<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Zone Protection - to or from in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-to-or-from/m-p/194584#M58200</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18719"&gt;@jdprovine&lt;/a&gt;&lt;/P&gt;&lt;P&gt;I would create a custom report that targets the Traffic Log database sorted by bytes and grouped by the Inbound Interface. This should give you a good idea of which zones you should actually target.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 10 Jan 2018 13:47:15 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2018-01-10T13:47:15Z</dc:date>
    <item>
      <title>Zone Protection - to or from</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-to-or-from/m-p/194430#M58170</link>
      <description>&lt;P&gt;Is Zone protection&amp;nbsp;applied from or too the zone?&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jan 2018 19:21:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-to-or-from/m-p/194430#M58170</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-01-09T19:21:34Z</dc:date>
    </item>
    <item>
      <title>Re: Zone Protection - to or from</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-to-or-from/m-p/194441#M58171</link>
      <description>&lt;P&gt;It's specifically ingress.&lt;/P&gt;&lt;P&gt;It's also important to note when configuring zone protection that it's only evaluated on traffic that doesn't match an existing session, if it matches an existing session it'll bypass your zone protection settings.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jan 2018 19:47:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-to-or-from/m-p/194441#M58171</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-01-09T19:47:11Z</dc:date>
    </item>
    <item>
      <title>Re: Zone Protection - to or from</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-to-or-from/m-p/194444#M58172</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I put it on my DMZ zone and so far I am not seeing anything.&amp;nbsp; But I have about 23 zones,&amp;nbsp;and none of them are name untrust anymore so I am trying to determine what zones would I would see the best results from using zone protection. I did have a health check run last fall but it did not show all of my zones and its recommendations were based on a untrust zone that I do not even have.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jan 2018 20:01:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-to-or-from/m-p/194444#M58172</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-01-09T20:01:52Z</dc:date>
    </item>
    <item>
      <title>Re: Zone Protection - to or from</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-to-or-from/m-p/194447#M58173</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;That is a it depends type of question. Obviously the untrust zone from the internet should have this, but it may also apply to certain internal zones, i.e. keeping kids from getting at your stuff.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers!&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jan 2018 20:10:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-to-or-from/m-p/194447#M58173</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-01-09T20:10:18Z</dc:date>
    </item>
    <item>
      <title>Re: Zone Protection - to or from</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-to-or-from/m-p/194448#M58174</link>
      <description>,&lt;BR /&gt;They likely simply utilized the common zone names for their recommendations, which is rather lazy on their end. Untrust would be the zone that you utilize as an ‘outside’ zone; essentially wherever your ISP connection comes in should be a non-trusted zone, hence it being shortened to simply untrust.&lt;BR /&gt;I wouldn’t expect to really see any triggers on a DMZ for zone protection. You really shouldn’t have too much traffic with the DMZ as the ingress zone. I would caution trying to trip the zone protection profile however. Zone protection is really what I consider to be the last line of defense against a flood, simply because it will effect new sessions on the entire zone when tripped.</description>
      <pubDate>Tue, 09 Jan 2018 20:14:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-to-or-from/m-p/194448#M58174</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-01-09T20:14:04Z</dc:date>
    </item>
    <item>
      <title>Re: Zone Protection - to or from</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-to-or-from/m-p/194449#M58175</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Adding it to the outside/internet in/ISP untrusted zone is an easy choice, but I do I determine what other zones it would be most beneficial on&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jan 2018 20:22:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-to-or-from/m-p/194449#M58175</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-01-09T20:22:46Z</dc:date>
    </item>
    <item>
      <title>Re: Zone Protection - to or from</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-to-or-from/m-p/194549#M58191</link>
      <description>&lt;P&gt;i would say only you can answer that as it's only you that really knows "your" network.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;for me..&amp;nbsp; trusted LAN, no point.. the LAN itself is quite secure, no guest or BYOD connections. only domain members can connect.&amp;nbsp; even then these devices are policied to the hilt.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;DMZ. no point.. as &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;stated, DMZ ingress is a big no no.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;internet (any untrusted) ... yes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;so... if you feel that any of your zones&amp;nbsp;are vulnerable to such attacks then protect them...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jan 2018 09:23:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-to-or-from/m-p/194549#M58191</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-01-10T09:23:12Z</dc:date>
    </item>
    <item>
