<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Different Actions for Security Rules in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/different-actions-for-security-rules/m-p/385335#M90131</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/163084"&gt;@Nikko&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here are all actions explained:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/policy/security-policy/security-policy-actions.html" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/policy/security-policy/security-policy-actions.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers !&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
    <pubDate>Thu, 11 Feb 2021 10:58:25 GMT</pubDate>
    <dc:creator>kiwi</dc:creator>
    <dc:date>2021-02-11T10:58:25Z</dc:date>
    <item>
      <title>Different Actions for Security Rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/different-actions-for-security-rules/m-p/385283#M90128</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;I would like to know what are the difference between the following actions in the security rules for PA.&lt;/P&gt;&lt;P&gt;1. Deny&lt;/P&gt;&lt;P&gt;2. Drop&lt;/P&gt;&lt;P&gt;3. Reset-client&lt;/P&gt;&lt;P&gt;4. Reset-server&lt;/P&gt;&lt;P&gt;5. Reset-both&lt;/P&gt;&lt;P&gt;Which of these are the most preferred to use? Is deny or drop action also resets the connection for both server and client?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 11 Feb 2021 04:31:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/different-actions-for-security-rules/m-p/385283#M90128</guid>
      <dc:creator>Nikko</dc:creator>
      <dc:date>2021-02-11T04:31:59Z</dc:date>
    </item>
    <item>
      <title>Re: Different Actions for Security Rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/different-actions-for-security-rules/m-p/385335#M90131</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/163084"&gt;@Nikko&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here are all actions explained:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/policy/security-policy/security-policy-actions.html" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/policy/security-policy/security-policy-actions.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers !&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Thu, 11 Feb 2021 10:58:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/different-actions-for-security-rules/m-p/385335#M90131</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2021-02-11T10:58:25Z</dc:date>
    </item>
    <item>
      <title>Re: Different Actions for Security Rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/different-actions-for-security-rules/m-p/385440#M90147</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/163084"&gt;@Nikko&lt;/a&gt;&amp;nbsp;You asked:&lt;/P&gt;
&lt;P&gt;"&lt;SPAN&gt;Which of these are the most preferred to use? Is deny or drop action also resets the connection for both server and client? "&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Answer:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;It really depends on what you are wanting to do. If this is normal traffic, then a Deny would be fine.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If this is traffic that you would want the remote end to not "get a response" , then you would use Drop.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;as far as the reset.. the note states:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;A reset is sent only after a session is formed. If the session is blocked before a 3-way handshake is completed, the firewall will not send the reset.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I hope this helps.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Feb 2021 16:26:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/different-actions-for-security-rules/m-p/385440#M90147</guid>
      <dc:creator>jdelio</dc:creator>
      <dc:date>2021-02-11T16:26:37Z</dc:date>
    </item>
    <item>
      <title>Re: Different Actions for Security Rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/different-actions-for-security-rules/m-p/386075#M90205</link>
      <description>&lt;P&gt;If no&amp;nbsp;Deny&amp;nbsp;Action&amp;nbsp;is&amp;nbsp;listed, the packets will be silently discarded.&amp;nbsp;Drop-reset will discard the session's packets and send a TCP RST packet to let the client know the session has been terminated so it can gracefully close the session locally. In case the session&amp;nbsp;is&amp;nbsp;UDP or ICMP based, an ICMP Unreachable will be sent&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jan 2022 20:39:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/different-actions-for-security-rules/m-p/386075#M90205</guid>
      <dc:creator>Kamron</dc:creator>
      <dc:date>2022-01-03T20:39:12Z</dc:date>
    </item>
    <item>
      <title>Re: Different Actions for Security Rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/different-actions-for-security-rules/m-p/386303#M90228</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;@&lt;A href="https://www.imessageapp.biz/imessage-app-for-pc-download/" target="_self"&gt;iMessage PC&lt;/A&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;I would like to know what are the difference between the following actions in the security rules for PA.&lt;/P&gt;&lt;P&gt;1. Deny&lt;/P&gt;&lt;P&gt;2. Drop&lt;/P&gt;&lt;P&gt;3. Reset-client&lt;/P&gt;&lt;P&gt;4. Reset-server&lt;/P&gt;&lt;P&gt;5. Reset-both&lt;/P&gt;&lt;P&gt;Which of these are the most preferred to use? Is deny or drop action also resets the connection for both server and client?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Relies upon what you are needing to do. On the off chance that this is typical traffic, at that point a Deny would be fine. On the off chance that this is traffic that you would need the far off finish to not "get a reaction" , at that point you would utilize Drop.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Feb 2021 11:40:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/different-actions-for-security-rules/m-p/386303#M90228</guid>
      <dc:creator>Justin468</dc:creator>
      <dc:date>2021-02-23T11:40:48Z</dc:date>
    </item>
  </channel>
</rss>

