<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Bypass/Disable Policy for destination address. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/bypass-disable-policy-for-destination-address/m-p/356191#M87627</link>
    <description>&lt;P&gt;I try but doesn't work. Checking for unused rules it evidence this rule, and I don't want add continuosly source ip addres, but use only the destination addesses.&lt;/P&gt;</description>
    <pubDate>Wed, 14 Oct 2020 06:23:08 GMT</pubDate>
    <dc:creator>mandrake</dc:creator>
    <dc:date>2020-10-14T06:23:08Z</dc:date>
    <item>
      <title>Bypass/Disable Policy for destination address.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bypass-disable-policy-for-destination-address/m-p/356015#M87602</link>
      <description>&lt;P&gt;I want to make a policy/rule to bypass/disable policy in case of certain destination ip addresses. There is a way?&lt;/P&gt;</description>
      <pubDate>Tue, 13 Oct 2020 08:26:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bypass-disable-policy-for-destination-address/m-p/356015#M87602</guid>
      <dc:creator>mandrake</dc:creator>
      <dc:date>2020-10-13T08:26:22Z</dc:date>
    </item>
    <item>
      <title>Re: Bypass/Disable Policy for destination address.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bypass-disable-policy-for-destination-address/m-p/356055#M87605</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/158758"&gt;@mandrake&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Why don't you add a policy/rule with the certain destination IP before the current policy/rule ?&lt;/P&gt;
&lt;P&gt;Or am I missing the point ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;-Kiwi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Tue, 13 Oct 2020 09:52:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bypass-disable-policy-for-destination-address/m-p/356055#M87605</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2020-10-13T09:52:01Z</dc:date>
    </item>
    <item>
      <title>Re: Bypass/Disable Policy for destination address.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bypass-disable-policy-for-destination-address/m-p/356072#M87609</link>
      <description>&lt;P&gt;You are right&lt;/P&gt;&lt;P&gt;But I already try it, but works only on personal IP address (PC client IP) and not to if i configure a destination address.&lt;/P&gt;&lt;P&gt;I've a pool of some destination public address that I want to reach without any filter / policy that are now on the firewall.&lt;/P&gt;&lt;P&gt;Just for convenience panos 8.1.x&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Oct 2020 10:58:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bypass-disable-policy-for-destination-address/m-p/356072#M87609</guid>
      <dc:creator>mandrake</dc:creator>
      <dc:date>2020-10-13T10:58:31Z</dc:date>
    </item>
    <item>
      <title>Re: Bypass/Disable Policy for destination address.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bypass-disable-policy-for-destination-address/m-p/356089#M87620</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Should just be setting the source IP's to any and destination IP's to your group of specific IP's. You can also use User-ID if you have that setup so those destination IP's are accessible only by the Users you specify, or AD group.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Tue, 13 Oct 2020 16:49:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bypass-disable-policy-for-destination-address/m-p/356089#M87620</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2020-10-13T16:49:30Z</dc:date>
    </item>
    <item>
      <title>Re: Bypass/Disable Policy for destination address.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bypass-disable-policy-for-destination-address/m-p/356191#M87627</link>
      <description>&lt;P&gt;I try but doesn't work. Checking for unused rules it evidence this rule, and I don't want add continuosly source ip addres, but use only the destination addesses.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Oct 2020 06:23:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bypass-disable-policy-for-destination-address/m-p/356191#M87627</guid>
      <dc:creator>mandrake</dc:creator>
      <dc:date>2020-10-14T06:23:08Z</dc:date>
    </item>
    <item>
      <title>Re: Bypass/Disable Policy for destination address.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bypass-disable-policy-for-destination-address/m-p/356194#M87629</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/158758"&gt;@mandrake&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This should be straightforward to configure.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Are you able to send how you configured it exactly + show us how the session/traffic is actually being identified by the firewall ? This could clarify why it's not hitting your rule.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Wed, 14 Oct 2020 07:44:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bypass-disable-policy-for-destination-address/m-p/356194#M87629</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2020-10-14T07:44:15Z</dc:date>
    </item>
    <item>
      <title>Re: Bypass/Disable Policy for destination address.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bypass-disable-policy-for-destination-address/m-p/356239#M87641</link>
      <description>&lt;P&gt;OK, as you can see in this image: rule 9 is the principal rule to go to internet.&lt;/P&gt;&lt;P&gt;If I put the client PC address in rule 4 it works but can reach any IP without security rules&lt;/P&gt;&lt;P&gt;If I put the client PC address and destination IP&amp;nbsp;in rule 3 doesn't works. Also doesn't works using only destination addess.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PA.jpg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/28199i7C1E811C37695EF0/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PA.jpg" alt="PA.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Oct 2020 12:16:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bypass-disable-policy-for-destination-address/m-p/356239#M87641</guid>
      <dc:creator>mandrake</dc:creator>
      <dc:date>2020-10-14T12:16:13Z</dc:date>
    </item>
    <item>
