<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Urgent - Port Block Help in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/urgent-port-block-help/m-p/204175#M60086</link>
    <description>&lt;P&gt;@jsalmans, &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That's fixed it, thank you both. Great help.&lt;/P&gt;&lt;P&gt;It makes perfect sense now I have seen my mistake!&lt;/P&gt;</description>
    <pubDate>Wed, 07 Mar 2018 20:23:23 GMT</pubDate>
    <dc:creator>sorrell</dc:creator>
    <dc:date>2018-03-07T20:23:23Z</dc:date>
    <item>
      <title>Urgent - Port Block Help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/urgent-port-block-help/m-p/204050#M60051</link>
      <description>&lt;P&gt;Hi All, we are trying to implement a security profile to block port 445.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Universal, source any/any, dest any/any, application unchecked, service port 445.&lt;/P&gt;&lt;P&gt;The profile is near the top of the list of profiles (above the outbound traffic profile).&lt;/P&gt;&lt;P&gt;For reasons unknown we are still seeing entries in the traffic log when we filter on:-&lt;/P&gt;&lt;P&gt;( port.dst eq 445 ) and ( action eq allow )&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sec Profile below:-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Line8&lt;/P&gt;&lt;P&gt;"Port Blocks" {&lt;BR /&gt;from any;&lt;BR /&gt;source any;&lt;BR /&gt;source-region none;&lt;BR /&gt;to any;&lt;BR /&gt;destination any;&lt;BR /&gt;destination-region none;&lt;BR /&gt;user any;&lt;BR /&gt;category any;&lt;BR /&gt;application/service any/tcp/445/445;&lt;BR /&gt;action deny;&lt;BR /&gt;icmp-unreachable: no&lt;BR /&gt;terminal no;&lt;BR /&gt;}&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Line 53 (Outbound Traffic)&lt;/P&gt;&lt;P&gt;"L3-MPLS to L3-Untrust" {&lt;BR /&gt;from L3-MPLS-Trust;&lt;BR /&gt;source any;&lt;BR /&gt;source-region none;&lt;BR /&gt;to L3-Untrust;&lt;BR /&gt;destination any;&lt;BR /&gt;destination-region none;&lt;BR /&gt;user any;&lt;BR /&gt;category any;&lt;BR /&gt;application/service any/any/any/any;&lt;BR /&gt;action allow;&lt;BR /&gt;icmp-unreachable: no&lt;BR /&gt;terminal yes;&lt;BR /&gt;}&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Traffic logs below.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class="x-panel-tl"&gt;&lt;DIV class="x-panel-tr"&gt;&lt;DIV class="x-panel-tc"&gt;&lt;DIV class="x-panel-header x-panel-header-noborder x-unselectable"&gt;&lt;SPAN class="x-panel-header-text"&gt;General&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="x-panel-bwrap"&gt;&lt;DIV class="x-panel-ml"&gt;&lt;DIV class="x-panel-mr"&gt;&lt;DIV class="x-panel-mc"&gt;&lt;DIV class=" x-column-layout-ct"&gt;&lt;DIV class="x-column-inner"&gt;&lt;DIV class=" x-form-label-left x-column"&gt;&lt;DIV class=" x-panel lightgrey undefined pan_widget x-grid-panel"&gt;&lt;DIV class="x-panel-bwrap"&gt;&lt;DIV class="x-panel-body x-panel-body-noheader"&gt;&lt;DIV class="x-grid3"&gt;&lt;DIV class="x-grid3-viewport"&gt;&lt;DIV class="x-grid3-scroller"&gt;&lt;DIV class="x-grid3-body"&gt;&lt;DIV class="x-grid3-row  x-grid3-row-first "&gt;&lt;TABLE border="0" cellspacing="0" cellpadding="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-id2"&gt;Session ID&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-3"&gt;33850521&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;DIV class="x-grid3-row "&gt;&lt;TABLE border="0" cellspacing="0" cellpadding="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-id2"&gt;Action&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-3"&gt;allow&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;DIV class="x-grid3-row "&gt;&lt;TABLE border="0" cellspacing="0" cellpadding="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-id2"&gt;Action Source&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-3"&gt;from-policy&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;DIV class="x-grid3-row "&gt;&lt;TABLE border="0" cellspacing="0" cellpadding="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-id2"&gt;Application&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-3"&gt;ms-ds-smb-base&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;DIV class="x-grid3-row "&gt;&lt;TABLE border="0" cellspacing="0" cellpadding="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-id2"&gt;Rule&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-3"&gt;L3-MPLS-Trust to