<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cleanup Rule in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/cleanup-rule/m-p/325664#M83046</link>
    <description>&lt;P&gt;The Interzone default acts as a "cleanup" rule for traffic &lt;STRONG&gt;between&lt;/STRONG&gt; zones.&amp;nbsp; You should still set logging on it to capture that traffic in logs.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The intrazone rule is for traffic between the &lt;STRONG&gt;same&lt;/STRONG&gt; zone and is a default ALLOW.&amp;nbsp; So inside-inside or outside-outside.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Generally, a cleanup rule isn't required, but as with all things, there is likely a use case out there.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 01 May 2020 15:18:36 GMT</pubDate>
    <dc:creator>gelgin</dc:creator>
    <dc:date>2020-05-01T15:18:36Z</dc:date>
    <item>
      <title>Cleanup Rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cleanup-rule/m-p/325583#M83027</link>
      <description>&lt;P&gt;Do you recommend creating a cleanup rule (last rule to deny any any) in PA? As far as I know, PA firewalls only allow traffic explicitly defined, and the last DENY is a built in "known rule"…correct?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;or will the interzone policy take care of this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Apr 2020 22:19:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cleanup-rule/m-p/325583#M83027</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2020-04-30T22:19:15Z</dc:date>
    </item>
    <item>
      <title>Re: Cleanup Rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cleanup-rule/m-p/325585#M83028</link>
      <description>&lt;P&gt;The whole thinking of having a "Clean Up" rule usually is for testing or for logging.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There may be other ways you can gather the same information,, but that is why you would want to have one.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Apr 2020 22:24:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cleanup-rule/m-p/325585#M83028</guid>
      <dc:creator>jdelio</dc:creator>
      <dc:date>2020-04-30T22:24:12Z</dc:date>
    </item>
    <item>
      <title>Re: Cleanup Rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cleanup-rule/m-p/325589#M83029</link>
      <description>&lt;P&gt;&lt;SPAN&gt;PA firewalls only allow traffic explicitly defined, and the last DENY is a built in "known rule"…&lt;U&gt;&lt;STRONG&gt;correct&lt;/STRONG&gt;&lt;/U&gt;?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Apr 2020 22:28:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cleanup-rule/m-p/325589#M83029</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2020-04-30T22:28:25Z</dc:date>
    </item>
    <item>
      <title>Re: Cleanup Rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cleanup-rule/m-p/325664#M83046</link>
      <description>&lt;P&gt;The Interzone default acts as a "cleanup" rule for traffic &lt;STRONG&gt;between&lt;/STRONG&gt; zones.&amp;nbsp; You should still set logging on it to capture that traffic in logs.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The intrazone rule is for traffic between the &lt;STRONG&gt;same&lt;/STRONG&gt; zone and is a default ALLOW.&amp;nbsp; So inside-inside or outside-outside.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Generally, a cleanup rule isn't required, but as with all things, there is likely a use case out there.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 01 May 2020 15:18:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cleanup-rule/m-p/325664#M83046</guid>
      <dc:creator>gelgin</dc:creator>
      <dc:date>2020-05-01T15:18:36Z</dc:date>
    </item>
  </channel>
</rss>

