<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Rule base management best practices in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/rule-base-management-best-practices/m-p/246103#M70105</link>
    <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm new to the Palo Alto firewall system. My experience is with Checkpoint firewalls. I've been asked by management to look into the best practices for rule base management.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Currently we go through the rule and look at every rule and try to determine if it's still valed. We then disable the rule for 30 days and then delete the rule after that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you have a lot of rules this gets tediuos and things can be missed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SO my question is; is there a best practice guide, whitepaper, suggestions etc to help. Also I'm looking at putting tags on the rules to help identify them and wanted to know if there are any suggestions as to what type of tags/info would be good to identify the rules.&lt;/P&gt;</description>
    <pubDate>Tue, 15 Jan 2019 16:04:50 GMT</pubDate>
    <dc:creator>arivera_12</dc:creator>
    <dc:date>2019-01-15T16:04:50Z</dc:date>
    <item>
      <title>Rule base management best practices</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rule-base-management-best-practices/m-p/246103#M70105</link>
      <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm new to the Palo Alto firewall system. My experience is with Checkpoint firewalls. I've been asked by management to look into the best practices for rule base management.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Currently we go through the rule and look at every rule and try to determine if it's still valed. We then disable the rule for 30 days and then delete the rule after that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you have a lot of rules this gets tediuos and things can be missed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SO my question is; is there a best practice guide, whitepaper, suggestions etc to help. Also I'm looking at putting tags on the rules to help identify them and wanted to know if there are any suggestions as to what type of tags/info would be good to identify the rules.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jan 2019 16:04:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rule-base-management-best-practices/m-p/246103#M70105</guid>
      <dc:creator>arivera_12</dc:creator>
      <dc:date>2019-01-15T16:04:50Z</dc:date>
    </item>
    <item>
      <title>Re: Rule base management best practices</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rule-base-management-best-practices/m-p/246117#M70107</link>
      <description>&lt;P&gt;PAN-OS 8.1 introduced rule hit counters, so that's probably the easiest way to do what you want. If you're stuck running 8.0 for now, the best you have is the "Highlight Unused Rules" checkbox at the bottom of the rule base that will highlight any rules not hit since the firewall was last restarted.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jan 2019 16:57:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rule-base-management-best-practices/m-p/246117#M70107</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2019-01-15T16:57:13Z</dc:date>
    </item>
    <item>
      <title>Re: Rule base management best practices</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rule-base-management-best-practices/m-p/246123#M70109</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/104858"&gt;@arivera_12&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I think the system you have is pretty good honestly, at the very least you are&amp;nbsp;&lt;EM&gt;looking&lt;/EM&gt; for non-needed rules which is something many people don't.&amp;nbsp;&lt;/P&gt;&lt;P&gt;As&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/28203"&gt;@gwesson&lt;/a&gt;&amp;nbsp;mentioned the rule-hit counters in 8.1 definately help in determining if the rule is still needed.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would however really recommend the following:&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Document the ticket number in the description. This ensures you know why the rule was created in the first place.&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Name entries appropriately. I've seen way too many rulebases with entries names "Rule 152" and so on. Build a proper name so you know what the rule is doing.&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Tags can help to group rules, but I've never seen them do a good job at telling you if the rule is still needed.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So you can probably make a better process at the moment. Then when you get upgraded to 8.1 you'll have the Hit Counts to actually see if the rule is being utilized, and then the next major version&amp;nbsp;&lt;EM&gt;maybe&lt;/EM&gt; has even more features to make this easier. If you want to see what that could&amp;nbsp;&lt;EM&gt;possibly&lt;/EM&gt; look like and how things&amp;nbsp;&lt;EM&gt;maybe&lt;/EM&gt; get even better, join the beta group so you get access to the release notes at least.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jan 2019 17:30:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rule-base-management-best-practices/m-p/246123#M70109</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-01-15T17:30:18Z</dc:date>
    </item>
  </channel>
</rss>