L3-Untrust&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;DIV class="x-grid3-row "&gt;&lt;TABLE border="0" cellspacing="0" cellpadding="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-id2"&gt;Session End Reason&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-3"&gt;tcp-fin&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;DIV class="x-grid3-row "&gt;&lt;TABLE border="0" cellspacing="0" cellpadding="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-id2"&gt;Category&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-3"&gt;any&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;DIV class="x-grid3-row "&gt;&lt;TABLE border="0" cellspacing="0" cellpadding="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-id2"&gt;Virtual System&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-3"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;DIV class="x-grid3-row "&gt;&lt;TABLE border="0" cellspacing="0" cellpadding="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-id2"&gt;Device SN&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-3"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;DIV class="x-grid3-row "&gt;&lt;TABLE border="0" cellspacing="0" cellpadding="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-id2"&gt;IP Protocol&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-3"&gt;tcp&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;DIV class="x-grid3-row "&gt;&lt;TABLE border="0" cellspacing="0" cellpadding="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-id2"&gt;Log Action&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-3"&gt;LFP-Default&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;DIV class="x-grid3-row "&gt;&lt;TABLE border="0" cellspacing="0" cellpadding="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-id2"&gt;Generated Time&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-3"&gt;2018/03/07 10:14:04&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;DIV class="x-grid3-row "&gt;&lt;TABLE border="0" cellspacing="0" cellpadding="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-id2"&gt;Start Time&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-3"&gt;2018/03/07 10:13:47&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;DIV class="x-grid3-row "&gt;&lt;TABLE border="0" cellspacing="0" cellpadding="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-id2"&gt;Receive Time&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-3"&gt;2018/03/07 10:14:04&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;DIV class="x-grid3-row  x-grid3-row-last "&gt;&lt;TABLE border="0" cellspacing="0" cellpadding="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-id2"&gt;Elapsed Time(sec)&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-3"&gt;15&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="x-grid3-row  x-grid3-row-first "&gt;&lt;TABLE border="0" cellspacing="0" cellpadding="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-id2"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;DIV class="x-panel-tl"&gt;&lt;DIV class="x-panel-tr"&gt;&lt;DIV class="x-panel-tc"&gt;&lt;DIV class="x-panel-header x-panel-header-noborder x-unselectable"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="x-panel-header x-panel-header-noborder x-unselectable"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="x-panel-header x-panel-header-noborder x-unselectable"&gt;&lt;SPAN class="x-panel-header-text"&gt;Source&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="x-panel-bwrap"&gt;&lt;DIV class="x-panel-ml"&gt;&lt;DIV class="x-panel-mr"&gt;&lt;DIV class="x-panel-mc"&gt;&lt;DIV class=" x-column-layout-ct"&gt;&lt;DIV class="x-column-inner"&gt;&lt;DIV class=" x-form-label-left x-column"&gt;&lt;DIV class=" x-panel lightgrey undefined pan_widget x-grid-panel"&gt;&lt;DIV class="x-panel-bwrap"&gt;&lt;DIV class="x-panel-body x-panel-body-noheader"&gt;&lt;DIV class="x-grid3"&gt;&lt;DIV class="x-grid3-viewport"&gt;&lt;DIV class="x-grid3-scroller"&gt;&lt;DIV class="x-grid3-body"&gt;&lt;DIV class="x-grid3-row  x-grid3-row-first "&gt;&lt;TABLE border="0" cellspacing="0" cellpadding="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-id2"&gt;User&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-3"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;DIV class="x-grid3-row "&gt;&lt;TABLE