- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Enhanced Security Measures in Place: To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.
12-16-2013 05:07 PM
When creating security policies would it be better to create a separate policy for inbound and outbound traffic, trusted and untrusted, per user group or one policy to manage both ways to minimize number of policies
12-16-2013 10:56 PM
Hello MemphisBrothers,
Most deployments choose to have separate rules for inbound and outbound traffic in order to properly log the security rule permitting the respective traffic.
By doing this, you could also be more granular and selective in the traffic permitted in or out of your network.
If you only need to permit the same type of traffic in and out, and don't care too much about individual control on either of the directions, then you can create one policy for both directions to minimize number of policies.
Regards,
tasonibare
12-17-2013 03:23 AM
Hello guys
a good way is:
you don't have to create on both direction the rule.
you need to create only a rule to allow the traffic base on the initiation side of this traffic, on which you could activate log at start or at end session, we prefere at end session to minimise logs.
and If you want to have a log for all drop packet, create at the bottom of rule list a deny all rule base on any zone src, any zone dst, and any app with a deny action and log at start session.
12-17-2013 04:57 PM
That's how we are doing it. I do like more granular management to troubleshoot the apps attached to multimedia sites better.
12-18-2013 12:16 AM
Ok in this case you just have to follow the deny action in the log traffic, that could show you what application is reconized by palo even multimedia apps or website multimedia if you have the url categorization enabled.
and create rule base on application or url categorie or service to allow that you want to allow.
regard's
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!