Security policy using group in negate form

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Security policy using group in negate form

Not applicable

Hi,

is it possible to create a security policy with user/group with NOT form?

for example :  LAN => WAN   !domain-group   any   all-app   deny

My task is to create a rule in order to block all known users except those belongs to a specific domain group indentified correctly in the PAN GUI via LDAP handshake.

I've tried introducing a simple "!" simbol before the group name. Commit is OK but in practice nothing happened.

If somebody has tried succesfully a smarter solutions please inform me.

Regards

1 accepted solution

Accepted Solutions

L4 Transporter

There are certain fields that can be negated (e.g. source and destination address) but I don't believe you can negate by source user group.  The way to accomplish this is to use two rules in this order:

  1. LAN -> WAN  domain-group  any  all-app  Allow
  2. LAN -> WAN  any-user  any  all-app  Deny

Cheers,

Kelly

View solution in original post

2 REPLIES 2

L4 Transporter

There are certain fields that can be negated (e.g. source and destination address) but I don't believe you can negate by source user group.  The way to accomplish this is to use two rules in this order:

  1. LAN -> WAN  domain-group  any  all-app  Allow
  2. LAN -> WAN  any-user  any  all-app  Deny

Cheers,

Kelly

Sometimes is quite useful deny a specific source in the beginning rather than apply the classic "deny any any" at the end.

But if is not possible using the negate form of a source group/user then the solution you proposed it's the only that works.

Thanks for support

  • 1 accepted solution
  • 3335 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!