<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Security Profiles on Deny Rules in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/security-profiles-on-deny-rules/m-p/254931#M72356</link>
    <description>&lt;P&gt;What is the best practice for adding security profiles to deny rules?&amp;nbsp; I like to add the URL profile to deny rules so I can see what URLs are being denied.&amp;nbsp; Who else adds security profiles to the deny rules and what benefit do you get? Has anyone had an issue with dataplane resources being consumed by using security profiles in deny rules?&amp;nbsp; -Thanks!&lt;/P&gt;</description>
    <pubDate>Mon, 25 Mar 2019 18:38:22 GMT</pubDate>
    <dc:creator>JohnJones</dc:creator>
    <dc:date>2019-03-25T18:38:22Z</dc:date>
    <item>
      <title>Security Profiles on Deny Rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-profiles-on-deny-rules/m-p/254931#M72356</link>
      <description>&lt;P&gt;What is the best practice for adding security profiles to deny rules?&amp;nbsp; I like to add the URL profile to deny rules so I can see what URLs are being denied.&amp;nbsp; Who else adds security profiles to the deny rules and what benefit do you get? Has anyone had an issue with dataplane resources being consumed by using security profiles in deny rules?&amp;nbsp; -Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 25 Mar 2019 18:38:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-profiles-on-deny-rules/m-p/254931#M72356</guid>
      <dc:creator>JohnJones</dc:creator>
      <dc:date>2019-03-25T18:38:22Z</dc:date>
    </item>
    <item>
      <title>Re: Security Profiles on Deny Rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-profiles-on-deny-rules/m-p/254946#M72359</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75270"&gt;@JohnJones&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are you sure that you have URL logs from rules that have the another action than "allow"?&lt;/P&gt;</description>
      <pubDate>Mon, 25 Mar 2019 19:08:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-profiles-on-deny-rules/m-p/254946#M72359</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2019-03-25T19:08:55Z</dc:date>
    </item>
    <item>
      <title>Re: Security Profiles on Deny Rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-profiles-on-deny-rules/m-p/254966#M72362</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;There is no reason to have these on deny rules as they wont give you any real info (since they are denied). Also thye will just eat up CPU. I only put security profiles on allow policies.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Mon, 25 Mar 2019 21:21:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-profiles-on-deny-rules/m-p/254966#M72362</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-03-25T21:21:06Z</dc:date>
    </item>
    <item>
      <title>Re: Security Profiles on Deny Rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-profiles-on-deny-rules/m-p/254982#M72366</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;There is no reason to have these on deny rules as they wont give you any real info (since they are denied).&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;That's what I actually meant with my question &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Also thye will just eat up CPU. I only put security profiles on allow policies.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;This one I think is partly true. The session will be denied based on the security policy criteria. So for example if there is a deny rule based on zones, IPs and/or ports there won't be anything left that can be processed by the content processors (FPGAs). If you have a deny rule based on applications then there will probably some packets that can be checked with secueity profiles.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Mar 2019 22:01:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-profiles-on-deny-rules/m-p/254982#M72366</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2019-03-25T22:01:19Z</dc:date>
    </item>
  </channel>
</rss>

