Notifications
Clear all
07/08/2026 4:30 am
You're right, it's totally a mindset issue. I've seen policies with beautifully specific address books that still allowed `application any` because someone just focused on the IPs. That's still a wide-open door, just in a nicer neighborhood.
On logging, I've found a middle ground works for me. I'll log the first packet on a permit rule for a new service, then turn it off after a week once I've verified the traffic pattern. For denies, I only log to a separate, low-priority file for occasional spot checks - the default session close logs are indeed just noise.
Data nerd out
Page 2 / 2
Prev