<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Application  with Custom Signature &amp;amp; Layer 7 Processing in Custom Signatures</title>
    <link>https://live.paloaltonetworks.com/t5/custom-signatures/application-with-custom-signature-amp-layer-7-processing/m-p/236332#M273</link>
    <description>&lt;P&gt;my understanding is that it will continue to scan for other apps in custom app if it does not detect any other app it will&amp;nbsp;&lt;/P&gt;&lt;P&gt;stop scanning for any other app and session is offloaded&lt;/P&gt;</description>
    <pubDate>Sat, 20 Oct 2018 15:31:06 GMT</pubDate>
    <dc:creator>MP18</dc:creator>
    <dc:date>2018-10-20T15:31:06Z</dc:date>
    <item>
      <title>Application  with Custom Signature &amp; Layer 7 Processing</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/application-with-custom-signature-amp-layer-7-processing/m-p/236160#M272</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;I have a PaloAlto PA-500 firewall on which I created my custom application based on custom signature. During the custom application creation on the Characterestics section I checked the "Continue scanning for other application" flag (refer to attached file -&amp;gt; CustomApplication-Characteristics.png).&lt;/P&gt;&lt;P&gt;I've configured a policy that allow the traffic that match my custom application and all the remaining traffic goes to default interzone policy (thus it is blocked).&lt;/P&gt;&lt;P&gt;As you can see from attached screenshot (refer to ShowSessionIdCommand.png) the firewall correctly identify the traffic and match my custom application (called Brass_FAB-TCP-2505-CMP).&lt;/P&gt;&lt;P&gt;Anyhow, I noticed that, as soon as the firewall identifies the traffic as Brass_FAB-TCP-2505-CMP, the "layer 7 processing" switch to "completed" (as shown on ShowSessionIdCommand.png) and from this moment on, within this session, any traffic flowing through the firewall will pass without any inspection.&lt;/P&gt;&lt;P&gt;Can you please clarify if this is the normal behaviour for the equipment or not? If yes, what is the purpose of the "Continue scanning for other application" flag?&lt;/P&gt;&lt;P&gt;What is the way to have the firewall continuously inspecting/analyzing the traffic that match my custom application?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks all.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="CustomApplication-Characteristics" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17234i3EBBF7CCE1908814/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="CustomApplication-Characteristics.png" alt="CustomApplication-Characteristics" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;CustomApplication-Characteristics&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ShowSessionIdCommand" style="width: 594px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17231i6567D4EA57D26EF9/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="ShowSessionIdCommand.PNG" alt="ShowSessionIdCommand" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;ShowSessionIdCommand&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Oct 2018 13:03:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/application-with-custom-signature-amp-layer-7-processing/m-p/236160#M272</guid>
      <dc:creator>Emanuele</dc:creator>
      <dc:date>2018-10-19T13:03:43Z</dc:date>
    </item>
    <item>
      <title>Re: Application  with Custom Signature &amp; Layer 7 Processing</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/application-with-custom-signature-amp-layer-7-processing/m-p/236332#M273</link>
      <description>&lt;P&gt;my understanding is that it will continue to scan for other apps in custom app if it does not detect any other app it will&amp;nbsp;&lt;/P&gt;&lt;P&gt;stop scanning for any other app and session is offloaded&lt;/P&gt;</description>
      <pubDate>Sat, 20 Oct 2018 15:31:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/application-with-custom-signature-amp-layer-7-processing/m-p/236332#M273</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2018-10-20T15:31:06Z</dc:date>
    </item>
    <item>
      <title>Re: Application  with Custom Signature &amp; Layer 7 Processing</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/application-with-custom-signature-amp-layer-7-processing/m-p/236437#M275</link>
      <description>&lt;P&gt;Thanks Mike. Can you clarify what do you mean when you say "session is offloaded"?&lt;/P&gt;&lt;P&gt;In addition,do you know if there is any way to maintain traffic scanning active after custom app has been detected?&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75039"&gt;@MP18&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;my understanding is that it will continue to scan for other apps in custom app if it does not detect any other app it will&amp;nbsp;&lt;/P&gt;&lt;P&gt;stop scanning for any other app and session is offloaded&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Oct 2018 07:38:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/application-with-custom-signature-amp-layer-7-processing/m-p/236437#M275</guid>
      <dc:creator>Emanuele</dc:creator>
      <dc:date>2018-10-22T07:38:24Z</dc:date>
    </item>
  </channel>
</rss>

