<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: New Feature request or ? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/new-feature-request-or/m-p/231162#M66370</link>
    <description>&lt;P&gt;Don't think i have worded it properly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want to add a policy say at the top that does match but doesn't allow the packet - just matches and say marks it or logs it . but then the packet/ stream still get evaluated later.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 17 Sep 2018 21:50:13 GMT</pubDate>
    <dc:creator>Alex_Samad</dc:creator>
    <dc:date>2018-09-17T21:50:13Z</dc:date>
    <item>
      <title>New Feature request or ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/new-feature-request-or/m-p/230979#M66335</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would like to have apolicy that just logs and does nothing else - ie the packet keeps getting evaluated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;some times I want to know there is packet there but not process it with that line.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can this be done already ?&lt;/P&gt;</description>
      <pubDate>Sun, 16 Sep 2018 10:03:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/new-feature-request-or/m-p/230979#M66335</guid>
      <dc:creator>Alex_Samad</dc:creator>
      <dc:date>2018-09-16T10:03:42Z</dc:date>
    </item>
    <item>
      <title>Re: New Feature request or ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/new-feature-request-or/m-p/231038#M66345</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/62286"&gt;@Alex_Samad&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Policies are always evaluated.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm guessing you're looking for a tap interface :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Community-Blog/What-s-a-TAP-interface-and-what-can-it-do/ba-p/160019" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Community-Blog/What-s-a-TAP-interface-and-what-can-it-do/ba-p/160019&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If this isn't what you're looking for then I'd recommend filing a feature request.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers !&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Mon, 17 Sep 2018 12:15:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/new-feature-request-or/m-p/231038#M66345</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2018-09-17T12:15:39Z</dc:date>
    </item>
    <item>
      <title>Re: New Feature request or ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/new-feature-request-or/m-p/231092#M66352</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/62286"&gt;@Alex_Samad&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;some times I want to know there is packet there but not process it with that line.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;What do you mean exactly with that?&lt;/P&gt;&lt;P&gt;As &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11943"&gt;@kiwi&lt;/a&gt;&amp;nbsp;already wrote a TAP interface or a simple any any allow policy with an application override rule may be something for you...&lt;/P&gt;</description>
      <pubDate>Mon, 17 Sep 2018 15:07:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/new-feature-request-or/m-p/231092#M66352</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-09-17T15:07:55Z</dc:date>
    </item>
    <item>
      <title>Re: New Feature request or ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/new-feature-request-or/m-p/231162#M66370</link>
      <description>&lt;P&gt;Don't think i have worded it properly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want to add a policy say at the top that does match but doesn't allow the packet - just matches and say marks it or logs it . but then the packet/ stream still get evaluated later.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Sep 2018 21:50:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/new-feature-request-or/m-p/231162#M66370</guid>
      <dc:creator>Alex_Samad</dc:creator>
      <dc:date>2018-09-17T21:50:13Z</dc:date>
    </item>
    <item>
      <title>Re: New Feature request or ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/new-feature-request-or/m-p/231169#M66374</link>
      <description>&lt;P&gt;Logging every new packet will likely flood you with logs that aren't really valuable, but you can do it. For each policy that will be evaluated, select "Log at session start" under the Actions tab in the security rule.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Every single new packet that gets installed as a new session will be logged before the rules themselves are processed. This will increase the load on the management plane, because of the extra logging. It will also reduce the number of completed logs you can store, since you're effectively logging everything twice.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What problem are you trying to solve?&amp;nbsp;Maybe your use case will help the community understand the goal, and get you there without using the policy approach you're attempting.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Sep 2018 22:27:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/new-feature-request-or/m-p/231169#M66374</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2018-09-17T22:27:24Z</dc:date>
    </item>
    <item>
      <title>Re: New Feature request or ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/new-feature-request-or/m-p/231174#M66378</link>
      <description>&lt;P&gt;Sorry that seems a but silly I already log all polices so currently each packet creates 1 log entry. so if I wasn stupid and added any any log then I would double the amount of logging.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;sorry what extra logging.&amp;nbsp; each packet is processed as it is already&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For example in iptables I can have chains that process lines and just log them. so lets say I want to see all the packets from a specif host that meet a specific criteria. but I don't want to allow it I just want to register it in the logs and then have the normal process of the rules happen&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A&lt;/P&gt;</description>
      <pubDate>Mon, 17 Sep 2018 23:59:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/new-feature-request-or/m-p/231174#M66378</guid>
      <dc:creator>Alex_Samad</dc:creator>
      <dc:date>2018-09-17T23:59:23Z</dc:date>
    </item>
    <item>
      <title>Re: New Feature request or ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/new-feature-request-or/m-p/231556#M66483</link>
      <description>&lt;P&gt;Lets say for example I want to capture all traffic from a specific location to a specific dest.. but I don't want the rule to allow, just to log. I would place this at the top of the policies&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Sep 2018 00:58:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/new-feature-request-or/m-p/231556#M66483</guid>
      <dc:creator>Alex_Samad</dc:creator>
      <dc:date>2018-09-20T00:58:02Z</dc:date>
    </item>
    <item>
      <title>Re: New Feature request or ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/new-feature-request-or/m-p/231577#M66488</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/62286"&gt;@Alex_Samad&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Not possible in the way you're describing it as far as I know. &amp;nbsp;The rule will always be evaluated as per the action you configured on it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'd use the TAP solution as proposed earlier or a 3rd party solution like SNORT could maybe help you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers !&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Sep 2018 07:23:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/new-feature-request-or/m-p/231577#M66488</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2018-09-20T07:23:17Z</dc:date>
    </item>
    <item>
      <title>Re: New Feature request or ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/new-feature-request-or/m-p/231578#M66489</link>
      <description>&lt;P&gt;Yep I understand its not possible now.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thats why i raised this.&amp;nbsp; the action could be to continue and log ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But I get the impression its not something people might want &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Sep 2018 07:27:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/new-feature-request-or/m-p/231578#M66489</guid>
      <dc:creator>Alex_Samad</dc:creator>
      <dc:date>2018-09-20T07:27:26Z</dc:date>
    </item>
    <item>
      <title>Re: New Feature request or ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/new-feature-request-or/m-p/231579#M66490</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/62286"&gt;@Alex_Samad&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I can see how this can be usefull &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It wouldn't hurt asking your local SE to file a feature request for this.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If it gets enough votes then it might be added to a future release.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers !&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Thu, 20 Sep 2018 07:30:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/new-feature-request-or/m-p/231579#M66490</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2018-09-20T07:30:25Z</dc:date>
    </item>
  </channel>
</rss>

