<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Can we create a rule to match only the selected application without selecting WEb-Browsing dependency in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/can-we-create-a-rule-to-match-only-the-selected-application/m-p/549049#M1489</link>
    <description>&lt;P&gt;Dear All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I need a community advice, we are migrating all our Firewalls from Checkpoint to Palo Alto.&lt;/P&gt;
&lt;P&gt;First Palo Alto was implemented 2 weeks ago, a PA 3420 version&amp;nbsp;&lt;SPAN&gt;10.2.4-h2&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are trying to transform the imported rules into Palo alto style.&lt;/P&gt;
&lt;P&gt;For example I want to create a rule to allow only access to "TeamViewer" application for some computers but not allowing them to browse internet.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So, first I implemented the SSL decrypt rule for thoses computers, decrypt is running fine.&lt;/P&gt;
&lt;P&gt;I create the filtering rule with Source = computers Ip's and Destination= TeamViewer application&lt;/P&gt;
&lt;P&gt;When I do that there are suggested applications dependency's that are SSL and Web-Browsing, so I add them also into the allowed Applications list. (Seem to be a best practice doing that)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But when I do this, the effect of this rule is that these computers can actually browse the whole Internet, not just TeamViewer.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So I read on some other posts that to filter correctly I should add an url list with (teamviewer.com and *.teamviewer.com) to the rule to filter only the Application teamviewer.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But, so what's the point to use application if in parallel I have to combine them with Url list ?&lt;/P&gt;
&lt;P&gt;Because I could instead create a URL List based rule only (without speechifying the Application) i will have the same effect ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Many thanks for your advices.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
    <pubDate>Wed, 12 Jul 2023 07:36:05 GMT</pubDate>
    <dc:creator>PauloVenancio</dc:creator>
    <dc:date>2023-07-12T07:36:05Z</dc:date>
    <item>
      <title>Can we create a rule to match only the selected application without selecting WEb-Browsing dependency</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/can-we-create-a-rule-to-match-only-the-selected-application/m-p/549049#M1489</link>
      <description>&lt;P&gt;Dear All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I need a community advice, we are migrating all our Firewalls from Checkpoint to Palo Alto.&lt;/P&gt;
&lt;P&gt;First Palo Alto was implemented 2 weeks ago, a PA 3420 version&amp;nbsp;&lt;SPAN&gt;10.2.4-h2&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are trying to transform the imported rules into Palo alto style.&lt;/P&gt;
&lt;P&gt;For example I want to create a rule to allow only access to "TeamViewer" application for some computers but not allowing them to browse internet.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So, first I implemented the SSL decrypt rule for thoses computers, decrypt is running fine.&lt;/P&gt;
&lt;P&gt;I create the filtering rule with Source = computers Ip's and Destination= TeamViewer application&lt;/P&gt;
&lt;P&gt;When I do that there are suggested applications dependency's that are SSL and Web-Browsing, so I add them also into the allowed Applications list. (Seem to be a best practice doing that)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But when I do this, the effect of this rule is that these computers can actually browse the whole Internet, not just TeamViewer.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So I read on some other posts that to filter correctly I should add an url list with (teamviewer.com and *.teamviewer.com) to the rule to filter only the Application teamviewer.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But, so what's the point to use application if in parallel I have to combine them with Url list ?&lt;/P&gt;
&lt;P&gt;Because I could instead create a URL List based rule only (without speechifying the Application) i will have the same effect ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Many thanks for your advices.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jul 2023 07:36:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/can-we-create-a-rule-to-match-only-the-selected-application/m-p/549049#M1489</guid>
      <dc:creator>PauloVenancio</dc:creator>
      <dc:date>2023-07-12T07:36:05Z</dc:date>
    </item>
    <item>
      <title>Re: Can we create a rule to match only the selected application without selecting WEb-Browsing dependency</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/can-we-create-a-rule-to-match-only-the-selected-application/m-p/550934#M1580</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/302780"&gt;@PauloVenancio&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If teamviewer is using its default port i.e. TCP/UDP 5938 then, it would be easier for you to filter traffic based on the destination port along-with app-id. But anyway, if teamviewer can't connect over default port, it will next try to connect over 443.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Coming to your questions-&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But, so what's the point to use application if in parallel I have to combine them with Url list ?&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;-&lt;/STRONG&gt;Most of admins use all the available options to restrict their security policies. So it will be good idea to use URL list in your case.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Because I could instead create a URL List based rule only (without speechifying the Application) i will have the same effect ?&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;-&lt;/STRONG&gt;Yes, that will also work based on the destination URLs allowed under the list.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jul 2023 15:59:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/can-we-create-a-rule-to-match-only-the-selected-application/m-p/550934#M1580</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2023-07-25T15:59:59Z</dc:date>
    </item>
  </channel>
</rss>

