I've got a Palo Alto FW HA Active/Passive pair, connected to two different Cisco switches (one for Edge traffic, the other as a DMZ switch). The Cisco switch interface for one of the FW pairs is ...
No it's not...because an exploit could be propagated via malicious website, for example. Now you've got machines communicating back outbound without restriction. Malware Command and control? wouldn't ...