<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Custom App-ID with just source and destination ip address in Custom Signatures</title>
    <link>https://live.paloaltonetworks.com/t5/custom-signatures/custom-app-id-with-just-source-and-destination-ip-address/m-p/598969#M516</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/321680"&gt;@ConorMc&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes, you can use Application Override to assign traffic to custom applications.&amp;nbsp; &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClVLCA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClVLCA0&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This 1st step for Application Override is to define the custom application.&amp;nbsp; If the source or destination port is consistent, you can define that in the custom application.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Then you create your Application Override policy based upon the source and/or destination IP addresses.&amp;nbsp; The traffic will then be assigned the custom App-ID and you can track it in your logs and use it in your security policy.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
    <pubDate>Fri, 27 Sep 2024 12:45:20 GMT</pubDate>
    <dc:creator>TomYoung</dc:creator>
    <dc:date>2024-09-27T12:45:20Z</dc:date>
    <item>
      <title>Custom App-ID with just source and destination ip address</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/custom-app-id-with-just-source-and-destination-ip-address/m-p/598962#M515</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have some traffic on a tap interface that I would like to create an APP-ID to identify it in the monitor logs. This a seperate network with its own custom application and functions. I have done some pcap's and can't see distinct data that relate to the context values in the custom App-ID form. Is there a list of what the context values are/mean?&amp;nbsp; &amp;nbsp;Is it possible to just create an App-ID with the source-ipaddress:port and destination-ipaddress:port? There are multiple sources talking to multiple servers but it is not a generic application available on the internet.&amp;nbsp; The ports seem to be distinct from the common ports used in other applications.&lt;/P&gt;
&lt;P&gt;Any help at all would be very gratefully recieved.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Sep 2024 12:23:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/custom-app-id-with-just-source-and-destination-ip-address/m-p/598962#M515</guid>
      <dc:creator>ConorMc</dc:creator>
      <dc:date>2024-09-27T12:23:59Z</dc:date>
    </item>
    <item>
      <title>Re: Custom App-ID with just source and destination ip address</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/custom-app-id-with-just-source-and-destination-ip-address/m-p/598969#M516</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/321680"&gt;@ConorMc&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes, you can use Application Override to assign traffic to custom applications.&amp;nbsp; &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClVLCA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClVLCA0&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This 1st step for Application Override is to define the custom application.&amp;nbsp; If the source or destination port is consistent, you can define that in the custom application.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Then you create your Application Override policy based upon the source and/or destination IP addresses.&amp;nbsp; The traffic will then be assigned the custom App-ID and you can track it in your logs and use it in your security policy.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Fri, 27 Sep 2024 12:45:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/custom-app-id-with-just-source-and-destination-ip-address/m-p/598969#M516</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2024-09-27T12:45:20Z</dc:date>
    </item>
    <item>
      <title>Re: Custom App-ID with just source and destination ip address</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/custom-app-id-with-just-source-and-destination-ip-address/m-p/598979#M517</link>
      <description>&lt;P&gt;Thanks for your help Tom,&lt;/P&gt;
&lt;P&gt;I'll look at that now. Just a question, this seems to bypass the&amp;nbsp;&lt;SPAN&gt;Content and Threat inspection for the traffic. I need the traffic to be inspected for malware etc. The system is an IDS for traffic on private networks that is sent to the Firewall tap interface.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Conor.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Sep 2024 14:09:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/custom-app-id-with-just-source-and-destination-ip-address/m-p/598979#M517</guid>
      <dc:creator>ConorMc</dc:creator>
      <dc:date>2024-09-27T14:09:19Z</dc:date>
    </item>
    <item>
      <title>Re: Custom App-ID with just source and destination ip address</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/custom-app-id-with-just-source-and-destination-ip-address/m-p/599427#M518</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/321680"&gt;@ConorMc&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You are correct.&amp;nbsp; Application Override will bypass content inspection (Content-ID).&amp;nbsp; If you do not have a parent app (see below), you may as well go this route.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Custom apps without a signature will not match traffic without Application Override.&amp;nbsp; &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClGvCAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClGvCAK&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In order for your custom app to be inspected at L7, you will need to identify a parent app &lt;EM&gt;and&lt;/EM&gt; check at least one of the boxes under the Scanning section on the Advanced tab.&amp;nbsp; &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClRoCAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClRoCAK&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes, there is a list of the context values!&amp;nbsp; &lt;A href="https://docs.paloaltonetworks.com/pan-os/u-v/custom-app-id-and-threat-signatures/custom-application-and-threat-signatures/custom-signature-contexts" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/u-v/custom-app-id-and-threat-signatures/custom-application-and-threat-signatures/custom-signature-contexts&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For unknown apps, you could use one or more of these 4 string contexts:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;unknown-req-tcp-payload&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;unknown-rsp-tcp-payload&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;unknown-req-udp-payload&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;unknown-rsp-udp-payload&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That will instruct the inspection engine to search for your regex starting with the payload portion of the TCP or UDP packet.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClmGCAS" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClmGCAS&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Shout out to &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt; for the helpful links!&amp;nbsp; &lt;A href="https://live.paloaltonetworks.com/t5/general-topics/urgent-custom-application-issue/td-p/312239" target="_blank"&gt;https://live.paloaltonetworks.com/t5/general-topics/urgent-custom-application-issue/td-p/312239&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Oct 2024 10:34:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/custom-app-id-with-just-source-and-destination-ip-address/m-p/599427#M518</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2024-10-03T10:34:05Z</dc:date>
    </item>
    <item>
      <title>Re: Custom App-ID with just source and destination ip address</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/custom-app-id-with-just-source-and-destination-ip-address/m-p/599526#M519</link>
      <description>&lt;P&gt;Thanks Tom,&lt;/P&gt;
&lt;P&gt;Excellent information and alot to have a go at. I'll look at the pcap's and see if I can get a pattern match for the tcp traffic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks again,&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Oct 2024 09:04:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/custom-app-id-with-just-source-and-destination-ip-address/m-p/599526#M519</guid>
      <dc:creator>ConorMc</dc:creator>
      <dc:date>2024-10-04T09:04:21Z</dc:date>
    </item>
  </channel>
</rss>

