<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: block IP's in same zone in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/block-ip-s-in-same-zone/m-p/233765#M67022</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18719"&gt;@jdprovine&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;It's essentially built out exactly the same as you would a normal security policy, the 'to' and 'from' are just going to be exactly the same.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17004iE05567F06F6B06CC/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;You can leave the rule type as universal or set it to intrazone, both would function the same.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 03 Oct 2018 20:33:47 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2018-10-03T20:33:47Z</dc:date>
    <item>
      <title>block IP's in same zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-ip-s-in-same-zone/m-p/233349#M66919</link>
      <description>&lt;P&gt;Is it possible or practical to block traffic between two server in the same firewall zone by designating the source IP from the server you want to block access to the server to the destination server indicated by IP&lt;/P&gt;</description>
      <pubDate>Tue, 02 Oct 2018 12:37:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-ip-s-in-same-zone/m-p/233349#M66919</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-10-02T12:37:37Z</dc:date>
    </item>
    <item>
      <title>Re: block IP's in same zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-ip-s-in-same-zone/m-p/233358#M66921</link>
      <description>&lt;P&gt;If the traffic is passingg through the firewall while staying in the same zone, you could create an intrazone policy to block the traffic. Are the servers on different subnets&amp;nbsp;and in the same zone?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Oct 2018 13:21:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-ip-s-in-same-zone/m-p/233358#M66921</guid>
      <dc:creator>rmfalconer</dc:creator>
      <dc:date>2018-10-02T13:21:55Z</dc:date>
    </item>
    <item>
      <title>Re: block IP's in same zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-ip-s-in-same-zone/m-p/233359#M66922</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/55733"&gt;@rmfalconer&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Different subnet same zones, that is why I thought I could name the source IP range that I didn't not want to have access to the specific IP's of the server I don't want them to have access to or from&lt;/P&gt;</description>
      <pubDate>Tue, 02 Oct 2018 13:29:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-ip-s-in-same-zone/m-p/233359#M66922</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-10-02T13:29:06Z</dc:date>
    </item>
    <item>
      <title>Re: block IP's in same zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-ip-s-in-same-zone/m-p/233368#M66930</link>
      <description>&lt;P&gt;As long as the traffic between these hosts passes through the firewall, then you should be able to create an intrazone rule to deny whatever you need.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Oct 2018 14:48:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-ip-s-in-same-zone/m-p/233368#M66930</guid>
      <dc:creator>rmfalconer</dc:creator>
      <dc:date>2018-10-02T14:48:22Z</dc:date>
    </item>
    <item>
      <title>Re: block IP's in same zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-ip-s-in-same-zone/m-p/233717#M66997</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/55733"&gt;@rmfalconer&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&lt;/P&gt;&lt;P&gt;How do you have to configure an intrazone rule?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Oct 2018 16:17:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-ip-s-in-same-zone/m-p/233717#M66997</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-10-03T16:17:35Z</dc:date>
    </item>
    <item>
      <title>Re: block IP's in same zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-ip-s-in-same-zone/m-p/233724#M67001</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;It would look something like this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(source zone) (source IP) (destination zone) (destination IP)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This way since they are different subnets and have to use the PAN as a gateway, you can create secutiy policies to distinguish traffic. I do this due to the amount of zones a PAN can have. This way I create one zone and subnet it out and use source and destination subnets.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that makes sense.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Oct 2018 16:43:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-ip-s-in-same-zone/m-p/233724#M67001</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-10-03T16:43:28Z</dc:date>
    </item>
    <item>
      <title>Re: block IP's in same zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-ip-s-in-same-zone/m-p/233728#M67003</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Yes that makes sense I thought I did that but I can still ping the server that I am trying to block access too&lt;/P&gt;</description>
      <pubDate>Wed, 03 Oct 2018 16:58:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-ip-s-in-same-zone/m-p/233728#M67003</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-10-03T16:58:56Z</dc:date>
    </item>
    <item>
      <title>Re: block IP's in same zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-ip-s-in-same-zone/m-p/233729#M67004</link>
      <description>&lt;P&gt;When you create the policy, make sure the type is 'intrazone'. Once you select the source zone, the destination zone selection is disabled.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Oct 2018 17:21:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-ip-s-in-same-zone/m-p/233729#M67004</guid>
      <dc:creator>rmfalconer</dc:creator>
      <dc:date>2018-10-03T17:21:21Z</dc:date>
    </item>
    <item>
      <title>Re: block IP's in same zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-ip-s-in-same-zone/m-p/233736#M67009</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/55733"&gt;@rmfalconer&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Where do you choose intrazone?&lt;/P&gt;</description>
      <pubDate>Wed, 03 Oct 2018 17:59:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-ip-s-in-same-zone/m-p/233736#M67009</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-10-03T17:59:17Z</dc:date>
    </item>
    <item>
      <title>Re: block IP's in same zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-ip-s-in-same-zone/m-p/233740#M67012</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/16998iD90F1DF046F83644/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Oct 2018 18:05:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-ip-s-in-same-zone/m-p/233740#M67012</guid>
