View Rules by Tag Group
Focus
Focus
Network Security

View Rules by Tag Group

Table of Contents

View Rules by Tag Group

View your policy rulebase as tag groups.
Where Can I Use This?
What Do I Need?
  • NGFW (PAN-OS & Panorama Managed)
  • Prisma Access (Panorama Managed)
Check for any license or role requirements for the products you're using.
View your policy rulebase as tag groups to visually group rules based on the tagging structure you created. In this view, you can perform operational procedures such as adding, deleting, and moving the rules in the selected tag group more easily. Viewing the rulebase as tag groups maintains the rule evaluation order and a single tag may appear multiple times throughout the rulebase to visually preserve the rule hierarchy.
You must create the tag before you can assign it as a group tag on a rule. Security rules that are already tagged on upgrade to PAN-OS 9.0 have the first tag automatically assigned as the Group tag. Before you upgrade to PAN-OS 9.0, review the tagged rules in your rulebase to ensure rules are correctly grouped. You must manually edit each tag rule and configure the correct Group tag if your rules are grouped incorrectly after you upgrade to PAN-OS 9.0.
  1. Create and Apply Tags you want to use for grouping rules.
  2. Assign a security rule to a tag group.
    1. Create a security rule. Refer to Create a Security Policy Rule for more information on creating security rules.
    2. In the
      Group Rules by Tag
      field, select the tag from the drop-down and click
      OK
      .
    3. Commit
      your changes.
  3. View your policy rulebase as groups.
    1. (
      Panorama only
      ) From the
      Device Group
      , select the device group rulebase to view or view all Shared rules.
    2. Click
      Policies
      and select the rulebase where you created the rules in Step 2.
    3. Select the
      View Rulebase as Groups
      option (at the bottom).
      Rules not assigned a tag group display as
      None
      .
  4. Perform Group operations as needed.
    1. Click
      Group
      to perform group operations for rules in the selected tag group.
      • (
        Panorama only
        )
        Move rules in group to a different rulebase or device group
        —Move all security rules in the selected tag group to the Pre-Rulebase or Post-Rulebase or move them to a different device group.
      • Change group of all rules
        —Move all rules in the selected tag group to a different tag group.
      • Move all rules in group
        —Move all rules in the selected tag group to change the rule priority order.
      • Delete all rules in group
        —Delete all rules in the selected tag group.
      • Clone all rules in group
        —Clone all rules in the selected tag group.
    2. Commit
      your changes.

Tag Browser

Tags allow you to identify the purpose or function of a security rule and help you better organize your policy rulebase. PAN-OS 11.1 introduces the ability to visually group and manage your policy rulebase using the assigned tags. When viewing your policy rulebase using tags, you can perform operation procedures such as adding, deleting, or moving the rules with the applied tag more easily. Viewing your policy rulebase using tags maintains the rule evaluation order.
For firewalls managed by a Panorama management server, you can create and assign tags to security rules from Panorama. Both Panorama, managed firewalls, and standalone firewalls running PAN-OS 10.2.5 or later 10.2 release, PAN-OS 11.0.3 or later 11.0 release, or any PAN-OS 11.1 release support policy rulebase base management using tags. Policy rulebase management using tags is supported for all policy types.
  1. (
    Panorama-managed firewalls
    ) Palo Alto Networks recommends you log in to the Panorama web interface to manage the policy rulebase for all managed firewalls belonging to the same device group.
  2. Create and apply tags to the security rules you created.
    You must apply tags to the security rule
    Tag
    field and not the
    Group Rules by Tag
    field.
  3. Select
    Policies
    and change the policy rulebase view from the
    Default View
    to
    Rulebase by Tags
    .
    (
    Panorama-managed firewalls
    ) You must also select a
    Device Group
    for which to manage the policy rulebase.
    On the left-hand size, the
    Tag Browser
    is displayed and all tags applied to all rules in the policy rulebase, the number of security rules with the tag applied, and the
    Rule Number
    indicating the rule order for all security rules within the policy rulebase with the tag applied.
  4. Select the Tag Browser display settings.
    1. (
      Optional
      ) Use the search bar to search for a specific tag.
    2. Keep enabled or disable
      Filter by first tag in rule
      .
      When enabled, the Tag Browser displays the
      Rule Count
      and
      Rule Number
      data based on the first tag applied to each security rule when multiple tags are applied. When disabled, the Tag Browser displays total
      Rule Count
      and
      Rule Number
      data when multiple tags are applied to your security rules.
    3. Select how to order tags in the Tag Browser.
      • Rule Order
        —Order the security rule tag data in the Tag Browser data based on how policy rules are ordered in the policy rulebase. This may mean that a tag applied to multiple security rules will display multiple times in the Tag Browser if the tagged policy rules are dispersed throughout the policy rulebase.
      • Alphabetical
        —Order the security rule tag data in the Tag Browser based on the alphabetical order of applied tags.
  5. Apply or remove tags from the Tag Browser.
    The Tag Browser allows you to both apply a tag to security rules within the policy rulebase, and remove a tag from all security rules where the tag is currently applied.
    • Apply a tag from the Tag Browser
    You can also drag and drop tags you want to apply from the Tag Browser to the security rule you want to apply it to.
    1. In the policy rulebase, select one or more security rules that you want to apply a tag to.
    2. In the Tag Browser
      Tag (Rule Count)
      column, select one or more tags you want to apply to the selected security rules.
    3. Expand the tag options and
      Apply Tag to the Selection(s)
      .
      Review which tags you are apply to the selected security rules and click
      Yes
      to apply the tags.
    • Remove tags from the Tag Browser
    1. In the Tag Browser
      Rule Number
      column, expand the tag options and
      Untag Rule(s)
      .
    2. A confirm window is displayed to confirm you want to untag your security rules.
      You can remove the tags from only the selected security rules or check
      Untag all the rules with the selected tag
      to remove the tag from all security rules with the tag.
    3. Click
      Yes
      to untag all security rules that have the selected tag applied.
  6. Move tagged rules within your the policy rulebase.
    You can use the Tag Browser to move multiple tagged rules at once to change the policy rulebase hierarchy as needed.
    1. Select the
      Rule Order
      Tag Browser display setting.
    2. In the Tag Browser
      Rule Number
      column, expand the tag options and
      Move Rule(s)
      .
      Alternatively, you can drag and drop rules to reorder them in the policy rulebase.
    3. Select the tag around which you want to move.
    4. Move Before
      or
      Move After
      as needed.
  7. Add a new security rule from the Tag Browser.
    You can add a new security rule with tags already assigned directly from the Tag Browser. The new security rule is added as the lowest rule in the rule order based on the selected tag.
    1. Select the
      Rule Order
      Tag Browser display setting.
    2. In the Tag Browser
      Rule Number
      column, expand the tag options and
      Add New Rule
      and configure the security rule as needed.
  8. Filter the policy rulebase using a tag.
    In the Tag Browser
    Rule Number
    column, expand the tag options and
    Filter
    the policy rulebase. This allows you to apply one or more tag search filters to the policy rulebase to narrow down the list of security rules displayed.

Recommended For You