<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Overlap-Zone difference Vsys in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/overlap-zone-difference-vsys/m-p/261540#M74148</link>
    <description>&lt;P&gt;"Just because you can do something doesn't mean you should"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Having managed a multi-vSYS environment, I can definitely recommend you NOT do this.&amp;nbsp; You can because the vSYS are considered completely separate systems.&amp;nbsp; But to keep things straight in your own head, I would recommend defining your zones with meaningful and specific names.&amp;nbsp; This means you will most likely have different zone names in each vSYS naturally.&amp;nbsp; Thoughts?&lt;/P&gt;</description>
    <pubDate>Fri, 17 May 2019 20:00:53 GMT</pubDate>
    <dc:creator>jeremy.larsen</dc:creator>
    <dc:date>2019-05-17T20:00:53Z</dc:date>
    <item>
      <title>Overlap-Zone difference Vsys</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/overlap-zone-difference-vsys/m-p/261441#M74124</link>
      <description>&lt;P&gt;HI Expert ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would like to know that it can be possible about overlap zone name but&amp;nbsp;difference Vsys such as I would to defind name Zone "Trust" on vsys1 and would to zone name "Trust" on vsys2 as well&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please&amp;nbsp; suggest to me&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 May 2019 07:11:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/overlap-zone-difference-vsys/m-p/261441#M74124</guid>
      <dc:creator>Pattarachai</dc:creator>
      <dc:date>2019-05-17T07:11:24Z</dc:date>
    </item>
    <item>
      <title>Re: Overlap-Zone difference Vsys</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/overlap-zone-difference-vsys/m-p/261464#M74126</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/81046"&gt;@Pattarachai&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes you can use the same zone names in different vsys.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers !&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Fri, 17 May 2019 08:35:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/overlap-zone-difference-vsys/m-p/261464#M74126</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2019-05-17T08:35:18Z</dc:date>
    </item>
    <item>
      <title>Re: Overlap-Zone difference Vsys</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/overlap-zone-difference-vsys/m-p/261540#M74148</link>
      <description>&lt;P&gt;"Just because you can do something doesn't mean you should"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Having managed a multi-vSYS environment, I can definitely recommend you NOT do this.&amp;nbsp; You can because the vSYS are considered completely separate systems.&amp;nbsp; But to keep things straight in your own head, I would recommend defining your zones with meaningful and specific names.&amp;nbsp; This means you will most likely have different zone names in each vSYS naturally.&amp;nbsp; Thoughts?&lt;/P&gt;</description>
      <pubDate>Fri, 17 May 2019 20:00:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/overlap-zone-difference-vsys/m-p/261540#M74148</guid>
      <dc:creator>jeremy.larsen</dc:creator>
      <dc:date>2019-05-17T20:00:53Z</dc:date>
    </item>
    <item>
      <title>Re: Overlap-Zone difference Vsys</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/overlap-zone-difference-vsys/m-p/261551#M74151</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/107910"&gt;@jeremy.larsen&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Depends on why you are using multi-vsys to begin with. In certain instances where I utilize multi-vsys in local government buildings to seperate out say Law Enforcement from the rest of the County I wouldn't necissarly say that a zone named "County Untrust" or "LEA Untrust" would really make that big of an difference over just "untrust". It might matter slightly more if you configure in the GUI instead of the XML or CLI, but you do have the dropdown up top specifying what VSYS you are on currently.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's also something that I've done on purpose when I template the XML file for utilization in Jinja2 for shared security policies where I might only want to make an "Internet Access" policy once or a similar shared policy that I would otherwise have to create in both security rulebases manually. Granted this is an extreme edge-case and something most people would never think of even doing, but reasons to utilize shared zone names do exist.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 May 2019 21:18:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/overlap-zone-difference-vsys/m-p/261551#M74151</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-05-17T21:18:07Z</dc:date>
    </item>
  </channel>
</rss>

