Is possible to get 100% Zone Protection Adoption?

cancel
Showing results for 
Search instead for 
Did you mean: 

Is possible to get 100% Zone Protection Adoption?

L1 Bithead

Hi All,

 

I have set all my zones with zone protection but after running BPA the zone protection adoption result is 90%, i have tested same on other firewall and get 97%, what i'm missing, Is it possible to get 100%?

 

Online manual says: (https://docs.paloaltonetworks.com/best-practices/9-0/bpa-getting-started/evaluate-security-policy-ca...)

Zone Protection Adoption

—Adoption of Zone protection across Security policy allow rules. The percentage value is based on the total number of allow rules in which the source zone has a Zone Protection profile configured. The BPA doesn’t count disabled rules.

 

If all zones have zone protection then is not possible there is an allow rule without zone protection on source zone.

 

Same concept on Antivirus, urlfiltering, etc and I can get 100% without problems.

 

Thanks!

5 REPLIES 5

L4 Transporter
Hi, For each Source Zone in Security rule is there is a Zone protection profile applied ? Also I may have to see how many allow rules etc are there. I can review this on your BPA report. Pls share it to bpa@paloaltonetworks.com

Hi Phoenix,

 

Yes all zones have zone protection profiles applied. I have shared the reports to bpa@paloaltonetworks.com.

 

Thanks

 

L4 Transporter

I've had the same issue for a long time, and just created a post for a similar issue.  The BPA tool may be given a false positive for Source Zone Any to Destination Zone Any and Untrust.  Feels like a software bug.  I have several similar issues I am trying to resolve.

Funnily enough, I think I traced half of the exceptions to rules created to satisfy the Best Practice Assessment  (based on PA's documentation) such as Sinkhole, Drop Inbound PANW Malicious IP, Drop Outbound PANW Malicious IP, BPA SSH Proxy, etc.

 

It's impossible to get 100%.  I figured out the bug, and it is impossible to get 100%.  You have to change every single Source Zone that is Any replacing it will each zone.  Once you do that, intrazone-default and interzone-default still show up with Zone Protection Profile not enabled.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!