<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic The allow security policy configured with the app-ID &amp;quot;netbackup&amp;quot; and an &amp;quot;application-default&amp;quot; as a service doesn't work correctly. in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/the-allow-security-policy-configured-with-the-app-id-quot/m-p/539346#M1161</link>
    <description>&lt;P&gt;Dear and valuable Live Community Members,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a problem understanding the below-described behavior in regard to the security policy used in the firewall:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;We have a firewall policy configured to allow &lt;STRONG&gt;NetBackup&lt;/STRONG&gt; traffic, but if we configure it by setting the "Application" tab to "netbackup", it often doesn't work (the behavior is random). And if we configure the policy specifying the TCP ports used by netbackup, it works correctly.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;As you can see below we have now two &lt;STRONG&gt;allow&lt;/STRONG&gt; policies to make it work:&lt;/P&gt;
&lt;P&gt;-----------------------------------------------------------------------------------------------------------------------&lt;/P&gt;
&lt;P&gt;1) The security policy that specifies the ports used by the application (Application - &lt;STRONG&gt;Any&lt;/STRONG&gt;; Service&amp;nbsp;&lt;STRONG&gt;TCP/1556,13724,13782,13722,10102,10082) &lt;/STRONG&gt;- &lt;STRONG&gt;&lt;FONT color="#008000"&gt;it works fine&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2) The security policy configured with the app ID "&lt;STRONG&gt;netbackup&lt;/STRONG&gt;" and an "&lt;STRONG&gt;application-default&lt;/STRONG&gt;" as a service&amp;nbsp; - &lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;doesn't work correctly&amp;nbsp;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image001.png" style="width: 984px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/49621iC0B7253C7505271C/image-dimensions/984x203/is-moderation-mode/true?v=v2" width="984" height="203" role="button" title="image001.png" alt="image001.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I could verify the list of standard ports and as per the KB&amp;nbsp;&lt;A title="What Does Application-default Under Service Mean?" href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClVwCAK" target="_self"&gt;Tips &amp;amp; Tricks: What Does Application-default Under Service Mean?&lt;/A&gt;&amp;nbsp;I was sure that we will need only one policy and that the 2nd policy should be enough for this.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Standard_Ports" style="width: 610px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/49622i9BE68B9E9852FDF7/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Standard Ports_netbackup.PNG" alt="Standard_Ports" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Standard_Ports&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Could you please help me to understand why the "Application" field, is not working as expected with the &lt;STRONG&gt;application-default&lt;/STRONG&gt;?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope someone could help me out and let me know if there is something that needs to be corrected (configuration-wise) if that's maybe a bug or an expected behavior...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I would kindly like to ask you for&amp;nbsp;some help and advice on this one.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Thank you in advance!&lt;/P&gt;
&lt;P&gt;Cheers!&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 19 Apr 2023 11:39:13 GMT</pubDate>
    <dc:creator>A_Adamski</dc:creator>
    <dc:date>2023-04-19T11:39:13Z</dc:date>
    <item>
      <title>The allow security policy configured with the app-ID "netbackup" and an "application-default" as a service doesn't work correctly.</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/the-allow-security-policy-configured-with-the-app-id-quot/m-p/539346#M1161</link>
      <description>&lt;P&gt;Dear and valuable Live Community Members,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a problem understanding the below-described behavior in regard to the security policy used in the firewall:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;We have a firewall policy configured to allow &lt;STRONG&gt;NetBackup&lt;/STRONG&gt; traffic, but if we configure it by setting the "Application" tab to "netbackup", it often doesn't work (the behavior is random). And if we configure the policy specifying the TCP ports used by netbackup, it works correctly.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;As you can see below we have now two &lt;STRONG&gt;allow&lt;/STRONG&gt; policies to make it work:&lt;/P&gt;
&lt;P&gt;-----------------------------------------------------------------------------------------------------------------------&lt;/P&gt;
&lt;P&gt;1) The security policy that specifies the ports used by the application (Application - &lt;STRONG&gt;Any&lt;/STRONG&gt;; Service&amp;nbsp;&lt;STRONG&gt;TCP/1556,13724,13782,13722,10102,10082) &lt;/STRONG&gt;- &lt;STRONG&gt;&lt;FONT color="#008000"&gt;it works fine&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2) The security policy configured with the app ID "&lt;STRONG&gt;netbackup&lt;/STRONG&gt;" and an "&lt;STRONG&gt;application-default&lt;/STRONG&gt;" as a service&amp;nbsp; - &lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;doesn't work correctly&amp;nbsp;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image001.png" style="width: 984px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/49621iC0B7253C7505271C/image-dimensions/984x203/is-moderation-mode/true?v=v2" width="984" height="203" role="button" title="image001.png" alt="image001.