<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Rule with Deny action Allowing traffic in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/rule-with-deny-action-allowing-traffic/m-p/254085#M72140</link>
    <description>&lt;P&gt;&amp;nbsp;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43418"&gt;@nanukanu&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What type are the EDLs? You mentioned that they are d URL list type, is that correct?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It is also possible that the firewall is allowing some traffic in order to get the actual URLs from the data. Once it retriefs the URLs it will evaluate the rules again to see if the this traffic is stil matching this rule (before that it is potential match, that is why some packets are allowed).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You should be easy to confirm if you filter the logs by address and not by rule name - that should give you all the rules that this traffic has hit.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But if you are right and the reason is that EDL is being used with static group in the same rule...This looks weard, not sure that the FW should act like that.&lt;/P&gt;</description>
    <pubDate>Mon, 18 Mar 2019 18:45:35 GMT</pubDate>
    <dc:creator>aleksandar.astardzhiev</dc:creator>
    <dc:date>2019-03-18T18:45:35Z</dc:date>
    <item>
      <title>Rule with Deny action Allowing traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rule-with-deny-action-allowing-traffic/m-p/252833#M71841</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We facing an strange issue regarding filtering to some destinations.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have a rule with 2 kinds of destination address:&lt;/P&gt;&lt;P&gt;1. Static Group Address defined in Palo Alto&lt;/P&gt;&lt;P&gt;2. External dynamic list (2 of them)&lt;/P&gt;&lt;P&gt;Those address are attached to a deny rule because are malicious url.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When take a look to the traffic log, we see that traffic hits the rule but the action is allow. We are running version 8.X&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any suggestion about that behaviour?&lt;/P&gt;</description>
      <pubDate>Fri, 08 Mar 2019 09:07:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rule-with-deny-action-allowing-traffic/m-p/252833#M71841</guid>
      <dc:creator>nanukanu</dc:creator>
      <dc:date>2019-03-08T09:07:19Z</dc:date>
    </item>
    <item>
      <title>Re: Rule with Deny action Allowing traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rule-with-deny-action-allowing-traffic/m-p/252840#M71842</link>
      <description>&lt;P&gt;Can you provide a bit more info?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;i'm assuming the traffic being allowed is not actually hitting that policy rule in the logs?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;also just to clarify:&lt;/P&gt;&lt;P&gt;you have 1 rule: containing a address group object. and 2 dynamic lists.&amp;nbsp;not 2 sepearate rules?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Mind sharing the EDL url's?&amp;nbsp;&lt;BR /&gt;also if the EDL uses url's, domains. make sure when to see if in monitoring tab the traffic being allowe dyou can resolve the url( checkbox at bottom of the page)&lt;/P&gt;</description>
      <pubDate>Fri, 08 Mar 2019 10:23:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rule-with-deny-action-allowing-traffic/m-p/252840#M71842</guid>
      <dc:creator>TommieVanHove</dc:creator>
      <dc:date>2019-03-08T10:23:05Z</dc:date>
    </item>
    <item>
      <title>Re: Rule with Deny action Allowing traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rule-with-deny-action-allowing-traffic/m-p/252844#M71843</link>
      <description>&lt;P&gt;Hi Tommie,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's hitting the deny rule as you can see in the screenshoots below.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Log.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/19025i57A3AA1275FCC42C/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Log.png" alt="Log.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Rule_1.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/19024i076B974A5B0BC942/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Rule_1.png" alt="Rule_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 08 Mar 2019 10:39:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rule-with-deny-action-allowing-traffic/m-p/252844#M71843</guid>
      <dc:creator>nanukanu</dc:creator>
      <dc:date>2019-03-08T10:39:50Z</dc:date>
    </item>
    <item>
      <title>Re: Rule with Deny action Allowing traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rule-with-deny-action-allowing-traffic/m-p/252854#M71845</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43418"&gt;@nanukanu&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My guess is that the traffic is allowed because the application isn't fully identified yet ...&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It's normal for the firewall to allow some packets through to allow it to identify the application as seen in this article :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CliLCAS" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CliLCAS&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Once the application is identified correctly it should block.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps.&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Fri, 08 Mar 2019 10:43:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rule-with-deny-action-allowing-traffic/m-p/252854#M71845</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2019-03-08T10:43:34Z</dc:date>
    </item>
    <item>
      <title>Re: Rule with Deny action Allowing traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rule-with-deny-action-allowing-traffic/m-p/252856#M71846</link>
      <description>Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11943"&gt;@kiwi&lt;/a&gt;,&lt;BR /&gt;&lt;BR /&gt;But it's Just destination IP. I want to deny from any source to X destination IP block. Just layer 3.&lt;BR /&gt;&lt;BR /&gt;I think the problem is related with external dynamic list. What happens if cannot reach the EDL? Block all traffic or allow? And what about if in the same rule we have edl and static? Which has more preference?&lt;BR /&gt;&lt;BR /&gt;By the way are added to destination field in the ruleta, maybe must be added to URL field?&lt;BR /&gt;&lt;BR /&gt;Thank you,&lt;BR /&gt;</description>
      <pubDate>Fri, 08 Mar 2019 10:58:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rule-with-deny-action-allowing-traffic/m-p/252856#M71846</guid>
      <dc:creator>nanukanu</dc:creator>
