I can find existing firewall rule in the Firewall policy by searching by just source IP address or Just Destination IP address but our Firewall policy rule base is huge and i need to filter it by Source IP and destination IP address (both) and possibly by port number as well , (Just like Checkpoint).
can someone kindly share screenshot of this, that how we can do this in the Palo alto FW.
So I'll actually do ya one better; the firewall actually has a built in function to test rulebase matches to ensure that traffic is actually going to match outside of just looking through the policies!
If you are using the GUI and a newer PAN-OS release, you can use the 'Test Policy Match' on the bottom right of the policies tab view. This lets you to simulate traffic flows to ensure that you do/don't have a policy already that will match the traffic.
You can also access this feature via the CLI if you aren't running one of the newer releases that exposes this feature in the GUI by building out the traffic flow with the test security-rulebase-match command.
Just in case you are still interested in filtering the security policy based on multiple criteria. Actually this is possible. You can click on the drop down in the objects to add them to the filter or only to see the syntax to create a filter. For example for filtering based on a specific source object, destination object and service object you can use the following:
(source/member eq 'OBJECTNAME') and (destination/member eq 'OBJECTNAME') and (service/member eq 'SERVICEOBJECTNAME')
perhaps a picture of you Mr Remo... ha ha..
Tags: (tag/member eq 'tagname')
Name: (name contains 'unlocate-block')
Type: (rule-type eq 'intrazone|interzone')
Source Zone: (from/member eq 'zonename')
Source Address: (source/member eq 'any|ip|object')
Source User: (source-user/member eq 'any|username|groupname')
Hip profile: (hip-profiles/member eq 'any|profilename')
Destination Zone: (to/member eq 'zonename')
Destination Address: (destination/member eq 'any|ip|object')
Destination User: (destination-user/member eq 'any|username|groupname')
Application: (application/member eq 'any|applicationname|applicationgroup|applicationfilter')
Service: (service/member eq 'any|servicename|application-default')
URL Category: (category/member eq 'any|categoryname')
This is a destination category, not a URL filtering security profile
Action: (action eq 'allow|drop|deny|reset-client|reset-server|reset-both')
stolen from here....
and here is @BPry suggestion which gets my vote...
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!