      <title>Re: Zone Protection - to or from</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-to-or-from/m-p/194584#M58200</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18719"&gt;@jdprovine&lt;/a&gt;&lt;/P&gt;&lt;P&gt;I would create a custom report that targets the Traffic Log database sorted by bytes and grouped by the Inbound Interface. This should give you a good idea of which zones you should actually target.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jan 2018 13:47:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-to-or-from/m-p/194584#M58200</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-01-10T13:47:15Z</dc:date>
    </item>
    <item>
      <title>Re: Zone Protection - to or from</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-to-or-from/m-p/194601#M58205</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Definitely things coming in from the outside we need to protect against, but a majority of ours users are students and are not a part of our domain but have access to the internal network so it is tricky&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jan 2018 14:03:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-to-or-from/m-p/194601#M58205</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-01-10T14:03:05Z</dc:date>
    </item>
    <item>
      <title>Re: Zone Protection - to or from</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-to-or-from/m-p/194620#M58208</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi.&amp;nbsp; you mentioned previously...&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Zone protection is really what I consider to be the last line of defense against a flood, simply because it will effect new sessions on the entire zone when tripped.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if you have time could you elaborate,&amp;nbsp; not so much on Zone Protection but the "trip" part.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jan 2018 15:00:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-to-or-from/m-p/194620#M58208</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-01-10T15:00:49Z</dc:date>
    </item>
    <item>
      <title>Re: Zone Protection - to or from</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-to-or-from/m-p/194635#M58211</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;So what I meant by "trip" is when you actually trigger the Activate or Maximum values. So when you look at Flood Protection it's very similar to the DoS profiles where you'll have an 'Alarm Rate', 'Activate Rate', and a 'Maximum' rate. The major difference is that it triggers on the&amp;nbsp;&lt;EM&gt;entire zone&lt;/EM&gt; for any traffic that doesn't match to an existing session. So on UDP packets the 'Activate Rate' will trigger random drops and you may start dropping legitimate traffic across the entire zone; 'Maximum Rate' obviosuly will cause any number of packets exceeding this value to simply drop. Same for SYN, however you do get the option to set this action on 'Activate' to SYN Cookies instead of RED.&amp;nbsp;&lt;/P&gt;&lt;P&gt;DoS Protection Policies are more of the first line of defense in my mind, just because of how much more granular you can get when working with them. It's also easier to work with the 'Activate' and 'Maximum' values since you can generally work in a time to properly attempt to hit that value and verify the policy is working as intended, while only effecting connections to the specified host(s).&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'd much rather see more aggressive DoS Protection Policies than aggressive Zone Protection Profiles simply because I never want to effect an entire zone of traffic. We host a lot of public websites; I would rather have one website be spotty or unreachable in the event of an attack over lossing all of them. Therefore I always try to set my Zone Protection to the point where my DoS Policies&lt;EM&gt;should&lt;/EM&gt; prevent the Zone Protection from ever hitting the Activate rates. Currently you would have to trigger the majority of my DoS Policies before my Zone Protection profiles ever had a chance to activate.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jan 2018 15:34:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-to-or-from/m-p/194635#M58211</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-01-10T15:34:21Z</dc:date>
    </item>
    <item>
      <title>Re: Zone Protection - to or from</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-to-or-from/m-p/194638#M58214</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&lt;/P&gt;&lt;P&gt;OK, got it.&lt;/P&gt;&lt;P&gt;Many thanks for taking the time to elaborate.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jan 2018 15:42:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-to-or-from/m-p/194638#M58214</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-01-10T15:42:46Z</dc:date>
    </item>
    <item>
      <title>Re: Zone Protection - to or from</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-to-or-from/m-p/194646#M58216</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;By granular on the DoS protection do you mean it is&amp;nbsp; because you can pick specific IP's and subnets not just full zones ?&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jan 2018 15:58:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-to-or-from/m-p/194646#M58216</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-01-10T15:58:09Z</dc:date>
    </item>
    <item>
      <title>Re: Zone Protection - to or from</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-to-or-from/m-p/194649#M58219</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18719"&gt;@jdprovine&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Correct. Since you can choose to single out an IP address (or multiple) you can limit the impacts of the DoS Policies to those hosts. With a Zone Protection Profile you'll effect&amp;nbsp;&lt;STRONG&gt;all&lt;/STRONG&gt; unmatched traffic across the entire zone without any way to negate a particular address.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jan 2018 16:01:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-to-or-from/m-p/194649#M58219</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-01-10T16:01:12Z</dc:date>
    </item>
    <item>
