Policy

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Policy

L3 Networker

Hi All,

 

Can we configure a single policy , giving user-id's and few different IP address as source.

Will both mentioned user id's and IP address are able reach the destinations which was allowed.

 

 

2 accepted solutions

Accepted Solutions

Cyber Elite
Cyber Elite

Hello,

I would recommend two policies. One that has the User-id's and another that has the source IP's. The way the Palo Alto reads policies is top to bottom and left to right. So if you have a policy with both user-id's and source IP's, both conditions must exist.

 

Hope that helps.

View solution in original post

L3 Networker

Thanks @OtakarKlier , @Raido_Rattameister  for giving the clarity.

 

 

View solution in original post

3 REPLIES 3

Cyber Elite
Cyber Elite

You can use both username field and source IP field filled in same rule.

 

Let's assume you have users John and Mary in username field and IPs 192.168.1.5 and 192.168.1.20 IPs in source IP field.

This means that traffic from users John or Mary will match to the rule if their IP is either 192.168.1.5 or 192.168.1.20

 

So if you look at the security policy page there is "OR" between items in same column and "AND" between columns.

Source user is either John OR Mary with source IP either 192.168.1.5 OR 192.168.1.20

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

Cyber Elite
Cyber Elite

Hello,

I would recommend two policies. One that has the User-id's and another that has the source IP's. The way the Palo Alto reads policies is top to bottom and left to right. So if you have a policy with both user-id's and source IP's, both conditions must exist.

 

Hope that helps.

L3 Networker

Thanks @OtakarKlier , @Raido_Rattameister  for giving the clarity.

 

 

  • 2 accepted solutions
  • 1459 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!