- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
07-06-2023 06:55 AM
I have a block rule for some of the more egregious regions of the internet. Unfortunately, the regions use the source address within the rule on the Palo so I see no way to negate an IP address in a region being blocked.
Is there a way I'm not aware of to do this? It would be nice if you could group a rule with another and skip the next rule if the first rule applies or if the rule criteria is met it isn't necessarily an allow or deny but a "continue at rule X".
Any ideas on how to do this?
07-06-2023 09:05 AM
There's not a great way of handling this exception process outside of making a prior rule that would capture the traffic for the exceptions you want to have still be able to reach your resources unfortunately. What resources are you hoping to allow access to? The easiest way to manage things is to create exceptions to a single resource like GlobalProtect if it's a user that belongs to your organization.
07-06-2023 09:05 AM
There's not a great way of handling this exception process outside of making a prior rule that would capture the traffic for the exceptions you want to have still be able to reach your resources unfortunately. What resources are you hoping to allow access to? The easiest way to manage things is to create exceptions to a single resource like GlobalProtect if it's a user that belongs to your organization.
07-06-2023 09:23 AM
The most likely exception in the future will be for GP which is a relatively simple rule that we could add except for the fact that these block rules are SHARE pre-rules making it difficult but I think in the rule I can just target the device directly.
The other though it that we have some developers spread about that could need exceptions but it could be a number of resources making it more difficult. I was hoping to get ahead of the question before it was aske but it sounds like the only way is the way I was thinking it would have to be to start with.
Thank you.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!