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I could verify the list of standard ports and as per the KB&amp;nbsp;&lt;A title="What Does Application-default Under Service Mean?" href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClVwCAK" target="_self"&gt;Tips &amp;amp; Tricks: What Does Application-default Under Service Mean?&lt;/A&gt;&amp;nbsp;I was sure that we will need only one policy and that the 2nd policy should be enough for this.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Standard_Ports" style="width: 610px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/49622i9BE68B9E9852FDF7/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Standard Ports_netbackup.PNG" alt="Standard_Ports" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Standard_Ports&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Could you please help me to understand why the "Application" field, is not working as expected with the &lt;STRONG&gt;application-default&lt;/STRONG&gt;?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope someone could help me out and let me know if there is something that needs to be corrected (configuration-wise) if that's maybe a bug or an expected behavior...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I would kindly like to ask you for&amp;nbsp;some help and advice on this one.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Thank you in advance!&lt;/P&gt;
&lt;P&gt;Cheers!&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Apr 2023 11:39:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/the-allow-security-policy-configured-with-the-app-id-quot/m-p/539346#M1161</guid>
      <dc:creator>A_Adamski</dc:creator>
      <dc:date>2023-04-19T11:39:13Z</dc:date>
    </item>
    <item>
      <title>Re: The allow security policy configured with the app-ID "netbackup" and an "application-default" as a service doesn't work correc</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/the-allow-security-policy-configured-with-the-app-id-quot/m-p/539501#M1169</link>
      <description>&lt;P&gt;Hi A_Adamski,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I agree with you, you should only need 2nd rule as it contains all ports you included in screenshot.&lt;/P&gt;
&lt;P&gt;that is a weird problem, two question if you don't mind.&lt;/P&gt;
&lt;P&gt;1) what is your application version on the dash board - is it&amp;nbsp; Application Version 8699-7991 (04/19/23) ?&lt;/P&gt;
&lt;P&gt;2) when you look at the logs for the first rule, which application(s) do you see in the logs?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Apr 2023 09:03:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/the-allow-security-policy-configured-with-the-app-id-quot/m-p/539501#M1169</guid>
      <dc:creator>Y-alwaysMe</dc:creator>
      <dc:date>2023-04-20T09:03:04Z</dc:date>
    </item>
    <item>
      <title>Re: The allow security policy configured with the app-ID "netbackup" and an "application-default" as a service doesn't work correc</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/the-allow-security-policy-configured-with-the-app-id-quot/m-p/539891#M1174</link>
      <description>&lt;P&gt;Hello Y-AlwaysMe,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1) The&amp;nbsp;Application Version is now 8697-7981 (04/14/23), but it as issue we've got in the past with the&amp;nbsp;&lt;SPAN&gt;8693-7959 (end of March)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;2) The firewall seams to be recognizing the application correctly&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image001 (1).png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/49703i70EFBF3E9AA6AA49/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image001 (1).png" alt="image001 (1).png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there anything I might be miing out and should verify/correct, or should I ask PA TAC for some support on this one?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you in advance!&lt;/P&gt;</description>
      <pubDate>Mon, 24 Apr 2023 12:14:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/the-allow-security-policy-configured-with-the-app-id-quot/m-p/539891#M1174</guid>
      <dc:creator>A_Adamski</dc:creator>
      <dc:date>2023-04-24T12:14:04Z</dc:date>
    </item>
    <item>
      <title>Re: The allow security policy configured with the app-ID "netbackup" and an "application-default" as a service doesn't work correc</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/the-allow-security-policy-configured-with-the-app-id-quot/m-p/539899#M1175</link>
      <description>&lt;P&gt;Hi A_Adamski,&lt;/P&gt;
&lt;P&gt;Thank you for information. I suspect the problem will potentially be the unknown-tcp, when you enable Bytes Sent &amp;amp; Bytes Received and look the unknown-tcp between the src and dst IP addresses, I am guessing there will be actual data that is eq or more than 200 bytes in the sent and received columns, which could potentially explain why it would randomly stop working as most packets are normal TCP/1556 packets, and then every now and then unknown-tcp will be sent and it will stop working against the application rule.&lt;/P&gt;
&lt;P&gt;Because the application rule you allowed only contains netbackup and you did not define unknown-tcp in your application rule.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I personally think there are two options use the L4 service-port based rule or look at custom application / app override - see that article by Reaper.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Clc6CAC" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Clc6CAC&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Apr 2023 12:59:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/the-allow-security-policy-configured-with-the-app-id-quot/m-p/539899#M1175</guid>
      <dc:creator>Y-alwaysMe</dc:creator>
      <dc:date>2023-04-24T12:59:42Z</dc:date>
    </item>
  </channel>
</rss>

