<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Policies with any zone in source and destination in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/policies-with-any-zone-in-source-and-destination/m-p/330502#M83776</link>
    <description>&lt;P&gt;While migrating from checkpoint to Palo Alto after defining zones and interface.&lt;/P&gt;&lt;P&gt;Can I simply use any in source and destination zone and create policies with specific objects in source/destination address.&lt;/P&gt;&lt;P&gt;Will it work, for replicating same policies while migrating from checkpoint to Palo Alto.&lt;/P&gt;</description>
    <pubDate>Fri, 29 May 2020 12:40:44 GMT</pubDate>
    <dc:creator>Vikram511</dc:creator>
    <dc:date>2020-05-29T12:40:44Z</dc:date>
    <item>
      <title>Policies with any zone in source and destination</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/policies-with-any-zone-in-source-and-destination/m-p/330502#M83776</link>
      <description>&lt;P&gt;While migrating from checkpoint to Palo Alto after defining zones and interface.&lt;/P&gt;&lt;P&gt;Can I simply use any in source and destination zone and create policies with specific objects in source/destination address.&lt;/P&gt;&lt;P&gt;Will it work, for replicating same policies while migrating from checkpoint to Palo Alto.&lt;/P&gt;</description>
      <pubDate>Fri, 29 May 2020 12:40:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/policies-with-any-zone-in-source-and-destination/m-p/330502#M83776</guid>
      <dc:creator>Vikram511</dc:creator>
      <dc:date>2020-05-29T12:40:44Z</dc:date>
    </item>
    <item>
      <title>Re: Policies with any zone in source and destination</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/policies-with-any-zone-in-source-and-destination/m-p/330551#M83785</link>
      <description>&lt;P&gt;You can do that, however I would recommend scoping the policies down as much as you can. We also migrated from CP and ended up with some pretty silly policies that had to be tuned. each column in the policy is going to strengthen your security stance so the more the merrier I say!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;instead of using any any in the zones I would recommend putting each zone that needs that traffic in there, this will also prevent you from unintentionally allowing any zones that are added later you may not want to allow for said policies.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 29 May 2020 16:37:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/policies-with-any-zone-in-source-and-destination/m-p/330551#M83785</guid>
      <dc:creator>shawnhafen</dc:creator>
      <dc:date>2020-05-29T16:37:04Z</dc:date>
    </item>
    <item>
      <title>Re: Policies with any zone in source and destination</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/policies-with-any-zone-in-source-and-destination/m-p/330588#M83798</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/142190"&gt;@Vikram511&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I'm a huge fan of actually&amp;nbsp;&lt;EM&gt;never&amp;nbsp;&lt;/EM&gt;using 'any' for a zone in the rulebase. That can cause issues down the road as you expand your use of zones and grant unknown additional access that you probably didn't intend for. Best to always specify the zones individually.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 29 May 2020 17:36:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/policies-with-any-zone-in-source-and-destination/m-p/330588#M83798</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-05-29T17:36:59Z</dc:date>
    </item>
  </channel>
</rss>

