policy is clear yet traffic is still DENIED

Showing results for 
Show  only  | Search instead for 
Did you mean: 

policy is clear yet traffic is still DENIED

L1 Bithead

hi all, we have a policy that clearly states FROM and TO objects and SMB_override (custom app, I presume, created earlier) as the application. The service is configured as Application-default. As per Monitor, it goes straight through to the deny rule ignoring our Allow rule. The application is correctly identified, the port is right. all looks good. Yet it's being denied. It's not the first time PA does it. It's very frustrating. People now want ANY to ANY because PA works half the time


If the rule isn't there on the firewall, that means it hasn't been pushed down from Panorama yet, which would explain why the traffic is hitting the deny rule

Tom Piens
PANgurus - SASE and Strata specialist; (co)managed services, VAR and consultancy
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!