About rules in
Palo Alto Networks Next Generation Firewall

Policies can be defined in Panorama by creating either Pre Rules or Post Rules. Pre Rules and Post Rules allow you to create a layered approach in implementing policies.
What are Pre Rules?
Pre rules are rules that are added to the top of the rule order and are evaluated first. You can use pre rules to enforce the acceptable use of a policy for an organization; for example, to block access to specific URL categories, or to allow DNS traffic for all users.
What are Post Rules?
Post rules are rules that are added at the bottom of the rule order and are evaluated after the pre rules and locally defined on the device. Post rules typically include rules to deny access to traffic, based on the App ID, User ID, or Service.