<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Next gen features on port based rules in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/next-gen-features-on-port-based-rules/m-p/379480#M133</link>
    <description>&lt;P&gt;Anyone please ?&lt;/P&gt;</description>
    <pubDate>Wed, 13 Jan 2021 10:52:11 GMT</pubDate>
    <dc:creator>FWPalolearner</dc:creator>
    <dc:date>2021-01-13T10:52:11Z</dc:date>
    <item>
      <title>Next gen features on port based rules</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/next-gen-features-on-port-based-rules/m-p/379451#M132</link>
      <description>&lt;P&gt;Hello ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are in process on migrating port based rules to APP -ID but as it is time taking process , it may take us sometime .&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can we still enable Security profiles like AV, Antispyware , Vul Protection , Wildfire&amp;nbsp; , Data Blocking ; URL filtering on Port based rules ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Or is there a preq to have APP ID for these features ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;we want to start applying Security profiles with less restrictive actions , observe and then take strict actions like reset or block&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kindly reply .&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 04 Jun 2021 03:07:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/next-gen-features-on-port-based-rules/m-p/379451#M132</guid>
      <dc:creator>FWPalolearner</dc:creator>
      <dc:date>2021-06-04T03:07:32Z</dc:date>
    </item>
    <item>
      <title>Re: Next gen features on port based rules</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/next-gen-features-on-port-based-rules/m-p/379480#M133</link>
      <description>&lt;P&gt;Anyone please ?&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jan 2021 10:52:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/next-gen-features-on-port-based-rules/m-p/379480#M133</guid>
      <dc:creator>FWPalolearner</dc:creator>
      <dc:date>2021-01-13T10:52:11Z</dc:date>
    </item>
    <item>
      <title>Re: Next gen features on port based rules</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/next-gen-features-on-port-based-rules/m-p/379537#M134</link>
      <description>&lt;P&gt;hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/133520"&gt;@FWPalolearner&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;yes absolutely you can enable all the security profiles on your port based rules&lt;/P&gt;&lt;P&gt;the content engines are smart enough to detect for themselves which protocols they can and will scan so they can be applied to anything from any any to fully set app + app-default rules and will function as expected&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;there is no concept of 'overscanning' like some legacy firewalls (eg. smtp signatures will not be matched if the content engine detects http) so it is perfectly safe to enable _everything_ on all rules even if there are no applications&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;hope this helps&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jan 2021 13:11:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/next-gen-features-on-port-based-rules/m-p/379537#M134</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2021-01-13T13:11:29Z</dc:date>
    </item>
    <item>
      <title>Re: Next gen features on port based rules</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/next-gen-features-on-port-based-rules/m-p/379558#M135</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp;Thanks a lot , really appreciate&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jan 2021 13:54:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/next-gen-features-on-port-based-rules/m-p/379558#M135</guid>
      <dc:creator>FWPalolearner</dc:creator>
      <dc:date>2021-01-13T13:54:03Z</dc:date>
    </item>
  </channel>
</rss>

