{"id":207,"date":"2026-08-03T22:36:03","date_gmt":"2026-08-03T17:06:03","guid":{"rendered":"https:\/\/networkfix.in\/uncategorized\/palo-alto-security-policy-configuration\/"},"modified":"2026-09-14T04:41:25","modified_gmt":"2026-09-13T23:11:25","slug":"palo-alto-security-policy-configuration","status":"publish","type":"post","link":"https:\/\/networkfix.in\/en\/tutorials\/palo\/palo-alto-security-policy-configuration\/","title":{"rendered":"Palo Alto Security Policy Configuration with a Real-Life Example"},"content":{"rendered":"<p>Mastering <strong>Palo Alto security policy configuration<\/strong> is the foundational skill every network engineer must acquire when deploying PAN-OS firewalls. Unlike traditional stateful firewalls that rely strictly on source IP, destination IP, and port numbers, Palo Alto Networks firewalls use Application Identification (App-ID) and User-ID to enforce security at Layer 7. By default, PAN-OS enforces an implicit deny rule between different security zones, blocking all inter-zone traffic until you explicitly permit it.<\/p>\n<p>In this technical tutorial, you will learn how to design, configure, verify, and troubleshoot security policies in PAN-OS. We will construct a real-life policy architecture that grants corporate network users secure, application-aware outbound access to web services and DNS, while preventing unauthorized or unsolicited inbound sessions from penetrating your internal network.<\/p>\n<h2>Real-Life Scenario<\/h2>\n<p>Consider an enterprise environment where the internal user segment resides on network subnet <code>192.168.10.0\/24<\/code>. The organization needs to establish an outbound internet policy that satisfies strict business and operational requirements:<\/p>\n<ul>\n<li><strong>Secure Web Browsing:<\/strong> Internal corporate clients must access public web resources using encrypted HTTPS (App-ID: <code>ssl<\/code>) and standard HTTP (App-ID: <code>web-browsing<\/code>).<\/li>\n<li><strong>Controlled Name Resolution:<\/strong> Clients must reach external DNS services (App-ID: <code>dns<\/code>) strictly targeting specified public DNS servers.<\/li>\n<li><strong>Port Enforcement:<\/strong> Applications must strictly execute over their standardized default ports to prevent evasive applications from tunneling over non-standard ports.<\/li>\n<li><strong>Inbound Blocking:<\/strong> All unsolicited traffic originating from the Internet toward internal subnets must be silently dropped or blocked.<\/li>\n<\/ul>\n<h2>Lab Topology<\/h2>\n<p>The network topology consists of a internal LAN zone, a single Palo Alto Networks firewall running PAN-OS, and an untrusted internet zone. All interfaces operate as Layer 3 interfaces.<\/p>\n<pre>\n+------------------------------------+\n|   Corporate Clients (LAN)          |\n|   Subnet: 192.168.10.0\/24          |\n|   Default Gateway: 192.168.10.1    |\n+-----------------+------------------+\n                  |\n                  | Interface: ethernet1\/2 (Zone: zone-trust)\n                  v\n+-----------------+------------------+\n|    Palo Alto Networks Firewall     |\n|   PAN-OS Next-Gen Firewall         |\n+-----------------+------------------+\n                  | Interface: ethernet1\/1 (Zone: zone-untrust)\n                  | Public Egress IP: 203.0.113.10\n                  v\n+-----------------+------------------+\n|          Public Internet           |\n|   External DNS: 198.51.100.53      |\n+------------------------------------+\n<\/pre>\n<h2>Example Addressing and Objects<\/h2>\n<p>To keep configurations modular, reusable, and easy to audit, always define network objects before building security rules. The following table details the baseline parameters for this configuration lab:<\/p>\n<table>\n<thead>\n<tr>\n<th>Object Name<\/th>\n<th>Type<\/th>\n<th>Value \/ Details<\/th>\n<th>Description<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><code>zone-trust<\/code><\/td>\n<td>Security Zone<\/td>\n<td>Layer 3 (Interface <code>ethernet1\/2<\/code>)<\/td>\n<td>Internal corporate network zone<\/td>\n<\/tr>\n<tr>\n<td><code>zone-untrust<\/code><\/td>\n<td>Security Zone<\/td>\n<td>Layer 3 (Interface <code>ethernet1\/1<\/code>)<\/td>\n<td>External internet network zone<\/td>\n<\/tr>\n<tr>\n<td><code>obj-net-corp-lan<\/code><\/td>\n<td>Address Object<\/td>\n<td><code>192.168.10.0\/24<\/code><\/td>\n<td>LAB subnet representing internal users<\/td>\n<\/tr>\n<tr>\n<td><code>obj-srv-dns-primary<\/code><\/td>\n<td>Address Object<\/td>\n<td><code>198.51.100.53\/32<\/code><\/td>\n<td>LAB public DNS server address<\/td>\n<\/tr>\n<tr>\n<td><code>app-dns<\/code><\/td>\n<td>App-ID Object<\/td>\n<td><code>dns<\/code><\/td>\n<td>Predefined application for domain name resolution<\/td>\n<\/tr>\n<tr>\n<td><code>app-web-group<\/code><\/td>\n<td>Application Group<\/td>\n<td><code>ssl<\/code>, <code>web-browsing<\/code><\/td>\n<td>Container for outbound web applications<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><em>Note: The IP addresses <code>198.51.100.53<\/code> and <code>203.0.113.10<\/code> are standard RFC 5737 documentation addresses used for demonstration purposes. Adapt these values to match your specific production environment.