Shadow Rule Notice - Really Not a Shadow

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Shadow Rule Notice - Really Not a Shadow

L3 Networker

I have a firewall (lab unit) with version 9.1 and I configured two Security Policy Rules.

The top rule (1) is Trust to Untrust, a source user is a group, all default options, and an Action of Deny.

The second rule (2) is Trust to Untrust, a source user is a group (different from above), all default options, and an Action of Allow.

 

When I commit the changes I receive a Rule Shadow warning stating rule 1 is shadowing rule 2. The commit succeeds but although both rules are the same, except for Deny and Allow, each is only different by the Source User and I would have thought it would know that. I assume this logic is not included in Shadow checks?

Thanks for any insight.

 

Jeff

Passionate about network infrastructure and all things Palo Alto Networks.
1 accepted solution

Accepted Solutions

Cyber Elite
Cyber Elite

@jeff6strings,

This is expected logic in the configuration validation, and while 9.1 made it better you won't see any major improvements until you get to utilize 10.0 in production. Thankfully PAN is finally taking notice that this is super annoying and can lead to admins missing more critical things when they essentially get trained to ignore commit warnings.

View solution in original post

3 REPLIES 3

L2 Linker

Hi,

 

I also noticed this behaviour with 9.0.9 (maybe other)...

 

Regards,

 

HA

Cyber Elite
Cyber Elite

@jeff6strings,

This is expected logic in the configuration validation, and while 9.1 made it better you won't see any major improvements until you get to utilize 10.0 in production. Thankfully PAN is finally taking notice that this is super annoying and can lead to admins missing more critical things when they essentially get trained to ignore commit warnings.

Thank you for all the responses and hopefully, this is addressed in the coming versions.

 

Jeff

Passionate about network infrastructure and all things Palo Alto Networks.
  • 1 accepted solution
  • 5827 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!