<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Stupid question time........ in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/stupid-question-time/m-p/354094#M87393</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sorry, I just saw I fat fingered my question:&lt;/P&gt;&lt;P&gt;Let's say I have an objected named "Pizza" with an ip of &lt;STRONG&gt;10.10.10.10/32&lt;/STRONG&gt; and it is in use on a security rule.&lt;/P&gt;&lt;P&gt;I create another object named "Pizza1" with an ip of &lt;STRONG&gt;10.10.10.10/32&lt;/STRONG&gt; and use it in a different security rule.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So same IP, different name.&amp;nbsp; How does the the Palo handle this?&lt;/P&gt;</description>
    <pubDate>Mon, 05 Oct 2020 17:53:22 GMT</pubDate>
    <dc:creator>MrWonderful</dc:creator>
    <dc:date>2020-10-05T17:53:22Z</dc:date>
    <item>
      <title>Stupid question time........</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/stupid-question-time/m-p/353926#M87381</link>
      <description>&lt;P&gt;Let's say I have an objected named "Pizza" with an ip of 10.10.10.10/32 and it is in use on a security rule.&lt;/P&gt;&lt;P&gt;I create another object named "Pizza1" with an ip of&amp;nbsp;0.10.10.10/32 and use it in a different security rule.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could that create a problem with the first rule assuming different let's say destinations or APP-ID/Ports?&lt;/P&gt;</description>
      <pubDate>Mon, 05 Oct 2020 12:23:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/stupid-question-time/m-p/353926#M87381</guid>
      <dc:creator>MrWonderful</dc:creator>
      <dc:date>2020-10-05T12:23:59Z</dc:date>
    </item>
    <item>
      <title>Re: Stupid question time........</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/stupid-question-time/m-p/354038#M87388</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/149924"&gt;@MrWonderful&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Nope. The objects are actually replaced in the configuration as far as the firewall is concerned. So your firewall doesn't read the configuration as "Pizza" is allowed to send DNS requests to 8.8.8.8, it actually replaces the object with the actual address so it looks at is as "10.10.10.10/32" is allowed to send DNS requests to 8.8.8.8.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Oct 2020 15:34:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/stupid-question-time/m-p/354038#M87388</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-10-05T15:34:18Z</dc:date>
    </item>
    <item>
      <title>Re: Stupid question time........</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/stupid-question-time/m-p/354094#M87393</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sorry, I just saw I fat fingered my question:&lt;/P&gt;&lt;P&gt;Let's say I have an objected named "Pizza" with an ip of &lt;STRONG&gt;10.10.10.10/32&lt;/STRONG&gt; and it is in use on a security rule.&lt;/P&gt;&lt;P&gt;I create another object named "Pizza1" with an ip of &lt;STRONG&gt;10.10.10.10/32&lt;/STRONG&gt; and use it in a different security rule.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So same IP, different name.&amp;nbsp; How does the the Palo handle this?&lt;/P&gt;</description>
      <pubDate>Mon, 05 Oct 2020 17:53:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/stupid-question-time/m-p/354094#M87393</guid>
      <dc:creator>MrWonderful</dc:creator>
      <dc:date>2020-10-05T17:53:22Z</dc:date>
    </item>
    <item>
      <title>Re: Stupid question time........</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/stupid-question-time/m-p/354095#M87394</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/149924"&gt;@MrWonderful&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;right, I kind of assumed that you had. Again, it doesn’t matter. You could have 50 address objects with different names all assigned the same address, and the firewall won’t care. When it compiles the configuration all of those objects simply get replaced with the address you have specified in the configuration.&lt;/P&gt;
&lt;P&gt;So really as far as the firewall is concerned, anything that you’ve specified as Pizza is just going to be replaced with 10.10.10.10/32 and anything with Pizza1 is going to be replaced with whatever you’ve configured for that object. The fact that you have multiple objects mapped to the same value doesn’t effect that process at all.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Oct 2020 18:05:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/stupid-question-time/m-p/354095#M87394</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-10-05T18:05:03Z</dc:date>
    </item>
    <item>
      <title>Re: Stupid question time........</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/stupid-question-time/m-p/354096#M87395</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;Just so I understand you correctly, the Palo basically treats each object individually within each rule set.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So that Pizza with a&amp;nbsp;&lt;SPAN&gt;10.10.10.10/32 in rule number one doesn't get confused with Pizza1&amp;nbsp;with a&amp;nbsp;10.10.10.10/32 in rule number two and wouldn't get confused with Pizza2&amp;nbsp;with a&amp;nbsp;10.10.10.10/32 in rule number three and so on, correct?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Oct 2020 19:14:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/stupid-question-time/m-p/354096#M87395</guid>
      <dc:creator>MrWonderful</dc:creator>
      <dc:date>2020-10-05T19:14:44Z</dc:date>
    </item>
    <item>
      <title>Re: Stupid question time........</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/stupid-question-time/m-p/354113#M87398</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/149924"&gt;@MrWonderful&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Correct. The firewall will simply replace the object with its configured value. The fact that you have multiple objects with the same configured value has no effect on that.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Oct 2020 19:36:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/stupid-question-time/m-p/354113#M87398</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-10-05T19:36:52Z</dc:date>
    </item>
    <item>
      <title>Re: Stupid question time........</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/stupid-question-time/m-p/354166#M87403</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/149924"&gt;@MrWonderful&lt;/a&gt;&amp;nbsp;one nuance though in this specific line of questioning&lt;/P&gt;&lt;P&gt;Bear in mind that the firewall will not distinguish between pizza and pizza1 when it comes down to matching security rules because both have the same IP address and this is the only thing the running configuration really cares about.&lt;/P&gt;&lt;P&gt;This means that in this specific case both pizza and pizza1 will be hitting the same rules, even though only 1 of them may be listed in the rule&lt;/P&gt;</description>
      <pubDate>Mon, 05 Oct 2020 22:30:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/stupid-question-time/m-p/354166#M87403</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2020-10-05T22:30:17Z</dc:date>
    </item>
  </channel>
</rss>

