PA is Default Deny

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

PA is Default Deny

L3 Networker

Stupid question. Just need confirmation.

PA (42020) devices are default deny correct?

If a packet is not specifically allowed or denied by a rule; when it gets to the bottom of the rules the default action is to deny, correct?

thanks

--CH

1 accepted solution

Accepted Solutions

L6 Presenter

Yes its denied but not logged.

In order to get denied packets logged you need to manually put a security policy in the end that says:

srczone: any

dstzone: any

srcip: any

dstip: any

user: any

appid: any

service: any

options: log on session end

action: deny

View solution in original post

4 REPLIES 4

L6 Presenter

Yes its denied but not logged.

In order to get denied packets logged you need to manually put a security policy in the end that says:

srczone: any

dstzone: any

srcip: any

dstip: any

user: any

appid: any

service: any

options: log on session end

action: deny

Hi,

just be careful with such an "deny all" rule since it will break intrazone traffic (traffic ingress and egress the same zone, this also includes e.g. ping to a data interface when enabled).

You can temporarily enable logging of the default deny rule on the CLI: set system setting logging default-policy-logging

With an intrazone rule created before it, is there a good reason (security purposes ot other) not to have the Deny All rule in place at the end? Or is it more of personal preference?

Creating a Deny-All rule is bad practice, don't do it. If there is intrazone traffic (Trust to Trust for example) that has not been allowed by a previous rule, this will be denied because your Deny-All rule will be matching before the Intrazone-default rule.

 

You don't need to make a deny-all rule to see denied traffic, you can actually click the click the default intra/interzone-default rules, click "Override" next to the Clone button at the bottom to edit them, then you can enable the "Log at session end" options under the Action tab.

  • 1 accepted solution
  • 5220 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!