<\/em><\/p>\n<h2>Prerequisites<\/h2>\n<p>Before implementing the Palo Alto security policy configuration, verify that the following underlying dependencies are fully operational on the firewall:<\/p>\n<ol>\n<li><strong>Interface Configuration:<\/strong> Layer 3 interfaces must be configured and assigned to their respective zones (<code>ethernet1\/2<\/code> in <code>zone-trust<\/code>, <code>ethernet1\/1<\/code> in <code>zone-untrust<\/code>).<\/li>\n<li><strong>Virtual Router Routing:<\/strong> A valid default route (<code>0.0.0.0\/0<\/code>) pointing to the next-hop ISP router must exist on the Virtual Router, along with connected routes for internal subnets.<\/li>\n<li><strong>Outbound Source NAT Policy:<\/strong> An active Source NAT (Interface Address or Dynamic IP and Port) rule must exist to translate private <code>192.168.10.0\/24<\/code> client IPs to the public interface IP (<code>203.0.113.10<\/code>) when egressing <code>zone-untrust<\/code>.<\/li>\n<li><strong>Content Updates:<\/strong> The App-ID database must be updated to the latest dynamic database version to ensure accurate signature identification.<\/li>\n<\/ol>\n<h2>Step-by-Step Palo Alto Security Policy Configuration<\/h2>\n<p>Follow these practical steps to configure the objects, application groups, and security rules inside the Web Interface (GUI).<\/p>\n<h3>Step 1: Create Address Objects<\/h3>\n<p>Define reusable address objects for the corporate subnet and the external DNS server.<\/p>\n<ol>\n<li>Navigate to <strong>Objects &gt; Addresses<\/strong>.<\/li>\n<li>Click <strong>Add<\/strong> at the bottom of the window.<\/li>\n<li>Configure the Corporate LAN Address Object:\n<ul>\n<li><strong>Name:<\/strong> <code>obj-net-corp-lan<\/code><\/li>\n<li><strong>Type:<\/strong> <code>IP Netmask<\/code><\/li>\n<li><strong>Value:<\/strong> <code>192.168.10.0\/24<\/code><\/li>\n<\/ul>\n<\/li>\n<li>Click <strong>OK<\/strong>.<\/li>\n<li>Click <strong>Add<\/strong> again to configure the DNS Server Address Object:\n<ul>\n<li><strong>Name:<\/strong> <code>obj-srv-dns-primary<\/code><\/li>\n<li><strong>Type:<\/strong> <code>IP Netmask<\/code><\/li>\n<li><strong>Value:<\/strong> <code>198.51.100.53\/32<\/code><\/li>\n<\/ul>\n<\/li>\n<li>Click <strong>OK<\/strong>.<\/li>\n<\/ol>\n<h3>Step 2: Create an Application Group<\/h3>\n<p>Group related applications together to simplify rule management and streamline policy maintenance.<\/p>\n<ol>\n<li>Navigate to <strong>Objects &gt; Application Groups<\/strong>.<\/li>\n<li>Click <strong>Add<\/strong>.<\/li>\n<li>In the <strong>Name<\/strong> field, enter <code>app-web-group<\/code>.<\/li>\n<li>Click <strong>Add<\/strong> in the Members section, then select <code>ssl<\/code> and <code>web-browsing<\/code>.<\/li>\n<li>Click <strong>OK<\/strong> to save the group.<\/li>\n<\/ol>\n<h3>Step 3: Configure the Outbound DNS Security Policy Rule<\/h3>\n<p>Create a restricted policy allowing internal clients to reach the external DNS server using the <code>dns<\/code> application.<\/p>\n<ol>\n<li>Navigate to <strong>Policies &gt; Security<\/strong>.<\/li>\n<li>Click <strong>Add<\/strong> at the bottom left to insert a new rule.<\/li>\n<li>Under the <strong>General<\/strong> tab:\n<ul>\n<li><strong>Name:<\/strong> <code>Allow-Corp-Outbound-DNS<\/code><\/li>\n<li><strong>Rule Type:<\/strong> <code>universal<\/code><\/li>\n<\/ul>\n<\/li>\n<li>Under the <strong>Source<\/strong> tab:\n<ul>\n<li><strong>Source Zone:<\/strong> Click <strong>Add<\/strong> and select <code>zone-trust<\/code>.<\/li>\n<li><strong>Source Address:<\/strong> Select <code>obj-net-corp-lan<\/code>.<\/li>\n<\/ul>\n<\/li>\n<li>Under the <strong>Destination<\/strong> tab:\n<ul>\n<li><strong>Destination Zone:<\/strong> Click <strong>Add<\/strong> and select <code>zone-untrust<\/code>.<\/li>\n<li><strong>Destination Address:<\/strong> Select <code>obj-srv-dns-primary<\/code>.<\/li>\n<\/ul>\n<\/li>\n<li>Under the <strong>Application<\/strong> tab:\n<ul>\n<li>Click <strong>Add<\/strong> and select <code>dns<\/code>.<\/li>\n<\/ul>\n<\/li>\n<li>Under the <strong>Service\/URL Category<\/strong> tab:\n<ul>\n<li>Select <strong>application-default<\/strong>.<\/li>\n<\/ul>\n<\/li>\n<li>Under the <strong>Actions<\/strong> tab:\n<ul>\n<li><strong>Action Setting:<\/strong> <code>Allow<\/code><\/li>\n<li><strong>Log Options:<\/strong> Ensure <strong>Log at Session End<\/strong> is checked.<\/li>\n<\/ul>\n<\/li>\n<li>Click <strong>OK<\/strong>.<\/li>\n<\/ol>\n<h3>Step 4: Configure the Outbound Web Security Policy Rule<\/h3>\n<p>Create a policy allowing internal clients to browse web services over HTTP and HTTPS using App-ID.<\/p>\n<ol>\n<li>Navigate to <strong>Policies &gt; Security<\/strong>.<\/li>\n<li>Click <strong>Add<\/strong>.