Hi All, I have an issue where, Panorama had some security policy rules that had the below configuration on them: “Any” is listed in combination with specific ports under services in a given rule “application-default” is listed in combination with specific ports under services in a given rule The Panorama was then upgraded from 9.0.11 to 9.1.0 and during the upgrade process the Panorama through an error saying that you are unable to have this type of configuration on a security policy rule. The rule's were tidied up and the upgrade completed. My question's are: 1. Obviously that type of config on a rule is redundant, but are you able to have that type of configuration on a security policy rule in Panorama or an a NGFW? When testing having 'any' or 'application default' and a service selected on a security policy, PAN doesn't allow you to do it. The firewall automatically switches to one or the other before you perform the commit. 2. Is this something PAN may have changed between OS releases? 3. Has the upgrade just exposed this incorrect configuration? If so, why was able to be commited in the first place? Thanks in advance for any advise here.
... View more