Security policy using group in negate form

Not applicable

Security policy using group in negate form


is it possible to create a security policy with user/group with NOT form?

for example :  LAN => WAN   !domain-group   any   all-app   deny

My task is to create a rule in order to block all known users except those belongs to a specific domain group indentified correctly in the PAN GUI via LDAP handshake.

I've tried introducing a simple "!" simbol before the group name. Commit is OK but in practice nothing happened.

If somebody has tried succesfully a smarter solutions please inform me.


L4 Transporter

Re: Security policy using group in negate form

There are certain fields that can be negated (e.g. source and destination address) but I don't believe you can negate by source user group.  The way to accomplish this is to use two rules in this order:

  1. LAN -> WAN  domain-group  any  all-app  Allow
  2. LAN -> WAN  any-user  any  all-app  Deny



Not applicable

Re: Security policy using group in negate form

Sometimes is quite useful deny a specific source in the beginning rather than apply the classic "deny any any" at the end.

But if is not possible using the negate form of a source group/user then the solution you proposed it's the only that works.

Thanks for support

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!