<\/li>\n<li>Under the <strong>General<\/strong> tab:\n<ul>\n<li><strong>Name:<\/strong> <code>Allow-Corp-Outbound-Web<\/code><\/li>\n<li><strong>Rule Type:<\/strong> <code>universal<\/code><\/li>\n<\/ul>\n<\/li>\n<li>Under the <strong>Source<\/strong> tab:\n<ul>\n<li><strong>Source Zone:<\/strong> Select <code>zone-trust<\/code>.<\/li>\n<li><strong>Source Address:<\/strong> Select <code>obj-net-corp-lan<\/code>.<\/li>\n<\/ul>\n<\/li>\n<li>Under the <strong>Destination<\/strong> tab:\n<ul>\n<li><strong>Destination Zone:<\/strong> Select <code>zone-untrust<\/code>.<\/li>\n<li><strong>Destination Address:<\/strong> Select <code>Any<\/code>.<\/li>\n<\/ul>\n<\/li>\n<li>Under the <strong>Application<\/strong> tab:\n<ul>\n<li>Click <strong>Add Application Group<\/strong> (or <strong>Add<\/strong>) and select <code>app-web-group<\/code>.<\/li>\n<\/ul>\n<\/li>\n<li>Under the <strong>Service\/URL Category<\/strong> tab:\n<ul>\n<li>Select <strong>application-default<\/strong>.<\/li>\n<\/ul>\n<\/li>\n<li>Under the <strong>Actions<\/strong> tab:\n<ul>\n<li><strong>Action Setting:<\/strong> <code>Allow<\/code><\/li>\n<li><strong>Log Options:<\/strong> Ensure <strong>Log at Session End<\/strong> is enabled.<\/li>\n<\/ul>\n<\/li>\n<li>Click <strong>OK<\/strong>.<\/li>\n<\/ol>\n<h3>Step 5: Commit changes<\/h3>\n<p>Configurations in PAN-OS are staged in candidate memory until committed to active memory.<\/p>\n<ol>\n<li>Click <strong>Commit<\/strong> located in the upper-right corner of the web interface.<\/li>\n<li>Review the change summary window.<\/li>\n<li>Click <strong>Commit<\/strong> again to process and activate the rulebase.<\/li>\n<\/ol>\n<h2>CLI Configuration<\/h2>\n<p>For engineers managing firewalls via automation or terminal access, execute the following CLI commands to achieve the exact same operational state.<\/p>\n<pre><code># Enter configuration mode\nconfigure\n\n# Create Address Objects\nset address obj-net-corp-lan ip-netmask 192.168.10.0\/24\nset address obj-srv-dns-primary ip-netmask 198.51.100.53\/32\n\n# Create Application Group\nset application-group app-web-group members [ ssl web-browsing ]\n\n# Create Security Rule for DNS\nset rulebase security rules Allow-Corp-Outbound-DNS from zone-trust source obj-net-corp-lan to zone-untrust destination obj-srv-dns-primary application dns service application-default action allow log-end yes\n\n# Create Security Rule for Web Access\nset rulebase security rules Allow-Corp-Outbound-Web from zone-trust source obj-net-corp-lan to zone-untrust destination any application app-web-group service application-default action allow log-end yes\n\n# Commit changes to active running configuration\ncommit\n<\/code><\/pre>\n<p><em>Caution: Always double-check security rule order before running a commit in production. Rules evaluate top-down, and broader catch-all rules placed above specific rules can cause unintended access patterns.<\/em><\/p>\n<h2>How the Traffic Flows: Pre-NAT vs. Post-NAT Evaluation<\/h2>\n<p>Understanding packet processing logic inside PAN-OS is necessary to prevent severe configuration misstatements during security rule setup. When an outbound flow initiates from client <code>192.168.10.15<\/code> toward internet host <code>198.51.100.53<\/code>, PAN-OS processes packets through distinct pipeline stages:<\/p>\n<pre>\nIngress Packet \n[Src: 192.168.10.15, Dst: 198.51.100.53]\n       |\n       v\n1. Interface &amp; Zone Determination ---&gt; Ingress: ethernet1\/2 (zone-trust)\n       |\n       v\n2. Route Lookup (Virtual Router)  ---&gt; Egress: ethernet1\/1 (zone-untrust)\n       |\n       v\n3. NAT Policy Lookup              ---&gt; Translates Src IP to 203.0.113.10\n       |                               (Prepares state, DOES NOT apply yet)\n       v\n4. Security Policy Lookup         ---&gt; EVALUATED HERE!\n       |                               Source Zone: zone-trust\n       |                               Source IP: 192.168.10.15 (PRE-NAT)\n       |                               Destination Zone: zone-untrust (POST-NAT ZONE)\n       |                               Destination IP: 198.51.100.53 (PRE-NAT IP)\n       v\n5. Session Creation               ---&gt; State created; return traffic matches state table.\n<\/pre>\n<p>Key technical considerations regarding security policy evaluation:<\/p>\n<ul>\n<li><strong>Source Address Evaluation:<\/strong> Security policies match the original <strong>Pre-NAT Source IP<\/strong> address (<code>192.168.10.15<\/code>), not the translated public address.<\/li>\n<li><strong>Destination Address Evaluation:<\/strong> Security policies match the original <strong>Pre-NAT Destination IP<\/strong> address. (For outbound internet traffic, destination IP is unaltered, but this rule applies equally to inbound Destination NAT\/DNAT).<\/li>\n<li><strong>Destination Zone Determination:<\/strong> Security policies evaluate the <strong>Post-NAT Destination Zone<\/strong>. PAN-OS queries the routing table to determine which outgoing interface and zone the destination IP routes through.