<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Rules check by logs with expedition in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/rules-check-by-logs-with-expedition/m-p/353197#M87300</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For one of our client , using PA 850 in cluster,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;They have 8 zones for voip , printer , camera etc&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And all the security policies are wide open.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now we want to restrict the policy by looking at logs from each zone towars other.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can we export logs from panorama to expedition to see or analyse it ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Or what is best approach to do reverse engineering and implement the specific rules between zones.&lt;/P&gt;</description>
    <pubDate>Thu, 01 Oct 2020 07:30:19 GMT</pubDate>
    <dc:creator>FWPalolearner</dc:creator>
    <dc:date>2020-10-01T07:30:19Z</dc:date>
    <item>
      <title>Rules check by logs with expedition</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rules-check-by-logs-with-expedition/m-p/353197#M87300</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For one of our client , using PA 850 in cluster,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;They have 8 zones for voip , printer , camera etc&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And all the security policies are wide open.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now we want to restrict the policy by looking at logs from each zone towars other.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can we export logs from panorama to expedition to see or analyse it ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Or what is best approach to do reverse engineering and implement the specific rules between zones.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Oct 2020 07:30:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rules-check-by-logs-with-expedition/m-p/353197#M87300</guid>
      <dc:creator>FWPalolearner</dc:creator>
      <dc:date>2020-10-01T07:30:19Z</dc:date>
    </item>
    <item>
      <title>Re: Rules check by logs with expedition</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rules-check-by-logs-with-expedition/m-p/353255#M87303</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;you can go with this filter so see respective logs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Monitor &amp;gt; Logs &amp;gt; Traffic &amp;gt; ( zone.src eq SRC_ZONE) and ( zone.dst eq DST_ZONE )&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can export the output shown into an CSV file.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="palo_logs.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/28042iAC7249B3D133004E/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="palo_logs.png" alt="palo_logs.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Based on this output normally a good approach, in my opinion, is:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- setup an application group with apps you want to allow (good apps)&lt;/P&gt;&lt;P&gt;- setup an application group with apps you &lt;STRONG&gt;do not&lt;/STRONG&gt; want to allow (bad apps),&lt;/P&gt;&lt;P&gt;- set up a policy with "application" = application group good apps, set it do allow, enable logging at session end&lt;/P&gt;&lt;P&gt;- set up a policy with "application" = application group bad apps, set it to deny or drop (whatever suits your setup), enable logging at session end&lt;/P&gt;&lt;P&gt;- set up a policy with "application" = any, set it to allow, enable logging at session end&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Continually monitor this rules and fine tune your policy. In Policies &amp;gt; Name column &amp;gt; hover over policy name &amp;gt; triangle icon &amp;gt; log viewer. Later on it might become more difficult because with a single "allow rule" you will be forced to decide for a service (any/select/app default). In case of you need different ports other than "app-default" you need to add a specific policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Oct 2020 10:51:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rules-check-by-logs-with-expedition/m-p/353255#M87303</guid>
      <dc:creator>Rene_Boehme</dc:creator>
      <dc:date>2020-10-01T10:51:30Z</dc:date>
    </item>
    <item>
      <title>Re: Rules check by logs with expedition</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rules-check-by-logs-with-expedition/m-p/353285#M87306</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/138831"&gt;@Rene_Boehme&lt;/a&gt;&amp;nbsp; thanks .this is indeed a better approach.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will see if expedition automates it&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Oct 2020 12:29:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rules-check-by-logs-with-expedition/m-p/353285#M87306</guid>
      <dc:creator>FWPalolearner</dc:creator>
      <dc:date>2020-10-01T12:29:04Z</dc:date>
    </item>
    <item>
      <title>Re: Rules check by logs with expedition</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rules-check-by-logs-with-expedition/m-p/353406#M87317</link>
      <description>&lt;P&gt;Good luck. Let us know if anything is missing.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Oct 2020 17:24:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rules-check-by-logs-with-expedition/m-p/353406#M87317</guid>
      <dc:creator>Rene_Boehme</dc:creator>
      <dc:date>2020-10-01T17:24:17Z</dc:date>
    </item>
  </channel>
</rss>

