is it possible to create a security policy with user/group with NOT form?
for example : LAN => WAN !domain-group any all-app deny
My task is to create a rule in order to block all known users except those belongs to a specific domain group indentified correctly in the PAN GUI via LDAP handshake.
I've tried introducing a simple "!" simbol before the group name. Commit is OK but in practice nothing happened.
If somebody has tried succesfully a smarter solutions please inform me.
Solved! Go to Solution.
There are certain fields that can be negated (e.g. source and destination address) but I don't believe you can negate by source user group. The way to accomplish this is to use two rules in this order:
Sometimes is quite useful deny a specific source in the beginning rather than apply the classic "deny any any" at the end.
But if is not possible using the negate form of a source group/user then the solution you proposed it's the only that works.
Thanks for support
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!
The Live Community thanks you for your participation!