<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Shadow Rule Warning in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/shadow-rule-warning/m-p/273607#M75053</link>
    <description>&lt;P&gt;Rule shadowing is always because a more general rule is above more specific rule below it (as you are aware)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Not knowing how many Source Zones you have... my recommendation is list all of the them in the source zone field vs using ANY.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You could also do ANY source zone (but then put in the 3 internal unrouteable address 10.0.0.0/8, 172.16.0.0/12 and 192.168.0.0/16)&lt;/P&gt;&lt;P&gt;Just need to modify the rule so it does not cause the shadowing.&lt;/P&gt;</description>
    <pubDate>Thu, 27 Jun 2019 17:08:41 GMT</pubDate>
    <dc:creator>S.Cantwell</dc:creator>
    <dc:date>2019-06-27T17:08:41Z</dc:date>
    <item>
      <title>Shadow Rule Warning</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/shadow-rule-warning/m-p/273444#M75033</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Recently I upgrades my firewall from PANOS 8.0.10 to 8.0.17.&amp;nbsp; The upgrade went fine.&amp;nbsp; However, after making a small configuration change (adding a new address object), my commit showed a Shadow Rule warning.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The warning is associated with a rule that I have that is designed to Deny traffic from ANY zone and ANY application whose destination is the outsize (untrusted) zone with a desitnation address that is identified by Palo's External Dynamic lists "PaloAlto Networks High Risk Addresses" and "PaloAlto Known Malicious IP Addresses"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This rule&amp;nbsp; "Block Malicious Sites" is the first security rule that is defined.&amp;nbsp; The warning indicates this rule shadoes anothe rule that is listed further down in my list that allows specific traffic (NTP application) to the outside.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;While I can move the "Block Malicious Site" rule further down the list, I can't comprehend why it would be considered shadowing.&amp;nbsp; It seems to me the rule targets specific address, essentially those identified in the dynamic list.&amp;nbsp; If it truly were shadowing, I would have thought I would have seen this warning prior to my upgrades from 8.0.10 to 8.0.17.&amp;nbsp; It seems to me that something has changed in the way the firewall evaluated the rules.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone else seen this behavior or have any ideas on what might be happening?&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I appreciate any input.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jun 2019 09:27:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/shadow-rule-warning/m-p/273444#M75033</guid>
      <dc:creator>sgoethals</dc:creator>
      <dc:date>2019-06-27T09:27:58Z</dc:date>
    </item>
    <item>
      <title>Re: Shadow Rule Warning</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/shadow-rule-warning/m-p/273593#M75049</link>
      <description>&lt;P&gt;Post a screenshot of the two rules, and (if possible) the full text of the error message.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jun 2019 15:53:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/shadow-rule-warning/m-p/273593#M75049</guid>
      <dc:creator>fjwcash</dc:creator>
      <dc:date>2019-06-27T15:53:35Z</dc:date>
    </item>
    <item>
      <title>Re: Shadow Rule Warning</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/shadow-rule-warning/m-p/273607#M75053</link>
      <description>&lt;P&gt;Rule shadowing is always because a more general rule is above more specific rule below it (as you are aware)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Not knowing how many Source Zones you have... my recommendation is list all of the them in the source zone field vs using ANY.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You could also do ANY source zone (but then put in the 3 internal unrouteable address 10.0.0.0/8, 172.16.0.0/12 and 192.168.0.0/16)&lt;/P&gt;&lt;P&gt;Just need to modify the rule so it does not cause the shadowing.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jun 2019 17:08:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/shadow-rule-warning/m-p/273607#M75053</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2019-06-27T17:08:41Z</dc:date>
    </item>
    <item>
      <title>Re: Shadow Rule Warning</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/shadow-rule-warning/m-p/273615#M75055</link>
      <description>&lt;P&gt;Thanks for the help &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/113304"&gt;@S.Cantwell&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I first tried to just change the Source Zones from Any to the specific zones I wanted to use. as you suggested.&amp;nbsp; This didn't seem to help.&amp;nbsp; I still received a warning indicating it was shadowing.&amp;nbsp; I then went ahead and added as a source address the regions (based on my address schemes) of 10.0.0.0 - 10.255.255.255 and 192.168.0.0-192.168.255.255.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Upon making this change, the validation of the commit worked fine and I was able to sucessfully commit the configuration.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jun 2019 18:49:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/shadow-rule-warning/m-p/273615#M75055</guid>
      <dc:creator>sgoethals</dc:creator>
      <dc:date>2019-06-27T18:49:22Z</dc:date>
    </item>
    <item>
      <title>Re: Shadow Rule Warning</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/shadow-rule-warning/m-p/336800#M84881</link>
      <description>&lt;P&gt;Are you sure this is the right solution?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Check difference in results between Validate and Commit actions:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PNvNCAW" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PNvNCAW&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This was the solution for me.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jul 2020 01:41:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/shadow-rule-warning/m-p/336800#M84881</guid>
      <dc:creator>SimonT</dc:creator>
      <dc:date>2020-07-07T01:41:05Z</dc:date>
    </item>
  </channel>
</rss>

