<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Default deny logging question in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/default-deny-logging-question/m-p/276182#M75343</link>
    <description>&lt;P&gt;Hi James,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;from my point of view there is no downsite. If your ruleset is appropriate there is no reason to let the intra-/inter-zone Default rules not log events. As mentioned by other user you can have a deny/any/any rule before the default rules but this is basically only useful if you have setup policies for everything. Imagine some customer/partner wants to setup a VPN with your outside interface. As he is based within the outside zone as well as your outside interface this would normally hit the "intra-zone default rule" - which can not being hit when a deny/any/any statement is placed before.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The best practice is to set logging to "at session end" and you can safely enable the logging on those rules as I do primarily assume you do not want this rule to be it but when it gets hit you want to see it in the logs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Rene&lt;/P&gt;</description>
    <pubDate>Thu, 11 Jul 2019 15:29:05 GMT</pubDate>
    <dc:creator>Rboehme</dc:creator>
    <dc:date>2019-07-11T15:29:05Z</dc:date>
    <item>
      <title>Default deny logging question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/default-deny-logging-question/m-p/275607#M75288</link>
      <description>&lt;P&gt;I notice that if a connection comes in and does not hit any policy correctly I do not see the deny in the logs. I think this is because the default behavior of the intrazone-default&amp;nbsp; rule is not to log anything. Is there a down side to setting this to log events so that we can see when a connection fails? Sometimes from a troubleshooting perspective this would be helpful but I wonder if its not enabled for a reason by default. I assume because it will generate a lot of logs but was wondering what everyone else thinks before I do this.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jul 2019 19:03:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/default-deny-logging-question/m-p/275607#M75288</guid>
      <dc:creator>dstjames</dc:creator>
      <dc:date>2019-07-09T19:03:07Z</dc:date>
    </item>
    <item>
      <title>Re: Default deny logging question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/default-deny-logging-question/m-p/275628#M75289</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I always turn on logging so I can see traffic even if its denied. I honestly&amp;nbsp;never use the default&amp;nbsp;inter/intra policies and put a DENY ALL one as my last policy and only then allow the traffic I want.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The down side is the logs will fill up faster and the PAN wont keep as much. But its worth that cost.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers!&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jul 2019 20:02:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/default-deny-logging-question/m-p/275628#M75289</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-07-09T20:02:04Z</dc:date>
    </item>
    <item>
      <title>Re: Default deny logging question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/default-deny-logging-question/m-p/275763#M75295</link>
      <description>&lt;P&gt;I have used both intrazone and block-alll policy.&lt;/P&gt;&lt;P&gt;i prefer to now use the custom block-all policy and leave the intrazone stuff alone.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we use panorama for our logs so this policy is not set for forwarding. It just logs locally.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;you can of course just enable/disable when needed for diags.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2019 12:21:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/default-deny-logging-question/m-p/275763#M75295</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-07-10T12:21:19Z</dc:date>
    </item>
    <item>
      <title>Re: Default deny logging question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/default-deny-logging-question/m-p/275923#M75319</link>
      <description>&lt;P&gt;I have a deny all and log as the last rule post rule in Panorama. It applies to all firewalls, so the default inter-zone and intra-zone rules never get hit. More logs is the double-edged sword. If I don't want to see something, I have been known to put in a rule to block traffic and not forward it to Panorama.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2019 20:51:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/default-deny-logging-question/m-p/275923#M75319</guid>
      <dc:creator>khsieh</dc:creator>
      <dc:date>2019-07-10T20:51:50Z</dc:date>
    </item>
    <item>
      <title>Re: Default deny logging question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/default-deny-logging-question/m-p/276182#M75343</link>
      <description>&lt;P&gt;Hi James,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;from my point of view there is no downsite. If your ruleset is appropriate there is no reason to let the intra-/inter-zone Default rules not log events. As mentioned by other user you can have a deny/any/any rule before the default rules but this is basically only useful if you have setup policies for everything. Imagine some customer/partner wants to setup a VPN with your outside interface. As he is based within the outside zone as well as your outside interface this would normally hit the "intra-zone default rule" - which can not being hit when a deny/any/any statement is placed before.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The best practice is to set logging to "at session end" and you can safely enable the logging on those rules as I do primarily assume you do not want this rule to be it but when it gets hit you want to see it in the logs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Rene&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jul 2019 15:29:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/default-deny-logging-question/m-p/276182#M75343</guid>
      <dc:creator>Rboehme</dc:creator>
      <dc:date>2019-07-11T15:29:05Z</dc:date>
    </item>
  </channel>
</rss>