border="0" cellspacing="0" cellpadding="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-id2"&gt;Address&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-3"&gt;10.48.237.205&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;DIV class="x-grid3-row "&gt;&lt;TABLE border="0" cellspacing="0" cellpadding="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-id2"&gt;Country&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-3"&gt;10.0.0.0-10.255.255.255&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;DIV class="x-grid3-row "&gt;&lt;TABLE border="0" cellspacing="0" cellpadding="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-id2"&gt;Port&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-3"&gt;59165&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;DIV class="x-grid3-row "&gt;&lt;TABLE border="0" cellspacing="0" cellpadding="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-id2"&gt;Zone&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-3"&gt;L3-MPLS-Trust&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;DIV class="x-grid3-row "&gt;&lt;TABLE border="0" cellspacing="0" cellpadding="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-id2"&gt;Interface&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-3"&gt;ethernet1/1&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;&lt;DIV class="x-grid3-row  x-grid3-row-over"&gt;&lt;DIV class="x-panel-tl"&gt;&lt;DIV class="x-panel-tr"&gt;&lt;DIV class="x-panel-tc"&gt;&lt;DIV class="x-panel-header x-panel-header-noborder x-unselectable"&gt;&lt;SPAN class="x-panel-header-text"&gt;Destination&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="x-panel-bwrap"&gt;&lt;DIV class="x-panel-ml"&gt;&lt;DIV class="x-panel-mr"&gt;&lt;DIV class="x-panel-mc"&gt;&lt;DIV class=" x-column-layout-ct"&gt;&lt;DIV class="x-column-inner"&gt;&lt;DIV class=" x-form-label-left x-column"&gt;&lt;DIV class=" x-panel lightgrey undefined pan_widget x-grid-panel"&gt;&lt;DIV class="x-panel-bwrap"&gt;&lt;DIV class="x-panel-body x-panel-body-noheader"&gt;&lt;DIV class="x-grid3"&gt;&lt;DIV class="x-grid3-viewport"&gt;&lt;DIV class="x-grid3-scroller"&gt;&lt;DIV class="x-grid3-body"&gt;&lt;DIV class="x-grid3-row  x-grid3-row-first "&gt;&lt;TABLE border="0" cellspacing="0" cellpadding="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-id2"&gt;User&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-3"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;DIV class="x-grid3-row "&gt;&lt;TABLE border="0" cellspacing="0" cellpadding="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-id2"&gt;Address&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-3"&gt;191.5.106.238&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;DIV class="x-grid3-row "&gt;&lt;TABLE border="0" cellspacing="0" cellpadding="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-id2"&gt;Country&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-3"&gt;Brazil&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;DIV class="x-grid3-row "&gt;&lt;TABLE border="0" cellspacing="0" cellpadding="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-id2"&gt;Port&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-3"&gt;445&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;DIV class="x-grid3-row "&gt;&lt;TABLE border="0" cellspacing="0" cellpadding="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-id2"&gt;Zone&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-3"&gt;L3-Untrust&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;DIV class="x-grid3-row "&gt;&lt;TABLE border="0" cellspacing="0" cellpadding="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-id2"&gt;Interface&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-3"&gt;ethernet1/12.100&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;DIV class="x-grid3-row "&gt;&lt;TABLE border="0" cellspacing="0" cellpadding="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-id2"&gt;NAT IP&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-3"&gt;191.5.106.238&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;DIV class="x-grid3-row  x-grid3-row-last "&gt;&lt;TABLE border="0" cellspacing="0" cellpadding="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-id2"&gt;NAT Port&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-3"&gt;445&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can anyone please suggest what we have overlooked?&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 07 Mar 2018 13:53:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/urgent-port-block-help/m-p/204050#M60051</guid>