<\/li>\n<li><strong>Stateful Return Traffic:<\/strong> Because PAN-OS is a stateful firewall, symmetric return traffic originating from internet servers is automatically matched against active entries in the session table. Return traffic does <strong>not<\/strong> require a corresponding inbound rule from <code>zone-untrust<\/code> to <code>zone-trust<\/code>. Unsolicited inbound sessions remain blocked by default.<\/li>\n<\/ul>\n<h2>Verification<\/h2>\n<p>To verify that the configuration functions as designed, use both GUI monitoring utilities and operational CLI diagnostic commands.<\/p>\n<h3>1. Monitor Live Traffic Logs (GUI)<\/h3>\n<p>Navigate to <strong>Monitor &gt; Logs &gt; Traffic<\/strong>. Generate web traffic from internal client machine <code>192.168.10.15<\/code>. Apply the following search filter in the log bar:<\/p>\n<pre><code>( zone.src eq 'zone-trust' ) and ( addr.src in '192.168.10.0\/24' )<\/code><\/pre>\n<p>Verify the generated traffic log entries display the expected results:<\/p>\n<ul>\n<li><strong>Rule:<\/strong> Displays <code>Allow-Corp-Outbound-Web<\/code> or <code>Allow-Corp-Outbound-DNS<\/code>.<\/li>\n<li><strong>Application:<\/strong> Displays identified applications such as <code>ssl<\/code>, <code>web-browsing<\/code>, or <code>dns<\/code> (rather than remaining on initial TCP signatures like <code>not-applicable<\/code>).<\/li>\n<li><strong>Action:<\/strong> Displays <code>allow<\/code>.<\/li>\n<li><strong>Session End Reason:<\/strong> Displays <code>tcp-end<\/code>, <code>tcp-fin<\/code>, or <code>aging-out<\/code>.<\/li>\n<\/ul>\n<h3>2. Active Session Inspection (CLI)<\/h3>\n<p>Execute operational diagnostic commands on the firewall CLI to inspect real-time active sessions established by internal hosts.<\/p>\n<p>To view active sessions matching a specific client source address:<\/p>\n<pre><code>show session all filter source 192.168.10.15<\/code><\/pre>\n<p>To inspect granular state details for a specific session ID, execute:<\/p>\n<pre><code>show session id 12345<\/code><\/pre>\n<p>Examine the detailed session output to verify key fields:<\/p>\n<pre><code>Session           12345: \n        c2s flow: 192.168.10.15[49152] -&gt; 198.51.100.53[443]\n                  proto 6 main-state ACTIVE tracker-state ACTIVE\n                  node 0 zone-src zone-trust zone-dst zone-untrust\n        s2c flow: 198.51.100.53[443] -&gt; 203.0.113.10[1024]\n                  proto 6 main-state ACTIVE tracker-state ACTIVE\n                  node 0 zone-src zone-untrust zone-dst zone-trust\n        ...\n        app               : ssl\n        security-policy   : Allow-Corp-Outbound-Web\n        action            : allow\n        ...\n<\/code><\/pre>\n<h3>3. Security Policy Match Simulator (CLI)<\/h3>\n<p>You can test policy logic statically without generating real user traffic using the built-in policy match engine:<\/p>\n<pre><code>test security-policy-match source 192.168.10.15 destination 198.51.100.53 protocol 17 port 53 application dns from zone-trust to zone-untrust<\/code><\/pre>\n<p>The CLI output will immediately display the exact security rule matching that specific parameter set.<\/p>\n<h2>Troubleshooting<\/h2>\n<p>When security rules block traffic unexpectedly or fail to identify applications correctly, follow this structured investigation matrix:<\/p>\n<h3>Symptom 1: Web browsing hangs or drops after initial TCP SYN<\/h3>\n<ul>\n<li><strong>Likely Cause:<\/strong> App-ID identification failure or missing dependent application. Initial TCP handshakes execute on standard ports, but once payload packets arrive, App-ID shifts from generic <code>web-browsing<\/code> or TCP port 80\/443 to specific protocols (e.g., <code>panos-web-interface<\/code> or underlying protocol structures).<\/li>\n<li><strong>Check:<\/strong> Look for traffic log entries showing Action: <code>deny<\/code> or Session End Reason: <code>policy-deny<\/code> immediately following an initial handshake.<\/li>\n<li><strong>Fix:<\/strong> Ensure implicit dependencies are accounted for, or check if SSL decryption is required to accurately classify HTTPS payload applications.<\/li>\n<\/ul>\n<h3>Symptom 2: Traffic hits <code>interzone-default<\/code> implicit deny rule<\/h3>\n<ul>\n<li><strong>Likely Cause 1:<\/strong> Destination zone misconfiguration. Remember that security policy checks query the egress interface zone based on VR routing decisions. If routing points to a different zone than intended, the rule fails to match.<\/li>\n<li><strong>Likely Cause 2:<\/strong> Service field set incorrectly. Using a fixed TCP\/UDP port object instead of <code>application-default<\/code> when enforcing App-ID can cause drops if the application attempts to run over non-standard ports, or vice versa.<\/li>\n<li><strong>Check:<\/strong> Run command <code>show session all filter source 192.168.10.15<\/code> and look for dropped sessions. Check destination zone in log outputs.