      <title>Re: Zone Protection - to or from</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-to-or-from/m-p/194651#M58221</link>
      <description>&lt;P&gt;so much to choose from on the PA sometimes its so overwhelming, I really wish I had a test system&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jan 2018 16:03:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-to-or-from/m-p/194651#M58221</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-01-10T16:03:13Z</dc:date>
    </item>
    <item>
      <title>Re: Zone Protection - to or from</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-to-or-from/m-p/195001#M58290</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When you say specifically ingress do you mean it should be applied to ingress zones like the outside? And the DMZ is considered internal by the PA? We first started out by putting zone protection on the DMZ and it showed our external DNS (in the DMZ) servers in scanning (alerting on host sweep) out to the internet/outside for DNS. I had been looking for it to alert on traffic coming into the DMZ not the other way around. Have I got something configured incorrectly on my profile? I have taken the zone protection off of the DMZ and put it on the outside Zone instead&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jan 2018 21:11:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-to-or-from/m-p/195001#M58290</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-01-12T21:11:04Z</dc:date>
    </item>
    <item>
      <title>Re: Zone Protection - to or from</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-to-or-from/m-p/195016#M58294</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18719"&gt;@jdprovine&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;It will be traffic ingressing the specified zone. For example my 'outside/untrust' zone would be the ingress interface for everything shown under ( zone.src eq outside ) on my firewall. All of this traffic would count towards the zone protection profile allocated to the 'outside' zone.&amp;nbsp;&lt;/P&gt;&lt;P&gt;For&amp;nbsp;&lt;EM&gt;most&lt;/EM&gt; situations if you are trying to protect your resources in the DMZ you would want the zone protection profile on your 'outside/untrust' zone. When traffic comes into the firewall the ingress zone is going to be 'outside/untrust', and the egress zone is going to be the 'dmz'.&amp;nbsp;&lt;/P&gt;&lt;P&gt;An easier way of thinking of it would be like this:&lt;/P&gt;&lt;P&gt;ingress: The same as&amp;nbsp;&lt;STRONG&gt;from&lt;/STRONG&gt; or&amp;nbsp;&lt;STRONG&gt;source&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;egress: Same as&amp;nbsp;&lt;STRONG&gt;to&lt;/STRONG&gt; or&amp;nbsp;&lt;STRONG&gt;destination&lt;/STRONG&gt;.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Currently your configuration should be correct. If the zone protection is on the 'outside' zone it will protect your dmz resources from external traffic/attacks.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jan 2018 22:04:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-to-or-from/m-p/195016#M58294</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-01-12T22:04:28Z</dc:date>
    </item>
    <item>
      <title>Re: Zone Protection - to or from</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-to-or-from/m-p/195094#M58317</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18719"&gt;@jdprovine&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Just so it's not lost in all of this. While Zone Protection will help the firewall keep the zone up and going and should protect from external users flooding your firewall with requests that could make it hit it's limits, it's also extremely important to protect public services living in your DMZ with a DoS Protection Profile.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Without a DoS Protection Profile assigned to a public facing device you could easily run into issues with an attacker flooding your web server or public DNS server and have then bring it down from a flood attack long before the limits for a Zone Protection profile are even close to triggering in most enviroments. This is why I always call Zone Protection 'Last Resort'. The DoS Protection profiles should&amp;nbsp;prevent everything but a very large attack from ever getting the chance to trigger your Zone Protection 'Activate' or 'Maximum' values.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 13 Jan 2018 18:35:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-to-or-from/m-p/195094#M58317</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-01-13T18:35:18Z</dc:date>
    </item>
    <item>
      <title>Re: Zone Protection - to or from</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-to-or-from/m-p/195131#M58331</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&lt;/P&gt;&lt;P&gt;So it would be better to start with DoS protection around our DNS servers in the DMZ and then add Zone protection later?&amp;nbsp; Is there a way to "whitelist" IP addresses that are related to our external DNS servers in the DMZ?&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jan 2018 13:37:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-to-or-from/m-p/195131#M58331</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-01-15T13:37:15Z</dc:date>
    </item>
    <item>
      <title>Re: Zone Protection - to or from</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-to-or-from/m-p/195132#M58332</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18719"&gt;@jdprovine&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Correct. I would start with DoS profiles around public facing DMZ servers and then move towards Zone Protection once DoS profiles are properly configured.&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can whitelist addresses within DoS profiles by using the 'negate' option when you actually build out the DoS Policies. While I know there is a feature request for it, there is not currently a way to exclude addresses from Zone Protection profiles.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jan 2018 13:38:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-to-or-from/m-p/195132#M58332</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-01-15T13:38:59Z</dc:date>
    </item>
  </channel>
</rss>