      <dc:date>2019-03-08T10:58:55Z</dc:date>
    </item>
    <item>
      <title>Re: Rule with Deny action Allowing traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rule-with-deny-action-allowing-traffic/m-p/252874#M71854</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43418"&gt;@nanukanu&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you can't reach the EDL then there will not be anything to match on.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As for having both static and dynamic in one policy ... my guess it will process top down like a normal policy check.&amp;nbsp; Static IPs are listed on top so they are checked first.&amp;nbsp; If there's no match then it will process further down to the EDL lists.&amp;nbsp; I haven't confirmed this but this seems logical to me.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Depending on what EDL you have configured you are limited on where you can use it :&lt;/P&gt;
&lt;P&gt;You can use an IP address list as an address object in the source and destination of your policy rules;&lt;/P&gt;
&lt;P&gt;you can use a URL List in &lt;SPAN class="fm_003a"&gt;&lt;A title="Objects &amp;gt; Security Profiles &amp;gt; URL Filtering" target="_blank"&gt;Objects &amp;gt; Security Profiles &amp;gt; URL Filtering&lt;/A&gt;&lt;/SPAN&gt; or as a match criteria in Security policy rules;&lt;/P&gt;
&lt;P&gt;you can use a domain list in &lt;SPAN class="fm_003a"&gt;&lt;A title="Objects &amp;gt; Security Profiles &amp;gt; Anti-Spyware Profile" target="_blank"&gt;Objects &amp;gt; Security Profiles &amp;gt; Anti-Spyware Profile&lt;/A&gt;&lt;/SPAN&gt; for sinkholing specified domain names.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers !&lt;/P&gt;
&lt;P&gt;-Kiwi&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Fri, 08 Mar 2019 12:59:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rule-with-deny-action-allowing-traffic/m-p/252874#M71854</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2019-03-08T12:59:51Z</dc:date>
    </item>
    <item>
      <title>Re: Rule with Deny action Allowing traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rule-with-deny-action-allowing-traffic/m-p/252885#M71858</link>
      <description>&lt;P&gt;Hi Kiwi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your response but not seems to clarify this behaviour.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why action allow if rule says block? There's nothing to evaluate, just if you are trying to go to any address inside the EDL or static addres group just deny.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I understand what you say about identify application, but in this case it's just IP to IP decision.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Fri, 08 Mar 2019 14:11:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rule-with-deny-action-allowing-traffic/m-p/252885#M71858</guid>
      <dc:creator>nanukanu</dc:creator>
      <dc:date>2019-03-08T14:11:34Z</dc:date>
    </item>
    <item>
      <title>Re: Rule with Deny action Allowing traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rule-with-deny-action-allowing-traffic/m-p/254071#M72136</link>
      <description>&lt;P&gt;HI,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any suggestion in this case?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After separate the rules (one with EDL and other with static group) seems that all is working fine, so it's something related about how PAN treat EDL and Static Groups in the same rule. Any new suggestion on that?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards!&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2019 15:00:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rule-with-deny-action-allowing-traffic/m-p/254071#M72136</guid>
      <dc:creator>nanukanu</dc:creator>
      <dc:date>2019-03-18T15:00:22Z</dc:date>
    </item>
    <item>
      <title>Re: Rule with Deny action Allowing traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rule-with-deny-action-allowing-traffic/m-p/254084#M72139</link>
      <description>&lt;P&gt;Can you share screenshots of the rule?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just looking at the logs, I only see 3 62-byte packets, and the traffic is incomplete. It looks like 3 SYN packets that go nowhere.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2019 18:24:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rule-with-deny-action-allowing-traffic/m-p/254084#M72139</guid>
      <dc:creator>DPoppleton</dc:creator>
      <dc:date>2019-03-18T18:24:04Z</dc:date>
    </item>
    <item>
      <title>Re: Rule with Deny action Allowing traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rule-with-deny-action-allowing-traffic/m-p/254085#M72140</link>
      <description>&lt;P&gt;&amp;nbsp;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43418"&gt;@nanukanu&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What type are the EDLs? You mentioned that they are d URL list type, is that correct?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It is also possible that the firewall is allowing some traffic in order to get the actual URLs from the data. Once it retriefs the URLs it will evaluate the rules again to see if the this traffic is stil matching this rule (before that it is potential match, that is why some packets are allowed).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You should be easy to confirm if you filter the logs by address and not by rule name - that should give you all the rules that this traffic has hit.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But if you are right and the reason is that EDL is being used with static group in the same rule...This looks weard, not sure that the FW should act like that.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2019 18:45:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rule-with-deny-action-allowing-traffic/m-p/254085#M72140</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2019-03-18T18:45:35Z</dc:date>
    </item>
    <item>
      <title>Re: Rule with Deny action Allowing traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rule-with-deny-action-allowing-traffic/m-p/256302#M72714</link>
      <description>&lt;P&gt;Hi, finally the rules are separated and works correctly. We will remain in this configuration because is working, but I think a problem exists mixing static and dynamic url.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks to all for your help,&lt;/P&gt;</description>
      <pubDate>Fri, 05 Apr 2019 12:59:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rule-with-deny-action-allowing-traffic/m-p/256302#M72714</guid>
      <dc:creator>nanukanu</dc:creator>
      <dc:date>2019-04-05T12:59:01Z</dc:date>
    </item>
  </channel>
</rss>

