05-14-2020 09:31 AM
Hi All,
I have set all my zones with zone protection but after running BPA the zone protection adoption result is 90%, i have tested same on other firewall and get 97%, what i'm missing, Is it possible to get 100%?
Online manual says: (https://docs.paloaltonetworks.com/best-practices/9-0/bpa-getting-started/evaluate-security-policy-ca...)
—Adoption of Zone protection across Security policy allow rules. The percentage value is based on the total number of allow rules in which the source zone has a Zone Protection profile configured. The BPA doesn’t count disabled rules.
If all zones have zone protection then is not possible there is an allow rule without zone protection on source zone.
Same concept on Antivirus, urlfiltering, etc and I can get 100% without problems.
Thanks!
05-14-2020 10:27 AM
05-14-2020 02:19 PM
Hi Phoenix,
Yes all zones have zone protection profiles applied. I have shared the reports to bpa@paloaltonetworks.com.
Thanks
08-27-2021 04:13 PM
I've had the same issue for a long time, and just created a post for a similar issue. The BPA tool may be given a false positive for Source Zone Any to Destination Zone Any and Untrust. Feels like a software bug. I have several similar issues I am trying to resolve.
08-27-2021 04:50 PM
Funnily enough, I think I traced half of the exceptions to rules created to satisfy the Best Practice Assessment (based on PA's documentation) such as Sinkhole, Drop Inbound PANW Malicious IP, Drop Outbound PANW Malicious IP, BPA SSH Proxy, etc.
08-27-2021 06:19 PM
It's impossible to get 100%. I figured out the bug, and it is impossible to get 100%. You have to change every single Source Zone that is Any replacing it will each zone. Once you do that, intrazone-default and interzone-default still show up with Zone Protection Profile not enabled.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!