<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic The Rule is allowed but hit policy-deny? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/the-rule-is-allowed-but-hit-policy-deny/m-p/254315#M72176</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Recentely the firewall upgraded from 6.1.5 to 8.1.6 but after upgrading there is something strange, there is a allowed rule but in monitor tab it hit deny, i tried to move it to top but still the same issue ( Session End Reason: policy-deny ).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help will be highly appricated&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Tue, 19 Mar 2019 22:20:50 GMT</pubDate>
    <dc:creator>DPWorld</dc:creator>
    <dc:date>2019-03-19T22:20:50Z</dc:date>
    <item>
      <title>The Rule is allowed but hit policy-deny?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/the-rule-is-allowed-but-hit-policy-deny/m-p/254315#M72176</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Recentely the firewall upgraded from 6.1.5 to 8.1.6 but after upgrading there is something strange, there is a allowed rule but in monitor tab it hit deny, i tried to move it to top but still the same issue ( Session End Reason: policy-deny ).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help will be highly appricated&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 19 Mar 2019 22:20:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/the-rule-is-allowed-but-hit-policy-deny/m-p/254315#M72176</guid>
      <dc:creator>DPWorld</dc:creator>
      <dc:date>2019-03-19T22:20:50Z</dc:date>
    </item>
    <item>
      <title>Re: The Rule is allowed but hit policy-deny?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/the-rule-is-allowed-but-hit-policy-deny/m-p/254339#M72181</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/12893"&gt;@DPWorld&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Can you include a screenshot of the rule that the traffic should be hitting along with an example of the detailed log view of the traffic that is hitting the interzone-default policy.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just to verify as well, are you actually hitting the interzone-default policy? If you are hitting the allow security entry that you expect, with the action being allow but the SER being policy-deny, you could possibly simply be running into a certificate pinning issue if you are running decryption.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2019 02:35:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/the-rule-is-allowed-but-hit-policy-deny/m-p/254339#M72181</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-03-20T02:35:58Z</dc:date>
    </item>
    <item>
      <title>Re: The Rule is allowed but hit policy-deny?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/the-rule-is-allowed-but-hit-policy-deny/m-p/254359#M72188</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/12893"&gt;@DPWorld&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As you have moved from 6 to 8, there are changes to default actions in PA,&lt;/P&gt;&lt;P&gt;Check whether you are hitting the below policy behaviour change,&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFtCAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFtCAK&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2019 06:01:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/the-rule-is-allowed-but-hit-policy-deny/m-p/254359#M72188</guid>
      <dc:creator>Abdul_Razaq</dc:creator>
      <dc:date>2019-03-20T06:01:53Z</dc:date>
    </item>
    <item>
      <title>Re: The Rule is allowed but hit policy-deny?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/the-rule-is-allowed-but-hit-policy-deny/m-p/254361#M72189</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PA.JPG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/19158i555FA204375066A6/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PA.JPG" alt="PA.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2019 06:58:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/the-rule-is-allowed-but-hit-policy-deny/m-p/254361#M72189</guid>
      <dc:creator>DPWorld</dc:creator>
      <dc:date>2019-03-20T06:58:01Z</dc:date>
    </item>
    <item>
      <title>Re: The Rule is allowed but hit policy-deny?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/the-rule-is-allowed-but-hit-policy-deny/m-p/254366#M72190</link>
      <description>&lt;P&gt;web-browsing standard port is tcp/80, your traffic is to tcp/8080 .&amp;nbsp;And your policy will be to allow web-browsing only on standard ports, so it wont match to policy.&lt;/P&gt;&lt;P&gt;You need to allow web-browsing over tcp/8080 in security policy.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="web-brows.PNG" style="width: 300px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/19159iEDE2B5CD6CD37B01/image-size/small/is-moderation-mode/true?v=v2&amp;amp;px=200" role="button" title="web-brows.PNG" alt="web-brows.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="policy.PNG" style="width: 300px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/19160i4996FACF60D8B476/image-size/small/is-moderation-mode/true?v=v2&amp;amp;px=200" role="button" title="policy.PNG" alt="policy.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2019 08:31:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/the-rule-is-allowed-but-hit-policy-deny/m-p/254366#M72190</guid>
      <dc:creator>Abdul_Razaq</dc:creator>
      <dc:date>2019-03-20T08:31:42Z</dc:date>
    </item>
  </channel>
</rss>

