I need to create security rule and/or not to allow port 6965 to a device. Do I need both a NAT and security rule? Need to find out from vendor if port is TCP, UDP or both. I have PA-3020 running PAN-OS 8.0.13.
Solved! Go to Solution.
It sounds like you have an inbound service on port 6965 you want to block? You can do this on a PAN but... if you want to do it the PAN way, you need to figure out what application is actually talking. This way you can deny based on user/application and not port/protocol. Of course not all apps will be recognized. In this case you could make a special rule and use the "service" field in a policy rule to filter out port 6965.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!
The Live Community thanks you for your participation!