<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Rule base documentation in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/rule-base-documentation/m-p/202362#M59718</link>
    <description>&lt;P&gt;PA Best practice says you should have your rules documented on the rules and some where other than your rule base. Anyone doing that? and if so how&lt;/P&gt;</description>
    <pubDate>Mon, 26 Feb 2018 20:37:36 GMT</pubDate>
    <dc:creator>jdprovine</dc:creator>
    <dc:date>2018-02-26T20:37:36Z</dc:date>
    <item>
      <title>Rule base documentation</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rule-base-documentation/m-p/202362#M59718</link>
      <description>&lt;P&gt;PA Best practice says you should have your rules documented on the rules and some where other than your rule base. Anyone doing that? and if so how&lt;/P&gt;</description>
      <pubDate>Mon, 26 Feb 2018 20:37:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rule-base-documentation/m-p/202362#M59718</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-02-26T20:37:36Z</dc:date>
    </item>
    <item>
      <title>Re: Rule base documentation</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rule-base-documentation/m-p/202380#M59721</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18719"&gt;@jdprovine&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We do this in our Changemanagement. Every Rule (Name,srczone,srcaddress,srcuser,dstzone,dstaddress,ports,apps,URL category,Log forwarding, security profiles) and specially every rulechange is documented there and depending on the actual Firewall the change also needs so be approved by different Security officers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Remo&lt;/P&gt;</description>
      <pubDate>Mon, 26 Feb 2018 21:36:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rule-base-documentation/m-p/202380#M59721</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-02-26T21:36:38Z</dc:date>
    </item>
    <item>
      <title>Re: Rule base documentation</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rule-base-documentation/m-p/202381#M59722</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yeah that would be great to do change management LOL, unfortunately we do not.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Feb 2018 21:39:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rule-base-documentation/m-p/202381#M59722</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-02-26T21:39:42Z</dc:date>
    </item>
    <item>
      <title>Re: Rule base documentation</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rule-base-documentation/m-p/202386#M59723</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;What we did was go through the entire firewall settings and approved the base. Then any firewall change requires approved chagne management. At the end of each month I have to review the changes with our security officer and justify them. This is how we get around certification and changes that are forced onto us by the customers.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For security reasons we do not keep like an excel spreadsheet of all the rules. That said, you can export the rules into a CSV.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://indeni.com/how-to-export-palo-alto-networks-firewalls/" target="_blank"&gt;https://indeni.com/how-to-export-palo-alto-networks-firewalls/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just a thought.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Feb 2018 22:16:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rule-base-documentation/m-p/202386#M59723</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-02-26T22:16:02Z</dc:date>
    </item>
    <item>
      <title>Re: Rule base documentation</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rule-base-documentation/m-p/202535#M59746</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I actually exported the configuration change logs to a csv and we backup the running config dail&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2018 14:04:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rule-base-documentation/m-p/202535#M59746</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-02-27T14:04:02Z</dc:date>
    </item>
    <item>
      <title>Re: Rule base documentation</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rule-base-documentation/m-p/202539#M59749</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18719"&gt;@jdprovine&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;So what I would recommend doing is having a bash or PowerShell script that pulls the running-config.xml from the firewall on a nightly basis, and saves it to a backed-up location. In this instance you would have a backup of your entire configuration and if need be, you can easily get replacement equipment up and running quickly.&amp;nbsp;&lt;/P&gt;&lt;P&gt;If need be I can share an example PowerShell script.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2018 14:22:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rule-base-documentation/m-p/202539#M59749</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-02-27T14:22:15Z</dc:date>
    </item>
    <item>
      <title>Re: Rule base documentation</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rule-base-documentation/m-p/202544#M59753</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&lt;/P&gt;&lt;P&gt;I would a appreciate you sharing some script&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2018 14:28:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rule-base-documentation/m-p/202544#M59753</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-02-27T14:28:06Z</dc:date>
    </item>
    <item>
      <title>Re: Rule base documentation</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rule-base-documentation/m-p/202550#M59756</link>
      <description>&lt;PRE&gt;$netAssembly = [Reflection.Assembly]::GetAssembly([System.Net.Configuration.SettingsSection])

if($netAssembly)
{
    $bindingFlags = [Reflection.BindingFlags] "Static,GetProperty,NonPublic"
    $settingsType = $netAssembly.GetType("System.Net.Configuration.SettingsSectionInternal")

