<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Negate please in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/negate-please/m-p/11671#M8574</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please open a ticket with your 3rd party support. The 3rd party will make a feature request will with concerned sales team..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 06 Sep 2012 22:04:45 GMT</pubDate>
    <dc:creator>sdurga</dc:creator>
    <dc:date>2012-09-06T22:04:45Z</dc:date>
    <item>
      <title>Negate please</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/negate-please/m-p/11668#M8571</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am running PanOS 4.1.7, migrating from a Checkpoint R75 platform.&amp;nbsp;&amp;nbsp; I have a lot of rules in place, but we are heavy into excpetions.&amp;nbsp; I keep running into situations that would be very easy to handle if I simply had the Negate option.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example, I have a rule that allows domain users out to specific web apps using my URL filtering, along with data filtering, and other policies in a single rule.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have around 20 of these rules based on AD user group.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Below these rules, I block access to the Internet.&amp;nbsp; If someone fires up a non domain VMware guest and uses a bridged connection, they basically get no Internet access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At the top and then in the middle of these rules, I have application filters blocking apps such as proxy, DNS, video, audio, etc.&amp;nbsp;&amp;nbsp; The location is based on which users can use these apps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem is I need to block things like http-audo and http-video, yet exclude specific sites from this blocking for everyone.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Life would be a lot easier if I could block using an application filter, while negating my URL custom category of "white listed sites."&amp;nbsp;&amp;nbsp;&amp;nbsp; Or if I could create a rule that blocks by application filter to all users while negating a specific AD user group.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know how to make this work with 4.1.7, I just really would love to see more Negate options in future releases.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Aug 2012 21:00:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/negate-please/m-p/11668#M8571</guid>
      <dc:creator>EdwinD</dc:creator>
      <dc:date>2012-08-29T21:00:02Z</dc:date>
    </item>
    <item>
      <title>Re: Negate please</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/negate-please/m-p/11669#M8572</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Feedback of this nature is very important to us.&amp;nbsp; Your feedback is what allows us deliver a stronger product.&amp;nbsp; Have you discussed submitting feature requests of this nature with your Palo Alto Networks SE or Account Team?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Sep 2012 23:34:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/negate-please/m-p/11669#M8572</guid>
      <dc:creator>bvandivier</dc:creator>
      <dc:date>2012-09-04T23:34:48Z</dc:date>
    </item>
    <item>
      <title>Re: Negate please</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/negate-please/m-p/11670#M8573</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To be honost, I'm not sure how to do this.&amp;nbsp; I have Palo Alto Networks support through a 3rd party.&amp;nbsp; Is there a formal feature request document, or do I just pass it on through my 3rd party support?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Sep 2012 21:41:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/negate-please/m-p/11670#M8573</guid>
      <dc:creator>EdwinD</dc:creator>
      <dc:date>2012-09-06T21:41:31Z</dc:date>
    </item>
    <item>
      <title>Re: Negate please</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/negate-please/m-p/11671#M8574</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please open a ticket with your 3rd party support. The 3rd party will make a feature request will with concerned sales team..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Sep 2012 22:04:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/negate-please/m-p/11671#M8574</guid>
      <dc:creator>sdurga</dc:creator>
      <dc:date>2012-09-06T22:04:45Z</dc:date>
    </item>
  </channel>
</rss>

