SV-228845r557387_rule
V-228845
SRG-NET-000202-ALG-000124
PANW-AG-000051
CAT II
10
Do not configure any policies or rules that violate a deny-all, permit-by-exception policy.
Configure policies that allow traffic through the device based only on the mission and system requirements.
Go to Policies >> Security
Review each of the configured security policies in turn.
Select each policy in turn; in the "Security Policy Rule" window, if the "Source Address" has "Any" selected, the "Destination Address" has "Any" selected, the "Application" has "Any" selected, and the "Action" Setting is "Allow", this is a finding.
If any Security Policy is too broad (allowing all traffic either inbound or outbound), this is also a finding.
V-228845
False
PANW-AG-000051
Go to Policies >> Security
Review each of the configured security policies in turn.
Select each policy in turn; in the "Security Policy Rule" window, if the "Source Address" has "Any" selected, the "Destination Address" has "Any" selected, the "Application" has "Any" selected, and the "Action" Setting is "Allow", this is a finding.
If any Security Policy is too broad (allowing all traffic either inbound or outbound), this is also a finding.
M
4233