    $instance = $settingsType.InvokeMember("Section", $bindingFlags, $null, $null, @())

    if($instance)
    {
        $bindingFlags = "NonPublic","Instance"
        $useUnsafeHeaderParsingField = $settingsType.GetField("useUnsafeHeaderParsing", $bindingFlags)

        if($useUnsafeHeaderParsingField)
        {
          $useUnsafeHeaderParsingField.SetValue($instance, $true)
        }
    }
}
[System.Net.ServicePointManager]::ServerCertificateValidationCallback = {$true}
[System.Net.ServicePointManager]::SecurityProtocol = [System.Net.SecurityProtocolType]::Tls12
$ConfigTime = Get-Date -Format "MM-dd-yyyy"
# Config File Logation
$ConfigFile = '\\fs1\Enterprise\Documentation\Network\Palo Alto\PA-3020 Backups\'+"running-config-"+$ConfigTime+".xml"
$wc = New-Object System.Net.WebClient
# Takes the running-config and saves it to the S drive.
$src=$wc.DownloadString("https://10.191.136.7/api/?type=export&amp;amp;category=configuration&amp;amp;key=*key*") | Out-File $ConfigFile
# Attempts to remove the commit lock if one is held by bpry.
$src=$wc.DownloadString("https://10.191.136.7/api/?type=op&amp;amp;cmd=&amp;lt;request&amp;gt;&amp;lt;commit-lock&amp;gt;&amp;lt;remove&amp;gt;&amp;lt;admin&amp;gt;bpry&amp;lt;/admin&amp;gt;&amp;lt;/remove&amp;gt;&amp;lt;/commit-lock&amp;gt;&amp;lt;/request&amp;gt;&amp;amp;key=*key*")
# Commits the current canidate-config.
$src=$wc.DownloadString("https://10.191.136.7/api/?type=commit&amp;amp;cmd=&amp;lt;commit&amp;gt;&amp;lt;/commit&amp;gt;&amp;amp;key=*key*")

