Rule tagging best practice and guidelines

Showing results for 
Show  only  | Search instead for 
Did you mean: 

Rule tagging best practice and guidelines

L4 Transporter

Hi ,


Can someone share best pratices and guidelines on how to use tags on PA ?


L3 Networker



Tags are nothing but you can create colour-coded labels for use in various places within the firewall web configuration. These labels can be visual aids which help you more quickly locate information.


Tags can be leveraged to groups, filters or easily identified many other objects. Like security zones, policy rules, or address objects can be tagged up to 64 tags per object.


With the Tags defined, you can assign them to your security rules. You will assign the Allow tag to all rules which have an action of Allow. You will assign the Blocked tag to all rules which have an action of Deny.



To effectively utilizing tagging admin can make tagging mandatory by following steps.

> Device 


                    > management 

                      [policy rule base settings]




Best Regards,







Cyber Elite
Cyber Elite


There's really no best practice guide as far as I'm aware, because how someone uses tags would very by deployment. Functionally I notice them the most in people's address objects due to the ability to tag address objects with a dedicated tag and using that tag in a dynamic address-group assignment. 

When you start looking at tags in security and NAT rulebase entries for example, they become more of a visual and sorting aid. You can easily sort through the rulebase by the tag/member search, which makes finding rules tagged really easy. So you might create a tag for all your VDI rulebase entires and do tags for particular services you have, or you could simply tag everything with the zones associated with them so your rulebase is color coded (or both). 



Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!