all the zone-protection states including those from the SG zones.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;Many Thanks to&amp;nbsp;vsys_remo&amp;nbsp;for the guidance.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Nov 2017 09:46:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-zone-protection-on-shared-gateways-supported/m-p/188914#M57268</guid>
      <dc:creator>CHammock</dc:creator>
      <dc:date>2017-11-28T09:46:43Z</dc:date>
    </item>
  </channel>
</rss>

