<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: New PA Purchase - Rules question and any tips? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/new-pa-purchase-rules-question-and-any-tips/m-p/12553#M9200</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;better to have two rules.helps in troubleshooting...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 31 Oct 2011 22:12:09 GMT</pubDate>
    <dc:creator>zajilioss</dc:creator>
    <dc:date>2011-10-31T22:12:09Z</dc:date>
    <item>
      <title>New PA Purchase - Rules question and any tips?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/new-pa-purchase-rules-question-and-any-tips/m-p/12552#M9199</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Recently purchased a PA2020 to replace our Cisco PIX 525.&amp;nbsp; I'm in the process of auditing our cisco config and recreating it in the PA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm looking for suggestions on how to allow applications inside to outside and outside to inside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I only have two zones setup.&amp;nbsp; inside-trust &amp;amp; outside-untrust&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can I just create one rule to allow skype that lists both zones on either side of the rule?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE border="1" cellpadding="3" cellspacing="0" class="jiveBorder" style="width: 100%; border: 1px solid #000000;"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;/TD&gt;&lt;TD&gt;&lt;/TD&gt;&lt;TD&gt;source&lt;/TD&gt;&lt;TD&gt;destination&lt;/TD&gt;&lt;TD&gt;&lt;/TD&gt;&lt;TD&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TH align="center" style="background-color:#6690BC;" valign="middle"&gt;&lt;SPAN style="color: #ffffff;"&gt;&lt;STRONG&gt;name&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/TH&gt;&lt;TH align="center" style="background-color:#6690BC;" valign="middle"&gt;&lt;SPAN style="color: #ffffff;"&gt;&lt;STRONG&gt;zone&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/TH&gt;&lt;TH align="center" style="background-color:#6690BC;" valign="middle"&gt;&lt;SPAN style="color: #ffffff;"&gt;&lt;STRONG&gt;address&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/TH&gt;&lt;TH align="center" style="background-color:#6690BC;" valign="middle"&gt;&lt;SPAN style="color: #ffffff;"&gt;&lt;STRONG&gt;zone&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/TH&gt;&lt;TH align="center" style="background-color:#6690BC;" valign="middle"&gt;&lt;SPAN style="color: #ffffff;"&gt;&lt;STRONG&gt;address&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;/TH&gt;&lt;TH align="center" style="background-color:#6690BC;" valign="middle"&gt;&lt;SPAN style="color: #ffffff;"&gt;&lt;STRONG&gt;application&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/TH&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;rule1&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;inside-trust&lt;/P&gt;&lt;P&gt;outside-untrust&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;any&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;inside-trust&lt;/P&gt;&lt;P&gt;outside-untrust&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;any&lt;/TD&gt;&lt;TD&gt;skype&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;or is it better to have two rules and break it up for inside to outside and outside to inside?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE border="1" cellpadding="3" cellspacing="0" style="width: 779px; height: 86px;"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;BR /&gt;&lt;/TD&gt;&lt;TD&gt;&lt;BR /&gt;&lt;/TD&gt;&lt;TD&gt;source&lt;/TD&gt;&lt;TD&gt;destination&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TH align="center" style="background-color:#6690bc" valign="middle"&gt;&lt;SPAN style="color: #ffffff;"&gt;&lt;STRONG&gt;name&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/TH&gt;&lt;TH align="center" style="background-color:#6690bc" valign="middle"&gt;&lt;SPAN style="color: #ffffff;"&gt;&lt;STRONG&gt;zone&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/TH&gt;&lt;TH align="center" style="background-color:#6690bc" valign="middle"&gt;&lt;SPAN style="color: #ffffff;"&gt;&lt;STRONG&gt;address&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/TH&gt;&lt;TH align="center" style="background-color:#6690bc" valign="middle"&gt;&lt;SPAN style="color: #ffffff;"&gt;&lt;STRONG&gt;zone&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/TH&gt;&lt;TH align="center" style="background-color:#6690bc" valign="middle"&gt;&lt;SPAN style="color: #ffffff;"&gt;&lt;STRONG&gt;address&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;/TH&gt;&lt;TH align="center" style="background-color:#6690bc" valign="middle"&gt;&lt;SPAN style="color: #ffffff;"&gt;&lt;STRONG&gt;application&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/TH&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;rule1&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;inside-trust&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;any&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;outside-untrust&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;any&lt;/TD&gt;&lt;TD&gt;skype&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE border="1" cellpadding="3" cellspacing="0" style="width: 775px; height: 86px;"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;BR /&gt;&lt;/TD&gt;&lt;TD&gt;&lt;BR /&gt;&lt;/TD&gt;&lt;TD&gt;source&lt;/TD&gt;&lt;TD&gt;destination&lt;/TD&gt;&lt;TD&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TH align="center" style="background-color:#6690bc" valign="middle"&gt;&lt;SPAN style="color: #ffffff;"&gt;&lt;STRONG&gt;name&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/TH&gt;&lt;TH align="center" style="background-color:#6690bc" valign="middle"&gt;&lt;SPAN style="color: #ffffff;"&gt;&lt;STRONG&gt;zone&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/TH&gt;&lt;TH align="center" style="background-color:#6690bc" valign="middle"&gt;&lt;SPAN style="color: #ffffff;"&gt;&lt;STRONG&gt;address&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/TH&gt;&lt;TH align="center" style="background-color:#6690bc" valign="middle"&gt;&lt;SPAN style="color: #ffffff;"&gt;&lt;STRONG&gt;zone&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/TH&gt;&lt;TH align="center" style="background-color:#6690bc" valign="middle"&gt;&lt;SPAN style="color: #ffffff;"&gt;&lt;STRONG&gt;address&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;/TH&gt;&lt;TH align="center" style="background-color:#6690bc" valign="middle"&gt;&lt;SPAN style="color: #ffffff;"&gt;&lt;STRONG&gt;application&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/TH&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;rule2&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;outside-untrust&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;any&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;inside-trust&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;any&lt;/TD&gt;&lt;TD&gt;skype&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Either way is fine with me, I'm just looking for best practices or if having both zones listed is a bad idea or even supported.&amp;nbsp; Also if anyone has done this and found if it is a good idea or bad idea?&amp;nbsp; Gaming is another example that relates to this question as I work at a university.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 31 Oct 2011 21:29:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/new-pa-purchase-rules-question-and-any-tips/m-p/12552#M9199</guid>
      <dc:creator>nathan_gilmore</dc:creator>
      <dc:date>2011-10-31T21:29:23Z</dc:date>
    </item>
    <item>
      <title>Re: New PA Purchase - Rules question and any tips?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/new-pa-purchase-rules-question-and-any-tips/m-p/12553#M9200</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;better to have two rules.helps in troubleshooting...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 31 Oct 2011 22:12:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/new-pa-purchase-rules-question-and-any-tips/m-p/12553#M9200</guid>
      <dc:creator>zajilioss</dc:creator>
      <dc:date>2011-10-31T22:12:09Z</dc:date>
    </item>
    <item>
      <title>Re: New PA Purchase - Rules question and any tips?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/new-pa-purchase-rules-question-and-any-tips/m-p/12554#M9201</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I agree - two rules is much easier to troubleshoot. You can also find yourself shadowing rules quite easily if you combine them. The 'Show Unused Rule' feature is handy to use after a few days as you might fiind some rules you thought were required are completely redundant.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Nov 2011 00:01:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/new-pa-purchase-rules-question-and-any-tips/m-p/12554#M9201</guid>
      <dc:creator>UKRB</dc:creator>
      <dc:date>2011-11-01T00:01:40Z</dc:date>
    </item>
  </channel>
</rss>