<\/li>\n<\/ul>\n<h3>Symptom 3: Applications fail when service is restricted to <code>application-default<\/code><\/h3>\n<ul>\n<li><strong>Likely Cause:<\/strong> Standard enterprise infrastructure running services on non-standard ports (e.g., web interface on port 8443 instead of 443).<\/li>\n<li><strong>Check:<\/strong> In Traffic Logs, inspect the destination port column. Compare the destination port against PAN-OS default app ports under <strong>Objects &gt; Applications<\/strong>.<\/li>\n<li><strong>Fix:<\/strong> Create a custom Service object matching the non-standard port (e.g., <code>TCP-8443<\/code>) and attach that service object explicitly to the rule instead of <code>application-default<\/code>.<\/li>\n<\/ul>\n<h2>Common Mistakes<\/h2>\n<p>Avoid these critical configuration mistakes frequently observed in production network environments:<\/p>\n<ul>\n<li><strong>Using &#8220;Any&#8221; Service with App-ID:<\/strong> Setting the Service field to <code>any<\/code> in a security policy allows applications to run over non-standard or arbitrary ports. Always set the Service to <code>application-default<\/code> to enforce standard port utilization unless explicit business requirements state otherwise.<\/li>\n<li><strong>Using Post-NAT IP Addresses in Security Policies:<\/strong> Configuring destination IP addresses using post-NAT translated public IPs instead of pre-NAT real addresses breaks policy matches. Always use pre-NAT IP addresses inside security policies.<\/li>\n<li><strong>Ignoring Application Dependencies:<\/strong> Certain applications rely on secondary protocols to function (e.g., specific web applications requiring <code>ssl<\/code>, <code>web-browsing<\/code>, and <code>ipsec-esp<\/code> simultaneously). Check the <strong>Dependencies<\/strong> tab under <strong>Objects &gt; Applications<\/strong> before deploying restrictive application lists.<\/li>\n<li><strong>Incorrect Rule Order:<\/strong> Placing broad top-level rules (e.g., permissive rules with wide subnet masks) above tightly defined rules renders lower rules ineffective. Maintain strict rule ordering (Specific rules at the top, general rules at the bottom).<\/li>\n<\/ul>\n<h2>Production Considerations<\/h2>\n<p>When moving from a lab environment to a mission-critical enterprise production network, enhance your security policy architecture with these advanced practices:<\/p>\n<h3>1. Attach Security Profiles (Layer 7 Threat Prevention)<\/h3>\n<p>Creating an <code>Allow<\/code> rule with App-ID guarantees traffic classification, but it does not scan content for malicious payloads. Always attach a <strong>Security Profile Group<\/strong> to every permissive outbound rule. Profile groups should include:<\/p>\n<ul>\n<li><strong>Antivirus:<\/strong> Blocks stream-based file downloads containing known malware signatures.<\/li>\n<li><strong>Anti-Spyware:<\/strong> Blocks command-and-control (C2) domain lookups and spyware phone-home traffic.<\/li>\n<li><strong>Vulnerability Protection:<\/strong> Prevents exploitation of client-side application vulnerabilities (buffer overflows, remote code execution).<\/li>\n<li><strong>URL Filtering:<\/strong> Restricts web navigation by domain reputation and URL category lists (e.g., blocking malware, phishing, and adult domains).<\/li>\n<li><strong>WildFire Analysis:<\/strong> Forwards unknown executable payloads to the WildFire cloud for real-time zero-day analysis.<\/li>\n<\/ul>\n<h3>2. SSL Decryption (Forward Proxy)<\/h3>\n<p>Over 90% of web traffic uses TLS encryption. Without SSL Decryption configured on the firewall, App-ID relies entirely on Server Name Indication (SNI) and certificate headers to identify applications. The firewall cannot inspect encrypted payload data for threats, viruses, or policy violations. Plan to deploy SSL Forward Proxy alongside your Palo Alto security policy configuration to gain complete application visibility and threat inspection.<\/p>\n<h3>3. Logging Best Practices<\/h3>\n<p>Ensure that <strong>Log at Session End<\/strong> (<code>log-end<\/code>) is enabled on custom security rules. Avoid enabling <strong>Log at Session Start<\/strong> unless required for specialized real-time session troubleshooting, as logging session starts doubles log storage consumption on log collectors and firewall storage partitions.<\/p>\n<h2>Summary<\/h2>\n<p>A structured <strong>Palo Alto security policy configuration<\/strong> forms the core defense line of your network architecture. By implementing application-aware policies instead of legacy port-based rules, you drastically minimize your attack surface and retain precise control over corporate traffic flows.<\/p>\n<p>Key concepts to keep in mind when engineering PAN-OS policies:<\/p>\n<ul>\n<li>Structure object groupings cleanly before crafting security policies.<\/li>\n<li>Always construct policies using <strong>Pre-NAT IP addresses<\/strong> combined with <strong>Post-NAT Egress Zones<\/strong>.<\/li>\n<li>Enforce strict operational security using <code>application-default<\/code> for standard service ports.