      <dc:creator>rmfalconer</dc:creator>
      <dc:date>2018-10-03T18:05:38Z</dc:date>
    </item>
    <item>
      <title>Re: block IP's in same zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-ip-s-in-same-zone/m-p/233742#M67014</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/55733"&gt;@rmfalconer&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Do you have to be very specific? like&lt;/P&gt;&lt;P&gt;source - server 1 10.10.10.10&amp;nbsp;&lt;/P&gt;&lt;P&gt;Source zone - myhouse&lt;/P&gt;&lt;P&gt;destination - server 2 10.10.189.16&lt;/P&gt;&lt;P&gt;destination zone - myhouse&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And have you used this on your firewall? Also I if I read this correctly that if I have the rule type set to universal,which I do, it should cover both interzone and intrazone&lt;/P&gt;</description>
      <pubDate>Wed, 03 Oct 2018 18:55:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-ip-s-in-same-zone/m-p/233742#M67014</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-10-03T18:55:33Z</dc:date>
    </item>
    <item>
      <title>Re: block IP's in same zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-ip-s-in-same-zone/m-p/233765#M67022</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18719"&gt;@jdprovine&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;It's essentially built out exactly the same as you would a normal security policy, the 'to' and 'from' are just going to be exactly the same.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17004iE05567F06F6B06CC/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;You can leave the rule type as universal or set it to intrazone, both would function the same.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Oct 2018 20:33:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-ip-s-in-same-zone/m-p/233765#M67022</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-10-03T20:33:47Z</dc:date>
    </item>
    <item>
      <title>Re: block IP's in same zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-ip-s-in-same-zone/m-p/233767#M67024</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&lt;/P&gt;&lt;P&gt;From what read I was under the same impression.&amp;nbsp; i guess i could move my server to another security zone but thats not assurrance either without making sure of how everything is routed&amp;nbsp; and aggregated etc&lt;/P&gt;</description>
      <pubDate>Wed, 03 Oct 2018 20:36:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-ip-s-in-same-zone/m-p/233767#M67024</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-10-03T20:36:50Z</dc:date>
    </item>
    <item>
      <title>Re: block IP's in same zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-ip-s-in-same-zone/m-p/233948#M67064</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18719"&gt;@jdprovine&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;As for the IP's, no they do not have to be specific if you dont want then to be. I have a zone called DMZ, then I carve out subnets out of it. Since I have a DENY ALL rule before the built in allow intra zone traffic, it will automatically be blocked and then I can chose what is allowed to talk to what. So instead of using specific IP's you can use Subnets.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;source zone = DMZ&lt;/P&gt;&lt;P&gt;source IP = 192.168.55.0/29&lt;/P&gt;&lt;P&gt;destination zone = DMZ&lt;/P&gt;&lt;P&gt;destination IP = 192.168.55.96/29&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that makes sense.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Oct 2018 16:00:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-ip-s-in-same-zone/m-p/233948#M67064</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-10-04T16:00:06Z</dc:date>
    </item>
    <item>
      <title>Re: block IP's in same zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-ip-s-in-same-zone/m-p/234395#M67190</link>
      <description>&lt;P&gt;Just checking.... But the server Default gateways are the firewall&amp;nbsp;not something else?&lt;/P&gt;</description>
      <pubDate>Mon, 08 Oct 2018 11:43:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-ip-s-in-same-zone/m-p/234395#M67190</guid>
      <dc:creator>RobinClayton</dc:creator>
      <dc:date>2018-10-08T11:43:11Z</dc:date>
    </item>
    <item>
      <title>Re: block IP's in same zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-ip-s-in-same-zone/m-p/234403#M67192</link>
      <description>&lt;P&gt;No the servers would have gateways associated with the vlan that they reside in&lt;/P&gt;</description>
      <pubDate>Mon, 08 Oct 2018 12:42:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-ip-s-in-same-zone/m-p/234403#M67192</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-10-08T12:42:11Z</dc:date>
    </item>
    <item>
      <title>Re: block IP's in same zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-ip-s-in-same-zone/m-p/234408#M67196</link>
      <description>&lt;P&gt;So the gateway for each vlan is not the firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What is the gateway device&lt;/P&gt;</description>
      <pubDate>Mon, 08 Oct 2018 13:12:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-ip-s-in-same-zone/m-p/234408#M67196</guid>
      <dc:creator>RobinClayton</dc:creator>
      <dc:date>2018-10-08T13:12:48Z</dc:date>
    </item>
    <item>
      <title>Re: block IP's in same zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-ip-s-in-same-zone/m-p/234410#M67197</link>
      <description>&lt;P&gt;No why would that gateway be on the firewall? The gateway would be a router&lt;/P&gt;</description>
      <pubDate>Mon, 08 Oct 2018 13:19:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-ip-s-in-same-zone/m-p/234410#M67197</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-10-08T13:19:10Z</dc:date>
    </item>
    <item>
      <title>Re: block IP's in same zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-ip-s-in-same-zone/m-p/234411#M67198</link>
      <description>&lt;P&gt;So does the router know about both vlans? and do the routing for both vlans?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;</description>
      <pubDate>Mon, 08 Oct 2018 13:20:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-ip-s-in-same-zone/m-p/234411#M67198</guid>
      <dc:creator>RobinClayton</dc:creator>
      <dc:date>2018-10-08T13:20:53Z</dc:date>
    </item>
    <item>
      <title>Re: block IP's in same zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-ip-s-in-same-zone/m-p/234418#M67200</link>
      <description>&lt;P&gt;Yes the routing it set up for the vlan I am talking about.&amp;nbsp; So what does this have to do with blocking the IP's&amp;nbsp; on the firewall?&lt;/P&gt;</description>
      <pubDate>Mon, 08 Oct 2018 13:25:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-ip-s-in-same-zone/m-p/234418#M67200</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-10-08T13:25:59Z</dc:date>
    </item>
  </channel>
</rss>

