Nominated Discussion: Best Practice for Allow Internet IP

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Community Team Member
Did you find this article helpful? Yes No
100% helpful (1/1)

This article is based on a discussion, Best practice to allow Internet IPs, posted by @thanawat_l and answered by @PavelK . Read on to see the discussion and solution!

 

 I want to optimize my security policy. I have many rules that allow any, but I want to change from any to internet IP. Does PaloAlto have an Internet IP object by default? or how can I define internet IP space in address?

 

Screen Shot 2022-07-12 at 12.26.52 PM.png

Solution: You can do it reverse by using "negate" in policy to allow anything except reserved RFC1918 addresses that are not routable on the internet. 

 

For these ranges there are Palo Alto built-in objects including class D IP ranges that you can exclude from policy and allow anything also on internet.

 

 

Rate this article:
Register or Sign-in
Labels
Article Dashboard
Version history
Last update:
‎07-13-2022 05:34 AM
Updated by: