<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: policy installation proccess in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/policy-installation-proccess/m-p/10607#M7820</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, but third rule have different sourcezone ("-Zone" is missing) - I guess thats why you get the dependency warning.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So in your case add web-browsing to the first rule and perhaps expand Block_Application_Filter to block stuff which can be identified as other applications based on web-browsing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If im not mistaken PANOS 5.x will fix some of the dependency stuff.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 17 May 2012 17:53:50 GMT</pubDate>
    <dc:creator>mikand</dc:creator>
    <dc:date>2012-05-17T17:53:50Z</dc:date>
    <item>
      <title>policy installation proccess</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/policy-installation-proccess/m-p/10606#M7819</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hey&lt;/P&gt;&lt;P&gt;i have some policy that gives me warning when i do commit on it so i dont realy understand the policy calculation proccedure, ill be glad if you could explain it to me.&lt;/P&gt;&lt;P&gt;i attached a policy screen shot, when i do install policy i get warnings for example face-book chat that it needs web-browsing and jabber to work.&lt;/P&gt;&lt;P&gt;lets focus about the manage zone, and the TMG is used as a proxy for almost all users.&lt;/P&gt;&lt;P&gt;the first rule is to allow some apps that are being blocked by the second and forth rules, but if we will look at the third rule we can see everything is allowed and going thgough URL, AV etc.. so:&lt;/P&gt;&lt;P&gt;at the first rule i opened facebook chat and on the third rule web-browsing is allowed so why do i get those warnings?&lt;/P&gt;&lt;P&gt;thank you for any help&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 May 2012 07:36:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/policy-installation-proccess/m-p/10606#M7819</guid>
      <dc:creator>minow</dc:creator>
      <dc:date>2012-05-17T07:36:21Z</dc:date>
    </item>
    <item>
      <title>Re: policy installation proccess</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/policy-installation-proccess/m-p/10607#M7820</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, but third rule have different sourcezone ("-Zone" is missing) - I guess thats why you get the dependency warning.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So in your case add web-browsing to the first rule and perhaps expand Block_Application_Filter to block stuff which can be identified as other applications based on web-browsing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If im not mistaken PANOS 5.x will fix some of the dependency stuff.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 May 2012 17:53:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/policy-installation-proccess/m-p/10607#M7820</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-05-17T17:53:50Z</dc:date>
    </item>
    <item>
      <title>Re: policy installation proccess</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/policy-installation-proccess/m-p/10608#M7821</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;but the "-zone" open web browsing on the fifth rule, the reson for this policy is that "-zone" and "maange-zone" should have different url filtering policy.&lt;/P&gt;&lt;P&gt;i still cant uderstand the reason for those warnings.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 May 2012 15:04:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/policy-installation-proccess/m-p/10608#M7821</guid>
      <dc:creator>minow</dc:creator>
      <dc:date>2012-05-18T15:04:31Z</dc:date>
    </item>
    <item>
      <title>Re: policy installation proccess</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/policy-installation-proccess/m-p/10609#M7822</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did a quick test on my Palo Alto device and found the same results.&lt;/P&gt;&lt;P&gt;I created a the following rule set:- &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Name:- Test Rule 1:-&amp;nbsp; From Trust, DMZ&amp;nbsp; to Untrust,&amp;nbsp;&amp;nbsp; Allow: facebook-chat,facebook-base and jabber&lt;/P&gt;&lt;P&gt;2) Name:- Test Rule 2 :-&amp;nbsp; From Trust to Untrust,&amp;nbsp;&amp;nbsp; Allow: web browsing , ssl&lt;/P&gt;&lt;P&gt;3) Name:- Test Rule 3 :-&amp;nbsp; From DMZ to Untrust,&amp;nbsp;&amp;nbsp; Allow: web browsing , ssl&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The commit will show us the dependency warning as you see in your case.&lt;/P&gt;&lt;P&gt;I guess since you have created a rule 1 to include&amp;nbsp; 2 source zones in the single rule to allow facebook base,facebook-chat jabber the dependency rule should also include the same 2 source zones.&lt;/P&gt;&lt;P&gt;I do understand your purpose of addidng 2 differnt URL filtering profiles to the two dependency rules.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This can be acheived without any dependency warnings by the following rule&amp;nbsp; Set:- &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Name:- Exclude_Applications:- &lt;STRONG&gt;From Manage-zon&lt;/STRONG&gt;e to Any zone with &lt;STRONG&gt;TMG-Manage-Source address&lt;/STRONG&gt; Allow facebook base-chat-mail-posting,dropbox etc &lt;/P&gt;&lt;P&gt;2) Name:- Exclude_Applications -2 :- &lt;STRONG&gt;From -Zone&lt;/STRONG&gt; to Any zone with&amp;nbsp; &lt;STRONG&gt;TMG-Source address&lt;/STRONG&gt; Allow facebook base-chat-mail-posting,dropbox etc&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3) Name:- Manage Application Control &lt;STRONG&gt;(No chang&lt;/STRONG&gt;e to that rule)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4)Internet_Manage:- &lt;STRONG&gt;From Manage-zone&lt;/STRONG&gt; to Any zone with&lt;STRONG&gt; TMG-Manage-Source address&lt;/STRONG&gt; Allow ssl, web-browsing &lt;STRONG&gt;(Add-URL category- 1)&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;5)YVC_Application Control:- &lt;STRONG&gt;From -Zone&lt;/STRONG&gt; to Any zone with &lt;STRONG&gt;TMG-Source address &lt;/STRONG&gt;Allow ssl,web-browsing &lt;STRONG&gt;(Add-URL category-2)&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You would not be seeing the warnings now. Let me know once you configure it and if that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Parth&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 20 May 2012 21:36:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/policy-installation-proccess/m-p/10609#M7822</guid>
      <dc:creator>ppatel</dc:creator>
      <dc:date>2012-05-20T21:36:37Z</dc:date>
    </item>
  </channel>
</rss>