<\/li>\n<li>Regularly verify live traffic sessions via CLI and Traffic Logs to validate App-ID classification.<\/li>\n<li>Augment permissive rules with comprehensive Security Profiles to defeat zero-day threats and malicious payloads.<\/li>\n<\/ul>\n<h2>Related Palo Alto Guides<\/h2>\n<ul>\n<li><a href=\"https:\/\/networkfix.in\/tutorials\/palo\/palo-alto-source-nat-configuration\/\">Palo Alto Source NAT Configuration<\/a><\/li>\n<li><a href=\"https:\/\/networkfix.in\/tutorials\/palo\/palo-alto-interfaces-zones-configuration\/\">Palo Alto Interfaces and Security Zones<\/a><\/li>\n<li><a href=\"https:\/\/networkfix.in\/tutorials\/palo\/palo-alto-virtual-router-default-route\/\">Palo Alto Virtual Router and Default Route<\/a><\/li>\n<li><a href=\"https:\/\/networkfix.in\/tutorials\/palo\/palo-alto-url-filtering-configuration\/\">Palo Alto URL Filtering Configuration<\/a><\/li>\n<\/ul>\n<h2>Frequently Asked Questions<\/h2>\n<h3>What is a Security Policy in Palo Alto?<\/h3>\n<p>A Palo Alto Security Policy determines which traffic is allowed or denied between security zones using criteria such as source, destination, application, service and user.<\/p>\n<h3>Should Palo Alto Security Policies use application-default?<\/h3>\n<p>For application-aware policies, application-default is generally preferred because it restricts applications to their standard ports unless a documented exception is required.<\/p>\n<h3>Do I need an inbound policy for return traffic?<\/h3>\n<p>No. Return traffic for an established session is handled statefully. Unsolicited inbound sessions remain blocked unless an explicit policy permits them.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Learn Palo Alto security policy configuration with a practical real-life example, step-by-step configuration, verification and troubleshooting.<\/p>","protected":false},"author":2,"featured_media":206,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","rank_math_title":"","rank_math_description":"","rank_math_focus_keyword":"","_dpc-meta-title":"","_dpc-meta-description":"","_dpc-keyword":""},"categories":[5],"tags":[28,29,32,39,31,40],"class_list":["post-207","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-palo","tag-beginner","tag-firewall-tutorial","tag-palo-alto-networks","tag-palo-alto-security-policy-configuration","tag-pan-os","tag-security-policy"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.2 (Yoast SEO v28.6) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Palo Alto Security Policy Configuration: Step-by-Step<\/title>\n<meta name=\"description\" content=\"Learn Palo Alto security policy configuration with a real-world internet access example, policy matching, logging, CLI and troubleshooting.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/networkfix.in\/en\/tutorials\/palo\/palo-alto-security-policy-configuration\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Palo Alto Security Policy Configuration with a Real-Life Example\" \/>\n<meta property=\"og:description\" content=\"Learn Palo Alto security policy configuration with a real-world internet access example, policy matching, logging, CLI and troubleshooting.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/networkfix.in\/en\/tutorials\/palo\/palo-alto-security-policy-configuration\/\" \/>\n<meta property=\"og:site_name\" content=\"NetworkFix\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-03T17:06:03+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-13T23:11:25+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/08\/palo-alto-security-policy-configuration-with-a-real-life-example-featured.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"630\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Ajay Yadav\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Ajay Yadav\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"1 minute\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/palo\\\/palo-alto-security-policy-configuration\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/palo\\\/palo-alto-security-policy-configuration\\\/\"},\"author\":{\"name\":\"Ajay Yadav\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/#\\\/schema\\\/person\\\/dac05d268c126277e74b684c5239d344\"},\"headline\":\"Palo Alto Security Policy Configuration with a Real-Life Example\",\"datePublished\":\"2026-08-03T17:06:03+00:00\",\"dateModified\":\"2026-09-13T23:11:25+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/palo\\\/palo-alto-security-policy-configuration\\\/\"},\"wordCount\":2113,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/#\\\/schema\\\/person\\\/28c6fb08b80eeae506b96250db4f30f0\"},\"image\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/palo\\\/palo-alto-security-policy-configuration\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/palo-alto-security-policy-configuration-with-a-real-life-example-featured.png\",\"keywords\":[\"Beginner\",\"Firewall Tutorial\",\"Palo Alto Networks\",\"Palo Alto security policy configuration\",\"PAN-OS\",\"Security Policy\"],\"articleSection\":[\"Palo