<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: To drop or deny in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/to-drop-or-deny/m-p/206903#M60684</link>
    <description>&lt;P&gt;yes there are many pages on this stuff...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we opted for similar to &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;.&lt;/P&gt;&lt;P&gt;untrust to trust... drop&lt;/P&gt;&lt;P&gt;trust to untrust, mostly drop but with a few overlapping policy denies for specific hosts and users&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;for trust to untrust diagnostics, deny (block all policy session start... not logging to paranormal) is a must, as and when required..&lt;/P&gt;&lt;P&gt;i prefer this to messing around with the default zone policies...&lt;/P&gt;</description>
    <pubDate>Thu, 22 Mar 2018 14:42:28 GMT</pubDate>
    <dc:creator>Mick_Ball</dc:creator>
    <dc:date>2018-03-22T14:42:28Z</dc:date>
    <item>
      <title>To drop or deny</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/to-drop-or-deny/m-p/206863#M60674</link>
      <description>&lt;P&gt;I found some best practices documentation on the fuel group site and they recommend drop over deny.&amp;nbsp; So I would be interested to see how people are configuring their fire wall more drops or denies and why?&lt;/P&gt;</description>
      <pubDate>Thu, 22 Mar 2018 13:24:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/to-drop-or-deny/m-p/206863#M60674</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-03-22T13:24:07Z</dc:date>
    </item>
    <item>
      <title>Re: To drop or deny</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/to-drop-or-deny/m-p/206900#M60682</link>
      <description>&lt;P&gt;A drop is silent, you simply discard the packet and don't tell anyone about it. This is great for most siatuations as you don't generate more traffic on your network and outsiders who may potentially be scanning you are non the wiser&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;A deny sends a notification to the sender that something happened and their packet was rejected&lt;/P&gt;
&lt;P&gt;This could be helpful in providing a 'friendly' user experience as some applications will be able to pop up an error message telling the user their connection was rejected (instead of timing out, causing the user to have to wait and possibly keep trying), and tell applications to stop trying to connect.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My inbound rules are all drop while my outbound ones are deny (for rules that only trigger on App-ID, eg. "block ftp", you can also pick from 'reset-client', 'reset-server' and 'reset-both' depending which ones are 'internal' and deserve a notification)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I wrote a couple things regarding this, fyi:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Tutorials/Configurable-Deny-Action/ta-p/76613" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Tutorials/Configurable-Deny-Action/ta-p/76613&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Featured-Articles/DotW-reset-server-reset-client-or-silent-drop/ta-p/77343" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Featured-Articles/DotW-reset-server-reset-client-or-silent-drop/ta-p/77343&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Mar 2018 14:21:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/to-drop-or-deny/m-p/206900#M60682</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-03-22T14:21:50Z</dc:date>
    </item>
    <item>
      <title>Re: To drop or deny</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/to-drop-or-deny/m-p/206902#M60683</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Don't fear the reaper !! So I guess it good for load on your firewall and stretches the days of logs out but could reduce information&lt;/P&gt;</description>
      <pubDate>Thu, 22 Mar 2018 14:41:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/to-drop-or-deny/m-p/206902#M60683</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-03-22T14:41:29Z</dc:date>
    </item>
    <item>
      <title>Re: To drop or deny</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/to-drop-or-deny/m-p/206903#M60684</link>
      <description>&lt;P&gt;yes there are many pages on this stuff...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we opted for similar to &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;.&lt;/P&gt;&lt;P&gt;untrust to trust... drop&lt;/P&gt;&lt;P&gt;trust to untrust, mostly drop but with a few overlapping policy denies for specific hosts and users&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;for trust to untrust diagnostics, deny (block all policy session start... not logging to paranormal) is a must, as and when required..&lt;/P&gt;&lt;P&gt;i prefer this to messing around with the default zone policies...&lt;/P&gt;</description>
      <pubDate>Thu, 22 Mar 2018 14:42:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/to-drop-or-deny/m-p/206903#M60684</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-03-22T14:42:28Z</dc:date>
    </item>
    <item>
      <title>Re: To drop or deny</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/to-drop-or-deny/m-p/206908#M60687</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Are you referring to the zone protection policies when you say default zone policies?&lt;/P&gt;</description>
      <pubDate>Thu, 22 Mar 2018 15:00:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/to-drop-or-deny/m-p/206908#M60687</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-03-22T15:00:48Z</dc:date>
    </item>
    <item>
      <title>Re: To drop or deny</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/to-drop-or-deny/m-p/206910#M60689</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18719"&gt;@jdprovine&lt;/a&gt;..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;No sorry...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the intrazone-default and interzone-default security policies .&lt;/P&gt;&lt;P&gt;you can overide these and enable logging but i prefer to use my own policy to "block all" from my test PC IP address.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if i see any traffic using this policy, then i know one of the many above it is not working properly.&lt;/P&gt;&lt;P&gt;if you get my drift...&lt;/P&gt;</description>
      <pubDate>Thu, 22 Mar 2018 15:08:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/to-drop-or-deny/m-p/206910#M60689</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-03-22T15:08:10Z</dc:date>
    </item>
    <item>
      <title>Re: To drop or deny</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/to-drop-or-deny/m-p/206961#M60717</link>
      <description>&lt;P&gt;Great info as always&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Mar 2018 18:01:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/to-drop-or-deny/m-p/206961#M60717</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-03-22T18:01:10Z</dc:date>
    </item>
  </channel>
</rss>

