<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Can custom appIDs, without signatures, be applied directly to a security policy? in Custom Signatures</title>
    <link>https://live.paloaltonetworks.com/t5/custom-signatures/can-custom-appids-without-signatures-be-applied-directly-to-a/m-p/577931#M498</link>
    <description>&lt;P&gt;For this discussion, we created custom appID `myApp`, it has NO signature.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If `myApp` uses port 22, the port of another known app (SSH), then to use `myApp`, it must be applied to an App Override policy.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But what if `myApp` uses unique port 2121, can then `myApp` be applied directly to a security policy or does it still need to be added to an App Override policy?&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We want to create simple appIDs, with no signature, to be applied to various security policies so we can A) ID the app in the policy without having to reference a service port and B) to be able to cleanly/clearly ID the traffic in traffic logs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;All the existing documentation I have found references creating custom appIDs using a port of a known app, but I can't find references to unique ports.&amp;nbsp; As well, the documentation seems to imply that any apps applied to a security policy must have a signature while also implying custom apps without a signature must still use App Override policies.&amp;nbsp; Its not very clear...IMO.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Wed, 21 Feb 2024 19:21:06 GMT</pubDate>
    <dc:creator>rolinger</dc:creator>
    <dc:date>2024-02-21T19:21:06Z</dc:date>
    <item>
      <title>Can custom appIDs, without signatures, be applied directly to a security policy?</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/can-custom-appids-without-signatures-be-applied-directly-to-a/m-p/577931#M498</link>
      <description>&lt;P&gt;For this discussion, we created custom appID `myApp`, it has NO signature.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If `myApp` uses port 22, the port of another known app (SSH), then to use `myApp`, it must be applied to an App Override policy.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But what if `myApp` uses unique port 2121, can then `myApp` be applied directly to a security policy or does it still need to be added to an App Override policy?&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We want to create simple appIDs, with no signature, to be applied to various security policies so we can A) ID the app in the policy without having to reference a service port and B) to be able to cleanly/clearly ID the traffic in traffic logs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;All the existing documentation I have found references creating custom appIDs using a port of a known app, but I can't find references to unique ports.&amp;nbsp; As well, the documentation seems to imply that any apps applied to a security policy must have a signature while also implying custom apps without a signature must still use App Override policies.&amp;nbsp; Its not very clear...IMO.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 21 Feb 2024 19:21:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/can-custom-appids-without-signatures-be-applied-directly-to-a/m-p/577931#M498</guid>
      <dc:creator>rolinger</dc:creator>
      <dc:date>2024-02-21T19:21:06Z</dc:date>
    </item>
  </channel>
</rss>

