Methods for creating security policies

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Methods for creating security policies

L3 Networker

When creating security policies would it be better to create a separate policy for inbound and outbound traffic, trusted and untrusted, per user group or one policy to manage both ways to minimize number of policies

4 REPLIES 4

L3 Networker

Hello MemphisBrothers,

Most deployments choose to have separate rules for inbound and outbound traffic in order to properly log the security rule permitting the respective traffic.

By doing this, you could also be more granular and selective in the traffic permitted in or out of your network.

If you only need to permit the same type of traffic in and out, and don't care too much about individual control on either of the directions, then you can create one policy for both directions to minimize number of policies.

Regards,

tasonibare

L4 Transporter

Hello guys

a good way is:

you don't have to create on both direction the rule.

you need to create only a rule to allow the traffic base on the initiation side of this traffic, on which you could activate log at start or at end session, we prefere  at end session to minimise logs.

and If you want to have a log for all drop packet, create at the bottom of rule list a deny all rule base on any zone src, any zone dst, and any app with a deny action and log at start session.

That's how we are doing it.  I do like more granular management to troubleshoot the apps attached to multimedia sites better. 

Ok in this case you just have to follow the deny action in the log traffic, that could show you what application is reconized by palo even multimedia apps or website multimedia if you have the url categorization enabled.

and create rule base on application or url categorie  or service to allow that you want to allow.

regard's

  • 2690 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!