<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic custom mail app-id in Custom Signatures</title>
    <link>https://live.paloaltonetworks.com/t5/custom-signatures/custom-mail-app-id/m-p/71050#M35</link>
    <description>&lt;P&gt;hi.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'am trying to create a custom mail app-id filter, for matching; to whom mail is gonging to and from what domain.&lt;/P&gt;
&lt;P&gt;I have add smtp as a parent application in the app-id.&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/2057iBC77A57BE5FA0C6A/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="application-smtp" title="application-smtp" width="596" height="346" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My app-id is matching the helo, mail from, rcp, data. from the mail. The policy with this custom app-id is partial match, if I only has this, the data is dropt.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/2058i67ADABE748B41C6D/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="application-ports" title="application-ports" width="604" height="405" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/2059i102DAB8A8D34483B/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="application-signature" title="application-signature" width="596" height="198" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/2060iF53B6A4AF6054C3C/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="policy-rule" title="policy-rule" /&gt;&lt;/P&gt;
&lt;P&gt;If I add a new policy row with application smtp below my custom app-id, the first package that came in match smtp, and all blowing data is matching my custom app-id.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/2062i1CD7F1D4BDF838BD/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="policy-rule-smtp" title="policy-rule-smtp" /&gt;&lt;/P&gt;
&lt;P&gt;the row application smtp, is becuse to make this policy working i hade to add smtp in the rule, the problem to do so is that it also match evry smtp packaged that comes in to the firewall.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have i missed somthing? or how can I solve this?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;/Kristofer&lt;/P&gt;</description>
    <pubDate>Sun, 17 Jan 2016 10:27:02 GMT</pubDate>
    <dc:creator>klokholm</dc:creator>
    <dc:date>2016-01-17T10:27:02Z</dc:date>
    <item>
      <title>custom mail app-id</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/custom-mail-app-id/m-p/71050#M35</link>
      <description>&lt;P&gt;hi.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'am trying to create a custom mail app-id filter, for matching; to whom mail is gonging to and from what domain.&lt;/P&gt;
&lt;P&gt;I have add smtp as a parent application in the app-id.&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/2057iBC77A57BE5FA0C6A/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="application-smtp" title="application-smtp" width="596" height="346" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My app-id is matching the helo, mail from, rcp, data. from the mail. The policy with this custom app-id is partial match, if I only has this, the data is dropt.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/2058i67ADABE748B41C6D/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="application-ports" title="application-ports" width="604" height="405" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/2059i102DAB8A8D34483B/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="application-signature" title="application-signature" width="596" height="198" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/2060iF53B6A4AF6054C3C/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="policy-rule" title="policy-rule" /&gt;&lt;/P&gt;
&lt;P&gt;If I add a new policy row with application smtp below my custom app-id, the first package that came in match smtp, and all blowing data is matching my custom app-id.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/2062i1CD7F1D4BDF838BD/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="policy-rule-smtp" title="policy-rule-smtp" /&gt;&lt;/P&gt;
&lt;P&gt;the row application smtp, is becuse to make this policy working i hade to add smtp in the rule, the problem to do so is that it also match evry smtp packaged that comes in to the firewall.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have i missed somthing? or how can I solve this?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;/Kristofer&lt;/P&gt;</description>
      <pubDate>Sun, 17 Jan 2016 10:27:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/custom-mail-app-id/m-p/71050#M35</guid>
      <dc:creator>klokholm</dc:creator>
      <dc:date>2016-01-17T10:27:02Z</dc:date>
    </item>
  </channel>
</rss>