      <dc:creator>sorrell</dc:creator>
      <dc:date>2018-03-07T13:53:15Z</dc:date>
    </item>
    <item>
      <title>Re: Urgent - Port Block Help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/urgent-port-block-help/m-p/204071#M60053</link>
      <description>&lt;P&gt;It looks like you've posted a traffic log but can you also post some screencaps of the rules involved?&amp;nbsp; Both the "L3-MPLS-Trust to L3-Untrust" as well as the rule you've put in place to block 445.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Mar 2018 13:38:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/urgent-port-block-help/m-p/204071#M60053</guid>
      <dc:creator>jsalmans</dc:creator>
      <dc:date>2018-03-07T13:38:11Z</dc:date>
    </item>
    <item>
      <title>Re: Urgent - Port Block Help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/urgent-port-block-help/m-p/204076#M60056</link>
      <description>&lt;P&gt;Hi - Original post updated, thanks&lt;/P&gt;</description>
      <pubDate>Wed, 07 Mar 2018 13:53:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/urgent-port-block-help/m-p/204076#M60056</guid>
      <dc:creator>sorrell</dc:creator>
      <dc:date>2018-03-07T13:53:49Z</dc:date>
    </item>
    <item>
      <title>Re: Urgent - Port Block Help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/urgent-port-block-help/m-p/204078#M60057</link>
      <description>&lt;P&gt;I'm not used to looking at this from the CLI, so forgive me if I have this incorrect, but it looks like your service you've configured for TCP 445 is looking for source AND destination 445?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you'll notice, your source in your logs is coming from a different port.&amp;nbsp; I'm guessing this is why you aren't matching.&amp;nbsp; I'd try modifying the TCP 445 service to only include destination port (leave source port blank) and see if that works.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;*edit* A destination only service would look something like:&amp;nbsp;&amp;nbsp; any/tcp/any/445&lt;/P&gt;</description>
      <pubDate>Wed, 07 Mar 2018 14:06:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/urgent-port-block-help/m-p/204078#M60057</guid>
      <dc:creator>jsalmans</dc:creator>
      <dc:date>2018-03-07T14:06:25Z</dc:date>
    </item>
    <item>
      <title>Re: Urgent - Port Block Help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/urgent-port-block-help/m-p/204081#M60058</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/83498"&gt;@sorrell&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/39461"&gt;@jsalmans&lt;/a&gt;&amp;nbsp;is currect, the rule that you have listed wouldn't match because you wouldn't have a&amp;nbsp;&lt;EM&gt;source&lt;/EM&gt; port of 445 as specified. One would usually just look for the destination port of 445 if this is something that you are looking to do. That would look like this to actually get it to build out currectly from the CLI.&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;configure
set rulebase security rules "Port Block" from any source any to any destination any application any service tcp-445 action deny icmp-unreachable no 
move rulebase security rules "Port Block" before "L3-MPLS to L3-Untrust" 
delete rulebase security rules "Port Blocks" &lt;/PRE&gt;&lt;P&gt;This would get rid of the malformed "Port Blocks" rule, configure a proper "Port Block" policy (assumes that the service configured is tcp-445), moves the new "Port Block" rule above your "L3-MPLS to Untrust" rule.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Mar 2018 14:40:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/urgent-port-block-help/m-p/204081#M60058</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-03-07T14:40:47Z</dc:date>
    </item>
    <item>
      <title>Re: Urgent - Port Block Help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/urgent-port-block-help/m-p/204175#M60086</link>
      <description>&lt;P&gt;@jsalmans, &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That's fixed it, thank you both. Great help.&lt;/P&gt;&lt;P&gt;It makes perfect sense now I have seen my mistake!&lt;/P&gt;</description>
      <pubDate>Wed, 07 Mar 2018 20:23:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/urgent-port-block-help/m-p/204175#M60086</guid>
      <dc:creator>sorrell</dc:creator>
      <dc:date>2018-03-07T20:23:23Z</dc:date>
    </item>
  </channel>
</rss>

