<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Best practice for applying list of IP's to a security policy. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/best-practice-for-applying-list-of-ip-s-to-a-security-policy/m-p/214336#M62294</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;If they are all in the same zone, then you wouldnt have to use IP's. Another thought would be to use subnets. You could download the XML config and add them in that way and then upload the XML back into your system.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just a few thoughts.&lt;/P&gt;</description>
    <pubDate>Tue, 15 May 2018 19:07:48 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2018-05-15T19:07:48Z</dc:date>
    <item>
      <title>Best practice for applying list of IP's to a security policy.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-practice-for-applying-list-of-ip-s-to-a-security-policy/m-p/214327#M62292</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm trying to identify what the best way of applying a list of datacenter IPs to one of our security policies.&amp;nbsp; The list has about 150 IP's and I'm apparently unable to paste the list of IP's into an address group as it gives me an error notice stating static "IP" is not a valid reference for all the IP's in the list.&amp;nbsp; Creating the options via GUI and CLI is an option it appears, but it seems really tedious having to generate the names and submit the entries.&amp;nbsp; I'm probably missing something though.&amp;nbsp; What's the best practice for this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 15 May 2018 18:13:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-practice-for-applying-list-of-ip-s-to-a-security-policy/m-p/214327#M62292</guid>
      <dc:creator>kahbernie</dc:creator>
      <dc:date>2018-05-15T18:13:39Z</dc:date>
    </item>
    <item>
      <title>Re: Best practice for applying list of IP's to a security policy.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-practice-for-applying-list-of-ip-s-to-a-security-policy/m-p/214336#M62294</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;If they are all in the same zone, then you wouldnt have to use IP's. Another thought would be to use subnets. You could download the XML config and add them in that way and then upload the XML back into your system.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just a few thoughts.&lt;/P&gt;</description>
      <pubDate>Tue, 15 May 2018 19:07:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-practice-for-applying-list-of-ip-s-to-a-security-policy/m-p/214336#M62294</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-05-15T19:07:48Z</dc:date>
    </item>
    <item>
      <title>Re: Best practice for applying list of IP's to a security policy.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-practice-for-applying-list-of-ip-s-to-a-security-policy/m-p/214343#M62295</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/88382"&gt;@kahbernie&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Personally I think&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;already mentioned the best possible solution, include them by directly modifying the XML and re-uploading it onto the box. Although it sounds like you could possibly benefit from putting these into a dynamic address-group and making it trigger on some sort of tag such as 'datacenter'. This allows you to quickly add members and remove them by simply creating the address object with the appropriate tag while maintaining the same security posture. Makes updating things a little bit smother as you only have to create/delete an address object instead of modifying a bunch of security policies.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 May 2018 19:37:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-practice-for-applying-list-of-ip-s-to-a-security-policy/m-p/214343#M62295</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-05-15T19:37:16Z</dc:date>
    </item>
    <item>
      <title>Re: Best practice for applying list of IP's to a security policy.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-practice-for-applying-list-of-ip-s-to-a-security-policy/m-p/214474#M62326</link>
      <description>&lt;P&gt;The option I've been presented with is to use an External Dynamic list from a file hosted on a server on our trusted zone.&amp;nbsp; This would essentially accomplish the same thing correct?&lt;/P&gt;</description>
      <pubDate>Wed, 16 May 2018 17:15:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-practice-for-applying-list-of-ip-s-to-a-security-policy/m-p/214474#M62326</guid>
      <dc:creator>kahbernie</dc:creator>
      <dc:date>2018-05-16T17:15:49Z</dc:date>
    </item>
    <item>
      <title>Re: Best practice for applying list of IP's to a security policy.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-practice-for-applying-list-of-ip-s-to-a-security-policy/m-p/214478#M62327</link>
      <description>&lt;P&gt;That was going to be my suggestion, if you have an internal webserver you can build an EDL.&amp;nbsp; The only advantage this has over the "internal" dynamic list using a tag is that to add or remove IP addresses you only need a text editor.&amp;nbsp; The disadvantage is you need a web server to host it.&lt;/P&gt;</description>
      <pubDate>Wed, 16 May 2018 17:58:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-practice-for-applying-list-of-ip-s-to-a-security-policy/m-p/214478#M62327</guid>
      <dc:creator>JoeAndreini</dc:creator>
      <dc:date>2018-05-16T17:58:48Z</dc:date>
    </item>
    <item>
      <title>Re: Best practice for applying list of IP's to a security policy.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-practice-for-applying-list-of-ip-s-to-a-security-policy/m-p/214479#M62328</link>
      <description>&lt;P&gt;Yes it should.&lt;/P&gt;</description>
      <pubDate>Wed, 16 May 2018 17:59:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-practice-for-applying-list-of-ip-s-to-a-security-policy/m-p/214479#M62328</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-05-16T17:59:01Z</dc:date>
    </item>
  </channel>
</rss>