&lt;/PRE&gt;&lt;P&gt;Obviously you would replace 10.191.136.7 with whatever IP your firewall is on, and replace the destination of $ConfigFile with whatever location you are going to save to. The *key* is going to simply be your API key which you'll need to generate if you haven't done so already.&amp;nbsp;&lt;/P&gt;&lt;P&gt;What this script will do is take a backup of the running-config with the first API call; then it removed a commit lock that I would potentially have in place (I have three lines for removing possible commit locks) and then it simply commits the current canidate-config.&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can simply issue the first line if you simply want a backup to be taken; however I use the entire script as a sort of 'scheduled commit' so that all of the changes that I've made throughout the day simply take effect at 10pm; you simply need to ensure that your team knows about this so that they don't leave something half-finished. If the config isn't valid obviously this will fail automatically during the commit process, but I wouldn't chance that.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2018 15:18:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rule-base-documentation/m-p/202550#M59756</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-02-27T15:18:02Z</dc:date>
    </item>
    <item>
      <title>Re: Rule base documentation</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rule-base-documentation/m-p/202651#M59767</link>
      <description>&lt;P&gt;What is the goal now? Documentation or backup &lt;span class="lia-unicode-emoji" title=":face_with_tongue:"&gt;😛&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2018 22:41:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rule-base-documentation/m-p/202651#M59767</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-02-27T22:41:16Z</dc:date>
    </item>
    <item>
      <title>Re: Rule base documentation</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rule-base-documentation/m-p/202732#M59780</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&lt;/P&gt;&lt;P&gt;For me it is to keep track of who made changes to the firewall and when.&amp;nbsp; We have a user or two who do not communicate when they make changes and why they are doing it.&amp;nbsp; We also do not have a change management process,not good. So I guess I am doing a little of both backing them up so I can review what has been done.&amp;nbsp; Sometimes the logs roll over and I loose the history.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Feb 2018 13:30:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rule-base-documentation/m-p/202732#M59780</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-02-28T13:30:31Z</dc:date>
    </item>
    <item>
      <title>Re: Rule base documentation</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rule-base-documentation/m-p/202795#M59804</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I can see how that can be a real pain. For the time being, unless you have a lot of changes, you can refer to the Configuration logs?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Monitor tab -&amp;gt; Logs-&amp;gt; Configuration&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That should let you know who made what changes. However a good change management policy should help out as well, expecially since there are many admins working in the systems.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can setup alerts to email you when changes are made.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Device tab -&amp;gt; Log Settings -&amp;gt; Configuration area.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers!&lt;/P&gt;</description>
      <pubDate>Wed, 28 Feb 2018 15:04:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rule-base-documentation/m-p/202795#M59804</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-02-28T15:04:37Z</dc:date>
    </item>
    <item>
      <title>Re: Rule base documentation</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rule-base-documentation/m-p/202801#M59806</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Yep I have started to export the config logs from monitor/configuration to maintain history. Though i also check those logs daily.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Feb 2018 15:18:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rule-base-documentation/m-p/202801#M59806</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-02-28T15:18:48Z</dc:date>
    </item>
    <item>
      <title>Re: Rule base documentation</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rule-base-documentation/m-p/202906#M59845</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18719"&gt;@jdprovine&lt;/a&gt;&lt;/P&gt;&lt;P&gt;This is bad when there is a security admin (you) needed to controll other admins. Do they know what what they have to do or is there maybe a conversation with the supervisor needed?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As mentionned by &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;you can configure alert emails when someone changes the configuration or limit these alert emails to the commit-log-events. This way you know at least when someone changed something. And as you then directly have the timestamp you can probably check the config logs more easily and find out what they changed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You may be also want to try a script that automatically pulls the config logs hourly/daily so this saves your time with the manual config-log-export-task.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Feb 2018 22:08:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rule-base-documentation/m-p/202906#M59845</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-02-28T22:08:14Z</dc:date>
    </item>
    <item>
      <title>Re: Rule base documentation</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rule-base-documentation/m-p/203017#M59859</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Well we have not change management in place so you can't hold people accountable for what you do not have rules concerning. I have heard for that last year that they want to put change management in place, I do think that would help&lt;/P&gt;</description>
      <pubDate>Thu, 01 Mar 2018 13:12:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rule-base-documentation/m-p/203017#M59859</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-03-01T13:12:54Z</dc:date>
    </item>
    <item>
      <title>Re: Rule base documentation</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rule-base-documentation/m-p/203386#M59922</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18719"&gt;@jdprovine&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ok, thats true. But you could also have some teaminternal guidelines that make it easier for all when they know what's been done and noone needs to waist time searching for a change which may resultet in something not working anymore.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11943"&gt;@kiwi&lt;/a&gt;&amp;nbsp;probably also read this topic &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt; ... and if not it's luck that he posted a blog post exactly about this config log topic and the basics on how to automate this here:&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/Community-Blog/The-Power-of-XML-API/ba-p/202789" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Community-Blog/The-Power-of-XML-API/ba-p/202789&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 03 Mar 2018 08:30:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rule-base-documentation/m-p/203386#M59922</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-03-03T08:30:51Z</dc:date>
    </item>
    <item>
      <title>Re: Rule base documentation</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rule-base-documentation/m-p/203532#M59959</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&lt;/P&gt;&lt;P&gt;I have written up guidelines and I cannot say that no one follows them but I think most people follow what they think is right and I am in no position to enforce anything&lt;/P&gt;</description>
      <pubDate>Mon, 05 Mar 2018 13:39:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rule-base-documentation/m-p/203532#M59959</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-03-05T13:39:33Z</dc:date>
    </item>
  </channel>
</rss>

