Security policy match troubleshooting fields in the web
Select the policy match test to execute.
) Select device
specify which devices and virtual systems for which to test the
policy functionality. Admin and device group & Template users
are presented with the devices and virtual systems based on their
access domain. Additionally, you can select the Panorama management
server as a device.
) Selected Devices
Lists the devices and virtual systems selected
Enter the zone where the traffic originated.
Select the destination zone of the traffic.
Enter the IP address where the traffic originated.
Enter the destination IP address of the
Enter the specific destination port for
which traffic is intended.
Enter the user from which the traffic originated.
Enter the IP protocol used for routing.
Can be 0 to 255.
Show all potential match rules
until first allow rule
Enable this option to show
all potential rule matches until the first matched rule result.
Disable (clear) to return only the first matched rule in the test
Select the application traffic
you want to test.
Select the traffic category you want to
) Check HIP mask
Select to check the security status of the
end device that is accessing your network.
Select to view the Result Details of the
) When executing the
test for multiple managed devices, the Results display the following
information for each device tested:
of the device group to which the firewall that is processing traffic
Firewall—Name of the firewall that is processing traffic
Status—Indicates the status of the test:
Result—Displays the test result. If the test could not be performed,
one of the following is displayed:
was not applicable to the device.
Device not connected
connection was dropped.
Shared policy disabled on device
Panorama settings on the device do not allow for the policy to be
pushed from Panorama.