Security Policy Rule application and service configuration

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Security Policy Rule application and service configuration

L4 Transporter

 Hi All,

 

I have an issue where, Panorama had some security policy rules that had the below configuration on them:

 

  1. “Any” is listed in combination with specific ports under services in a given rule
  2. “application-default” is listed in combination with specific ports under services in a given rule

The Panorama was then upgraded from 9.0.11 to 9.1.0 and during the upgrade process the Panorama through an error saying that you are unable to have this type of configuration on a security policy rule. The rule's were tidied up and the upgrade completed. 

 

My question's are:

1. Obviously that type of config on a rule is redundant, but are you able to have that type of configuration on a security policy rule in Panorama or an a NGFW? When testing having 'any' or 'application default' and a service selected on a security policy, PAN doesn't allow you to do it. The firewall automatically switches to one or the other before you perform the commit.

 

2. Is this something PAN may have changed between OS releases? 

 

3. Has the upgrade just exposed this incorrect configuration? If so, why was able to be commited in the first place?

 

Thanks in advance for any advise here.

2 REPLIES 2

Cyber Elite
Cyber Elite

@Ben-Price,

I'm not exactly sure what you're asking to be honest. Are you trying to combine 'any' and 'application-default' in the same rulebase entry? You can't specify 'any' and then list individual services, likewise you can't specify 'application-default' and then list additional services, and lastly you can't specify 'any' and 'application-default'. 

L4 Transporter

Hi @BPry 

 

Thanks, that is what I thought. I am unable to replicate the issue when I try to create such a rule in my lab, but our client has forwarded me a config file from before they upgraded their Panorama and this type of config looks to be present? (see below).

BenPrice_0-1627515801130.png

 

BenPrice_1-1627515854252.png

 

Any ideas?

 

  • 1747 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!