<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How security policy - intrazone works? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-security-policy-intrazone-works/m-p/222121#M63892</link>
    <description>&lt;P&gt;Nice pop from Mr Reaper...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/General-Topics/Intrazone-Rules/m-p/147789#M49440" target="_blank"&gt;https://live.paloaltonetworks.com/t5/General-Topics/Intrazone-Rules/m-p/147789#M49440&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 13 Jul 2018 04:58:10 GMT</pubDate>
    <dc:creator>Mick_Ball</dc:creator>
    <dc:date>2018-07-13T04:58:10Z</dc:date>
    <item>
      <title>How security policy - intrazone works?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-security-policy-intrazone-works/m-p/222112#M63889</link>
      <description>&lt;P&gt;Trying to use a Security policy with type intrazone and action is Deny (any application &amp;amp; service).&lt;/P&gt;&lt;P&gt;Target is to block all communication within the same zone (subnet). Such as ping, file share (smb), ftp, etc.&lt;/P&gt;&lt;P&gt;The layer3 interface and the computers were connected to a unmanaged switch.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But the outcome is only the gateway (layer3 interface) cannot be contact. All the computers can still comunicate with each other.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Jul 2018 02:05:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-security-policy-intrazone-works/m-p/222112#M63889</guid>
      <dc:creator>jeremylo</dc:creator>
      <dc:date>2018-07-13T02:05:45Z</dc:date>
    </item>
    <item>
      <title>Re: How security policy - intrazone works?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-security-policy-intrazone-works/m-p/222120#M63891</link>
      <description>&lt;P&gt;Your devices are on the same broadcast domain so they do not need to pass through the PA interface to communicate with each other.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;search this site for “intrazone”.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Jul 2018 04:55:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-security-policy-intrazone-works/m-p/222120#M63891</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-07-13T04:55:32Z</dc:date>
    </item>
    <item>
      <title>Re: How security policy - intrazone works?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-security-policy-intrazone-works/m-p/222121#M63892</link>
      <description>&lt;P&gt;Nice pop from Mr Reaper...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/General-Topics/Intrazone-Rules/m-p/147789#M49440" target="_blank"&gt;https://live.paloaltonetworks.com/t5/General-Topics/Intrazone-Rules/m-p/147789#M49440&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Jul 2018 04:58:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-security-policy-intrazone-works/m-p/222121#M63892</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-07-13T04:58:10Z</dc:date>
    </item>
    <item>
      <title>Re: How security policy - intrazone works?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-security-policy-intrazone-works/m-p/222239#M63925</link>
      <description>&lt;P&gt;Hosts on the same subnet&amp;nbsp;never see the firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Intrazone&amp;nbsp;seperates different subnets from each other, and requires that the firewall is the Gateway for these subnets.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Jul 2018 15:27:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-security-policy-intrazone-works/m-p/222239#M63925</guid>
      <dc:creator>RobinClayton</dc:creator>
      <dc:date>2018-07-13T15:27:51Z</dc:date>
    </item>
    <item>
      <title>Re: How security policy - intrazone works?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-security-policy-intrazone-works/m-p/222254#M63926</link>
      <description>&lt;P&gt;You could segregate traffic within the same subnet using L2 or vwire interfaces and inspect the traffic using intra-zone rules.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Jul 2018 16:12:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-security-policy-intrazone-works/m-p/222254#M63926</guid>
      <dc:creator>JoeAndreini</dc:creator>
      <dc:date>2018-07-13T16:12:17Z</dc:date>
    </item>
    <item>
      <title>Re: How security policy - intrazone works?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-security-policy-intrazone-works/m-p/222338#M63950</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/83021"&gt;@JoeAndreini&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;You could segregate traffic within the same subnet using L2 or vwire interfaces and inspect the traffic using intra-zone rules.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Hello JoeAndreini,&lt;/P&gt;&lt;P&gt;This seems impractical. I'll have huge workload to assign each computer to has its own L2 interface.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jul 2018 01:35:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-security-policy-intrazone-works/m-p/222338#M63950</guid>
      <dc:creator>jeremylo</dc:creator>
      <dc:date>2018-07-16T01:35:03Z</dc:date>
    </item>
  </channel>
</rss>

