<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Security Policy Rule application and service configuration in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-rule-application-and-service-configuration/m-p/422693#M94083</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/181759"&gt;@Ben-Price&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I'm not exactly sure what you're asking to be honest. Are you trying to combine 'any' and 'application-default' in the same rulebase entry? You can't specify 'any' and then list individual services, likewise you can't specify 'application-default' and then list additional services, and lastly you can't specify 'any' and 'application-default'.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 28 Jul 2021 15:08:57 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2021-07-28T15:08:57Z</dc:date>
    <item>
      <title>Security Policy Rule application and service configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-rule-application-and-service-configuration/m-p/422567#M94077</link>
      <description>&lt;P&gt;&amp;nbsp;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have an issue where, Panorama had some security policy rules that had the below configuration on them:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;SPAN&gt;“Any” is listed in combination with specific ports under services in a given rule&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;“application-default” is listed in combination with specific ports under services in a given rule&lt;/SPAN&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;SPAN&gt;The Panorama was then upgraded from 9.0.11 to 9.1.0 and during the upgrade process the Panorama through an error saying that you are unable to have this type of configuration on a security policy rule. The rule's were tidied up and the upgrade completed.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;My question's are:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;1. Obviously that type of config on a rule is redundant, but are you able to have that type of configuration on a security policy rule in Panorama or an a NGFW? When testing having '&lt;/SPAN&gt;any' or 'application default' and a service selected on a security policy, PAN doesn't allow you to do it. The firewall automatically switches to one or the other before you perform the commit.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. Is this something PAN may have changed between OS releases?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3. Has the upgrade just exposed this incorrect configuration? If so, why was able to be commited in the first place?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance for any advise here.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jul 2021 05:33:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-rule-application-and-service-configuration/m-p/422567#M94077</guid>
      <dc:creator>Ben-Price</dc:creator>
      <dc:date>2021-07-28T05:33:13Z</dc:date>
    </item>
    <item>
      <title>Re: Security Policy Rule application and service configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-rule-application-and-service-configuration/m-p/422693#M94083</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/181759"&gt;@Ben-Price&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I'm not exactly sure what you're asking to be honest. Are you trying to combine 'any' and 'application-default' in the same rulebase entry? You can't specify 'any' and then list individual services, likewise you can't specify 'application-default' and then list additional services, and lastly you can't specify 'any' and 'application-default'.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jul 2021 15:08:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-rule-application-and-service-configuration/m-p/422693#M94083</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-07-28T15:08:57Z</dc:date>
    </item>
    <item>
      <title>Re: Security Policy Rule application and service configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-rule-application-and-service-configuration/m-p/422845#M94100</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks, that is what I thought. I am unable to replicate the issue when I try to create such a rule in my lab, but our client has forwarded me a config file from before they upgraded their Panorama and this type of config looks to be present? (see below).&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="BenPrice_0-1627515801130.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/35302iAEDDC8B1D4202365/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="BenPrice_0-1627515801130.png" alt="BenPrice_0-1627515801130.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="BenPrice_1-1627515854252.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/35303iA7DDA6F338F6D084/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="BenPrice_1-1627515854252.png" alt="BenPrice_1-1627515854252.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jul 2021 23:46:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-rule-application-and-service-configuration/m-p/422845#M94100</guid>
      <dc:creator>Ben-Price</dc:creator>
      <dc:date>2021-07-28T23:46:10Z</dc:date>
    </item>
  </channel>
</rss>

