After enabling Web-Access Security Policy Feature, traffic is not hitting the correct security rule

After enabling Web-Access Security Policy Feature, traffic is not hitting the correct security rule

4351
Created On 10/13/22 20:19 PM - Last Modified 12/06/24 04:16 AM


Symptom


After enabling Web-Access Security Policy Feature, traffic is not hitting the correct security rule.

 



Environment


  • Cloud Managed Prisma Access
  • Web-Security Feature needs to be enabled



Cause


  • Web Security comes with default security policy enabled. 
  • Web access Security policy is enforced ahead of configured security policy rulebase.
  • This may cause the configured security policies not to work.


Resolution


Here is how the administrator can check the Security Rules when Web-security is on Cloud Managed Prisma Access:

1. Custom Web Access Security Policy under Web-Security > Web Access Policy

 <

2. Global/Default Web Access Policies under Web-Security > Web Access Policy (Refer the above image)

3. Prisma Access Default Pre-rules under Configuration > Security Policy

4. Custom Security Rules under Configuration > Security Policy

 

 

5. Prisma Access Post Security Rules under Configuration > Security Rules

 

 

Customers can either import saas_recommended policies to Web-Security or configure new custom web-access policies so that their traffic will not match the predefined Web-Access security policy.

 

 


 



Additional Information


Web-security
About-web-security
Saas-Security



Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000sZZECA2&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language