Alto\"],\"inLanguage\":\"en\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/palo\\\/palo-alto-security-policy-configuration\\\/\",\"url\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/palo\\\/palo-alto-security-policy-configuration\\\/\",\"name\":\"Palo Alto Security Policy Configuration: Step-by-Step\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/palo\\\/palo-alto-security-policy-configuration\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/palo\\\/palo-alto-security-policy-configuration\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/palo-alto-security-policy-configuration-with-a-real-life-example-featured.png\",\"datePublished\":\"2026-08-03T17:06:03+00:00\",\"dateModified\":\"2026-09-13T23:11:25+00:00\",\"description\":\"Learn Palo Alto security policy configuration with a real-world internet access example, policy matching, logging, CLI and troubleshooting.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/palo\\\/palo-alto-security-policy-configuration\\\/#breadcrumb\"},\"inLanguage\":\"en\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/palo\\\/palo-alto-security-policy-configuration\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/palo\\\/palo-alto-security-policy-configuration\\\/#primaryimage\",\"url\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/palo-alto-security-policy-configuration-with-a-real-life-example-featured.png\",\"contentUrl\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/palo-alto-security-policy-configuration-with-a-real-life-example-featured.png\",\"width\":1200,\"height\":630,\"caption\":\"Palo Alto Security Policy Configuration with a Real-Life Example\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/palo\\\/palo-alto-security-policy-configuration\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/networkfix.in\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Palo Alto Security Policy Configuration with a Real-Life Example\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/#website\",\"url\":\"https:\\\/\\\/networkfix.in\\\/\",\"name\":\"NetworkFix\",\"description\":\"Practical Network Security &amp; Firewall Guides\",\"publisher\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/#\\\/schema\\\/person\\\/28c6fb08b80eeae506b96250db4f30f0\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/networkfix.in\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en\"},{\"@type\":[\"Person\",\"Organization\"],\"@id\":\"https:\\\/\\\/networkfix.in\\\/#\\\/schema\\\/person\\\/28c6fb08b80eeae506b96250db4f30f0\",\"name\":\"networkfix\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png\",\"url\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png\",\"contentUrl\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png\",\"width\":737,\"height\":591,\"caption\":\"networkfix\"},\"logo\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png\"},\"sameAs\":[\"http:\\\/\\\/networkfix.in\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/#\\\/schema\\\/person\\\/dac05d268c126277e74b684c5239d344\",\"name\":\"Ajay Yadav\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g\",\"caption\":\"Ajay Yadav\"},\"url\":\"https:\\\/\\\/networkfix.in\\\/en\\\/author\\\/networkfix-news-bot\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Palo Alto Security Policy Configuration: Step-by-Step","description":"Learn Palo Alto security policy configuration with a real-world internet access example, policy matching, logging, CLI and troubleshooting.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/networkfix.in\/en\/tutorials\/palo\/palo-alto-security-policy-configuration\/","og_locale":"en_US","og_type":"article","og_title":"Palo Alto Security Policy Configuration with a Real-Life Example","og_description":"Learn Palo Alto security policy configuration with a real-world internet access example, policy matching, logging, CLI and troubleshooting.","og_url":"https:\/\/networkfix.in\/en\/tutorials\/palo\/palo-alto-security-policy-configuration\/","og_site_name":"NetworkFix","article_published_time":"2026-08-03T17:06:03+00:00","article_modified_time":"2026-09-13T23:11:25+00:00","og_image":[{"width":1200,"height":630,"url":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/08\/palo-alto-security-policy-configuration-with-a-real-life-example-featured.png","type":"image\/png"}],"author":"Ajay Yadav","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Ajay Yadav","Est. reading time":"1 minute"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/networkfix.in\/tutorials\/palo\/palo-alto-security-policy-configuration\/#article","isPartOf":{"@id":"https:\/\/networkfix.in\/tutorials\/palo\/palo-alto-security-policy-configuration\/"},"author":{"name":"Ajay Yadav","@id":"https:\/\/networkfix.in\/#\/schema\/person\/dac05d268c126277e74b684c5239d344"},"headline":"Palo Alto Security Policy Configuration with a Real-Life