      <title>Re: Bypass/Disable Policy for destination address.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bypass-disable-policy-for-destination-address/m-p/356268#M87644</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;That is because your rule 4 has the destination IP's set to any. If you put in the destination IP's that you only want to get to, it will then be restricted to only those IP's.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope that makes sense.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 14 Oct 2020 14:36:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bypass-disable-policy-for-destination-address/m-p/356268#M87644</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2020-10-14T14:36:31Z</dc:date>
    </item>
    <item>
      <title>Re: Bypass/Disable Policy for destination address.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bypass-disable-policy-for-destination-address/m-p/356270#M87646</link>
      <description>&lt;P&gt;You wrong, because I wrote:&amp;nbsp;&lt;SPAN&gt;If I put the client &lt;STRONG&gt;PC address and destination IP&amp;nbsp;in rule 3&lt;/STRONG&gt; doesn't works. Also doesn't works &lt;STRONG&gt;using only destination addess&lt;/STRONG&gt;.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rule number 4 insted of 3 works, but for all DESTINATION ADDRESS.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Oct 2020 15:30:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bypass-disable-policy-for-destination-address/m-p/356270#M87646</guid>
      <dc:creator>mandrake</dc:creator>
      <dc:date>2020-10-14T15:30:47Z</dc:date>
    </item>
    <item>
      <title>Re: Bypass/Disable Policy for destination address.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bypass-disable-policy-for-destination-address/m-p/356271#M87647</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Please look at your policies. Rule 3 and 4 have different source IP's. Please keep in mind the following:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The firewall reads rules top to bottom and left to right and all set conditions must match. If you provide me the current IP of the workstation and the external destination IP's I can help you write the correct policy.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 14 Oct 2020 15:34:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bypass-disable-policy-for-destination-address/m-p/356271#M87647</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2020-10-14T15:34:06Z</dc:date>
    </item>
    <item>
      <title>Re: Bypass/Disable Policy for destination address.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bypass-disable-policy-for-destination-address/m-p/356272#M87648</link>
      <description>&lt;P&gt;Of course there are different IPs I'm trying different configuration from different PC.&lt;/P&gt;&lt;P&gt;But no result with rule 3 or 4 as I expect.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The rule 3 is as you describe before, (source address and destination address) but if try no works, or I check with "highligt unused rules" it marks the rule.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So source IP can be any in the Lan basically 192.168.14.0/24 destination ip can be something else 62.100.200.100; but my goal is not to set the client IP on the rule, but only the destination IP if them change; if possibile, of course.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Oct 2020 15:48:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bypass-disable-policy-for-destination-address/m-p/356272#M87648</guid>
      <dc:creator>mandrake</dc:creator>
      <dc:date>2020-10-14T15:48:00Z</dc:date>
    </item>
    <item>
      <title>Re: Bypass/Disable Policy for destination address.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bypass-disable-policy-for-destination-address/m-p/356273#M87649</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Try the following:&lt;/P&gt;
&lt;P&gt;Source Zone = trust&lt;/P&gt;
&lt;P&gt;Source IP = any&lt;/P&gt;
&lt;P&gt;Destination zone = Untrust_IS&lt;/P&gt;
&lt;P&gt;Destination IP's =&amp;nbsp;&lt;SPAN&gt;62.100.200.100 (or group or IP/s subnets etc.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Also make sure to enable the rule as they appear to be disabled, all italics, at the moment.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Oct 2020 15:54:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bypass-disable-policy-for-destination-address/m-p/356273#M87649</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2020-10-14T15:54:17Z</dc:date>
    </item>
    <item>
      <title>Re: Bypass/Disable Policy for destination address.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bypass-disable-policy-for-destination-address/m-p/356406#M87653</link>
      <description>&lt;P&gt;It was my first try before write in this blog, but doesn't work.&lt;/P&gt;&lt;P&gt;Next I try adding the source IP also and doesn't work too (see rule 3).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Oct 2020 06:28:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bypass-disable-policy-for-destination-address/m-p/356406#M87653</guid>
      <dc:creator>mandrake</dc:creator>
      <dc:date>2020-10-15T06:28:30Z</dc:date>
    </item>
    <item>
      <title>Re: Bypass/Disable Policy for destination address.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bypass-disable-policy-for-destination-address/m-p/356521#M87665</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Not sure what is happening incorrectly. However these policies should work correctly. Please make sure that the policies have the proper fields filled in, the policy is enabled, and the configuration is commited.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If this still doesnt work, I say contact support.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Thu, 15 Oct 2020 14:05:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bypass-disable-policy-for-destination-address/m-p/356521#M87665</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2020-10-15T14:05:36Z</dc:date>
    </item>
    <item>
      <title>Re: Bypass/Disable Policy for destination address.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bypass-disable-policy-for-destination-address/m-p/356522#M87666</link>
      <description>&lt;P&gt;OK so, I need to contact support.&lt;/P&gt;&lt;P&gt;Thanks for your help.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Oct 2020 14:21:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bypass-disable-policy-for-destination-address/m-p/356522#M87666</guid>
      <dc:creator>mandrake</dc:creator>
      <dc:date>2020-10-15T14:21:04Z</dc:date>
    </item>
  </channel>
</rss>

