Negate SRC or DST in CSV Security Rule Import

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Negate SRC or DST in CSV Security Rule Import

L0 Member

I'm trying to create a custom CSV to import a fairly large number of rules from a Barracuda firewall.  There's over 30 rules that are blocking traffic that has any src as not the internal network.  I'm following the CSV guide from here:

https://live.paloaltonetworks.com/t5/expedition-discussions/csv-import-how-to-guide/m-p/259392

but there's no mention how to set a rule in the csv to have a src or dst as negated within the csv.  Is that a feature built into expedition?

 

I need to have the src of all of these rules to be the negated internal networks.  How would that be formatted?

This section from the documentation doesn't include that:

sec_rule_example.png

Any help would be appreciated!

1 REPLY 1

L6 Presenter

@utahman3431 for security rule import via CSV , there is no column to specify negate on the source or destination, you will import the rule as it is and modify the rule that contain negate src or dst src by checking the negate checkbox manually. 

  • 1368 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!