Example","datePublished":"2026-08-03T17:06:03+00:00","dateModified":"2026-09-13T23:11:25+00:00","mainEntityOfPage":{"@id":"https:\/\/networkfix.in\/tutorials\/palo\/palo-alto-security-policy-configuration\/"},"wordCount":2113,"commentCount":0,"publisher":{"@id":"https:\/\/networkfix.in\/#\/schema\/person\/28c6fb08b80eeae506b96250db4f30f0"},"image":{"@id":"https:\/\/networkfix.in\/tutorials\/palo\/palo-alto-security-policy-configuration\/#primaryimage"},"thumbnailUrl":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/08\/palo-alto-security-policy-configuration-with-a-real-life-example-featured.png","keywords":["Beginner","Firewall Tutorial","Palo Alto Networks","Palo Alto security policy configuration","PAN-OS","Security Policy"],"articleSection":["Palo Alto"],"inLanguage":"en"},{"@type":"WebPage","@id":"https:\/\/networkfix.in\/tutorials\/palo\/palo-alto-security-policy-configuration\/","url":"https:\/\/networkfix.in\/tutorials\/palo\/palo-alto-security-policy-configuration\/","name":"Palo Alto Security Policy Configuration: Step-by-Step","isPartOf":{"@id":"https:\/\/networkfix.in\/#website"},"primaryImageOfPage":{"@id":"https:\/\/networkfix.in\/tutorials\/palo\/palo-alto-security-policy-configuration\/#primaryimage"},"image":{"@id":"https:\/\/networkfix.in\/tutorials\/palo\/palo-alto-security-policy-configuration\/#primaryimage"},"thumbnailUrl":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/08\/palo-alto-security-policy-configuration-with-a-real-life-example-featured.png","datePublished":"2026-08-03T17:06:03+00:00","dateModified":"2026-09-13T23:11:25+00:00","description":"Learn Palo Alto security policy configuration with a real-world internet access example, policy matching, logging, CLI and troubleshooting.","breadcrumb":{"@id":"https:\/\/networkfix.in\/tutorials\/palo\/palo-alto-security-policy-configuration\/#breadcrumb"},"inLanguage":"en","potentialAction":[{"@type":"ReadAction","target":["https:\/\/networkfix.in\/tutorials\/palo\/palo-alto-security-policy-configuration\/"]}]},{"@type":"ImageObject","inLanguage":"en","@id":"https:\/\/networkfix.in\/tutorials\/palo\/palo-alto-security-policy-configuration\/#primaryimage","url":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/08\/palo-alto-security-policy-configuration-with-a-real-life-example-featured.png","contentUrl":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/08\/palo-alto-security-policy-configuration-with-a-real-life-example-featured.png","width":1200,"height":630,"caption":"Palo Alto Security Policy Configuration with a Real-Life Example"},{"@type":"BreadcrumbList","@id":"https:\/\/networkfix.in\/tutorials\/palo\/palo-alto-security-policy-configuration\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/networkfix.in\/"},{"@type":"ListItem","position":2,"name":"Palo Alto Security Policy Configuration with a Real-Life Example"}]},{"@type":"WebSite","@id":"https:\/\/networkfix.in\/#website","url":"https:\/\/networkfix.in\/","name":"NetworkFix","description":"Practical Network Security &amp; Firewall Guides","publisher":{"@id":"https:\/\/networkfix.in\/#\/schema\/person\/28c6fb08b80eeae506b96250db4f30f0"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/networkfix.in\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en"},{"@type":["Person","Organization"],"@id":"https:\/\/networkfix.in\/#\/schema\/person\/28c6fb08b80eeae506b96250db4f30f0","name":"networkfix","image":{"@type":"ImageObject","inLanguage":"en","@id":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/06\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png","url":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/06\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png","contentUrl":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/06\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png","width":737,"height":591,"caption":"networkfix"},"logo":{"@id":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/06\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png"},"sameAs":["http:\/\/networkfix.in"]},{"@type":"Person","@id":"https:\/\/networkfix.in\/#\/schema\/person\/dac05d268c126277e74b684c5239d344","name":"Ajay Yadav","image":{"@type":"ImageObject","inLanguage":"en","@id":"https:\/\/secure.gravatar.com\/avatar\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g","caption":"Ajay Yadav"},"url":"https:\/\/networkfix.in\/en\/author\/networkfix-news-bot\/"}]}},"_links":{"self":[{"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/posts\/207","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/comments?post=207"}],"version-history":[{"count":2,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/posts\/207\/revisions"}],"predecessor-version":[{"id":1590,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/posts\/207\/revisions\/1590"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/media\/206"}],"wp:attachment":[{"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/media?parent=207"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/categories?post=207"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/tags?post=207"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}