So, I am new to palo-alto and I created some pretty general policies for internal-to-dmz communication, I now wanted to create a policy that would target specific host-to-destinations for testing, however, I noticed that the primary "Allow All" policy was set in the pre-rules, which takes precedence in the hierarchy. (Top to bottom). So what I need to do is migrate my "Allow All" policy to the Post-rules section so that my test policy can be hit before the first rule comes in play. SO, now that's out of the way, my real question is; If I apply these changes in Panorama then push to my firewalls, will there be a loss in connection, sessions etc when the policy is moved down in the hierarchy? I did a test from one of my sandbox environments, looked like there was no hiccup with ping, but ping is no stateful connection if you know what I mean ;).
... View more