Search security policies of network or related IPs

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Search security policies of network or related IPs

L2 Linker

Hi,

I need to migrate a vlan from a security zone to a new one.

Which is the best way to search the related rules?

Ae1.1200 10.100.15.0/24

I need to identify the rules of this network and the rules that use a specific ip like 10.100.15.20 and so one.

 

 

 

1 accepted solution

Accepted Solutions

Cyber Elite
Cyber Elite

Hi @Charlie80 ,

 

If you use the Global Find feature for 10.100.15, it will show you every where the string is in the config.  If you did not use objects in the security policy, the matching rules will show under the Security Rules section.

 

If you used address objects in the security policy, you can expand the matching address objects, and it will show you the security policy rules where those are used.  https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/firewall-administration/use-the-web-interf...

 

You can then click on the rule from the drop down, and you will pivot to Policies > Security to edit the rule.

 

The filter bar on the Policies > Security page does not show objects that match 10.100.15, which is probably why you asked.

 

Thanks,

 

Tom

 

Help the community: Like helpful comments and mark solutions.

View solution in original post

2 REPLIES 2

Cyber Elite
Cyber Elite

Hi @Charlie80 ,

 

If you use the Global Find feature for 10.100.15, it will show you every where the string is in the config.  If you did not use objects in the security policy, the matching rules will show under the Security Rules section.

 

If you used address objects in the security policy, you can expand the matching address objects, and it will show you the security policy rules where those are used.  https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/firewall-administration/use-the-web-interf...

 

You can then click on the rule from the drop down, and you will pivot to Policies > Security to edit the rule.

 

The filter bar on the Policies > Security page does not show objects that match 10.100.15, which is probably why you asked.

 

Thanks,

 

Tom

 

Help the community: Like helpful comments and mark solutions.

Cyber Elite
Cyber Elite

One trick you can use is to search for "0.100.15.20" instead of "10.100.15.20"
If you remove one number from IP then filter is looking for exact text and don't match to 10.100.15.0/24 IPs any more.

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011
  • 1 accepted solution
  • 1117 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!