<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Enabling Security Features in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/enabling-security-features/m-p/379301#M89558</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11943"&gt;@kiwi&lt;/a&gt;&amp;nbsp; Thanks&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As i mentioned , we are still having few rules where we are using port based and not APP ID but we are in transition phase;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know of Best Practices document ;&amp;nbsp; Is it OK that we apply these security profiles in alert mode as mentioned in best Pratices document&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and then observe.&lt;/P&gt;&lt;P&gt;and later on move to more strict actions&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it OK to apply Security Profiles to the rules which dont have APP ID , will Security profiles work without APP-ID , just asking ?&lt;/P&gt;</description>
    <pubDate>Tue, 12 Jan 2021 13:28:30 GMT</pubDate>
    <dc:creator>FWPalolearner</dc:creator>
    <dc:date>2021-01-12T13:28:30Z</dc:date>
    <item>
      <title>Enabling Security Features</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/enabling-security-features/m-p/379242#M89553</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;We have a customer running a cluster of PA 3060 .&amp;nbsp;&lt;/P&gt;&lt;P&gt;The goal is to enable security features on at least 30-40 percent of the rules initially . like&lt;/P&gt;&lt;P&gt;URL Filtering&amp;nbsp;&lt;/P&gt;&lt;P&gt;AntiVirus&lt;/P&gt;&lt;P&gt;Antispyware&lt;/P&gt;&lt;P&gt;Wildfire&lt;/P&gt;&lt;P&gt;Vulnerability Assessment&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are there any Best practices rules which covers or are generic to most ( if not all) organisations ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SSL Decryption is at later stage . The rules where these features are required to be implemented have mostly APP-ID enabled .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But how to start with piratically . I have read Best Practices guide but it is more theory . Do anyone has a LAB or sample dump of rule base for each of the above Security features&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jan 2021 10:03:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/enabling-security-features/m-p/379242#M89553</guid>
      <dc:creator>FWPalolearner</dc:creator>
      <dc:date>2021-01-12T10:03:12Z</dc:date>
    </item>
    <item>
      <title>Re: Enabling Security Features</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/enabling-security-features/m-p/379255#M89554</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/133520"&gt;@FWPalolearner&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You might want to check out the Best Practice Assessment page here on LIVE which will provide you with loads of information on best practices: &lt;A href="https://live.paloaltonetworks.com/t5/best-practice-assessment/ct-p/Best_Practice_Assessment" target="_blank" rel="noopener"&gt;https://live.paloaltonetworks.com/t5/best-practice-assessment/ct-p/Best_Practice_Assessment&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;A good place to start would be to run the Best Practice Assessment in the Customer Support Portal and then, based on the output report, move forward from there.&amp;nbsp; A detailed video on how to do that can be found on the LIVEcommunity YouTube channel : &lt;A href="https://www.youtube.com/watch?v=WJSGCDdN2Q4" target="_blank" rel="noopener"&gt;https://www.youtube.com/watch?v=WJSGCDdN2Q4&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;cheers !&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jan 2021 10:34:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/enabling-security-features/m-p/379255#M89554</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2021-01-12T10:34:41Z</dc:date>
    </item>
    <item>
      <title>Re: Enabling Security Features</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/enabling-security-features/m-p/379301#M89558</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11943"&gt;@kiwi&lt;/a&gt;&amp;nbsp; Thanks&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As i mentioned , we are still having few rules where we are using port based and not APP ID but we are in transition phase;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know of Best Practices document ;&amp;nbsp; Is it OK that we apply these security profiles in alert mode as mentioned in best Pratices document&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and then observe.&lt;/P&gt;&lt;P&gt;and later on move to more strict actions&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it OK to apply Security Profiles to the rules which dont have APP ID , will Security profiles work without APP-ID , just asking ?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jan 2021 13:28:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/enabling-security-features/m-p/379301#M89558</guid>
      <dc:creator>FWPalolearner</dc:creator>
      <dc:date>2021-01-12T13:28:30Z</dc:date>
    </item>
  </channel>
</rss>

