Is possible to get 100% Zone Protection Adoption?

Reply
Highlighted
L0 Member

Is possible to get 100% Zone Protection Adoption?

Hi All,

 

I have set all my zones with zone protection but after running BPA the zone protection adoption result is 90%, i have tested same on other firewall and get 97%, what i'm missing, Is it possible to get 100%?

 

Online manual says: (https://docs.paloaltonetworks.com/best-practices/9-0/bpa-getting-started/evaluate-security-policy-ca...)

Zone Protection Adoption

—Adoption of Zone protection across Security policy allow rules. The percentage value is based on the total number of allow rules in which the source zone has a Zone Protection profile configured. The BPA doesn’t count disabled rules.

 

If all zones have zone protection then is not possible there is an allow rule without zone protection on source zone.

 

Same concept on Antivirus, urlfiltering, etc and I can get 100% without problems.

 

Thanks!

Highlighted
L4 Transporter

Re: Is possible to get 100% Zone Protection Adoption?

Hi, For each Source Zone in Security rule is there is a Zone protection profile applied ? Also I may have to see how many allow rules etc are there. I can review this on your BPA report. Pls share it to bpa@paloaltonetworks.com
Highlighted
L0 Member

Re: Is possible to get 100% Zone Protection Adoption?

Hi Phoenix,

 

Yes all zones have zone protection profiles applied. I have shared the reports to bpa@paloaltonetworks.com.

 

Thanks

 

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!