<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FW Policy Skipped When Either App-Based only or SMTP-BASE app and 587 Port is Defined in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/fw-policy-skipped-when-either-app-based-only-or-smtp-base-app/m-p/558490#M1866</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/301972"&gt;@EmmanB-NC&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Because that FQDN destination is changing IP every few seconds I believe you might be hitting the following issue:&lt;BR /&gt;&lt;STRONG&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000POKhCAO" target="_blank" rel="noopener"&gt;Using FQDN address object with dynamic IP for Policies&lt;/A&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps,&lt;/P&gt;
&lt;P&gt;-Kim.&lt;/P&gt;</description>
    <pubDate>Tue, 19 Sep 2023 06:53:47 GMT</pubDate>
    <dc:creator>kiwi</dc:creator>
    <dc:date>2023-09-19T06:53:47Z</dc:date>
    <item>
      <title>FW Policy Skipped When Either App-Based only or SMTP-BASE app and 587 Port is Defined</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/fw-policy-skipped-when-either-app-based-only-or-smtp-base-app/m-p/555066#M1763</link>
      <description>&lt;P&gt;Firewall is skipping policy when the traffic has&amp;nbsp;&lt;STRONG&gt;smtp-base port 587&lt;/STRONG&gt;&amp;nbsp;on it&lt;STRONG&gt;.&lt;/STRONG&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I created a firewall policy application based with &lt;STRONG&gt;smtp-base&lt;/STRONG&gt; as application but it skips the policy goes to the implicit interzone deny policy. So I created it with by just port based, &lt;STRONG&gt;587,&amp;nbsp;&lt;/STRONG&gt;it sill skips the policy and goes to interzone default deny.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;So I explicitly defined app-based and port based on the policy, it still skips the policy.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;When I run the troubleshooter, Test Policy, it is able to match the policy created when I only specified the port 587. It skips it when I add the application, smtp-base.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;PA-440, PANOS 10.1.9&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;Anyone else encountered the same issue and was able to solve it? Or anything you recommend to solve this is greatly appreciated!&lt;/P&gt;</description>
      <pubDate>Thu, 24 Aug 2023 14:17:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/fw-policy-skipped-when-either-app-based-only-or-smtp-base-app/m-p/555066#M1763</guid>
      <dc:creator>EmmanB-NC</dc:creator>
      <dc:date>2023-08-24T14:17:44Z</dc:date>
    </item>
    <item>
      <title>Re: FW Policy Skipped When Either App-Based only or SMTP-BASE app and 587 Port is Defined</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/fw-policy-skipped-when-either-app-based-only-or-smtp-base-app/m-p/555485#M1767</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/301972"&gt;@EmmanB-NC&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Strange. It would be interesting to see the full configuration of the rules in question and compare it to the deny rule.&lt;/P&gt;
&lt;P&gt;When you're hitting the default-deny rules, how is the traffic being identified exactly ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;/P&gt;
&lt;P&gt;-Kim.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Aug 2023 07:23:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/fw-policy-skipped-when-either-app-based-only-or-smtp-base-app/m-p/555485#M1767</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2023-08-28T07:23:59Z</dc:date>
    </item>
    <item>
      <title>Re: FW Policy Skipped When Either App-Based only or SMTP-BASE app and 587 Port is Defined</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/fw-policy-skipped-when-either-app-based-only-or-smtp-base-app/m-p/558347#M1861</link>
      <description>&lt;P&gt;Hi Kiwi,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;It turned out the application recognized to destination smtp.office365.com is outlook-web-online using port 587 and not smtp-base. This is when I enabled Any Any temporarily to see what application traffic is actually going over the firewall.&amp;nbsp;&lt;BR /&gt;Traffic appears to be allowed on the firewall however email is not received by expected recipient.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Sep 2023 11:29:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/fw-policy-skipped-when-either-app-based-only-or-smtp-base-app/m-p/558347#M1861</guid>
      <dc:creator>EmmanB-NC</dc:creator>
      <dc:date>2023-09-18T11:29:41Z</dc:date>
    </item>
    <item>
      <title>Re: FW Policy Skipped When Either App-Based only or SMTP-BASE app and 587 Port is Defined</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/fw-policy-skipped-when-either-app-based-only-or-smtp-base-app/m-p/558490#M1866</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/301972"&gt;@EmmanB-NC&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Because that FQDN destination is changing IP every few seconds I believe you might be hitting the following issue:&lt;BR /&gt;&lt;STRONG&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000POKhCAO" target="_blank" rel="noopener"&gt;Using FQDN address object with dynamic IP for Policies&lt;/A&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps,&lt;/P&gt;
&lt;P&gt;-Kim.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Sep 2023 06:53:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/fw-policy-skipped-when-either-app-based-only-or-smtp-base-app/m-p/558490#M1866</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2023-09-19T06:53:47Z</dc:date>
    </item>
    <item>
      <title>Re: FW Policy Skipped When Either App-Based only or SMTP-BASE app and 587 Port is Defined</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/fw-policy-skipped-when-either-app-based-only-or-smtp-base-app/m-p/559402#M1897</link>
      <description>&lt;P&gt;I tried it also with the actual IP range object defined on the policy. It appears as allowed traffic but the application still gets an error.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Sep 2023 18:37:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/fw-policy-skipped-when-either-app-based-only-or-smtp-base-app/m-p/559402#M1897</guid>
      <dc:creator>EmmanB-NC</dc:creator>
      <dc:date>2023-09-25T18:37:33Z</dc:date>
    </item>
    <item>
      <title>Re: FW Policy Skipped When Either App-Based only or SMTP-BASE app and 587 Port is Defined</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/fw-policy-skipped-when-either-app-based-only-or-smtp-base-app/m-p/594986#M3596</link>
      <description>&lt;P&gt;Hi expert,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;anyone know the answer? facing same issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Thu, 15 Aug 2024 04:19:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/fw-policy-skipped-when-either-app-based-only-or-smtp-base-app/m-p/594986#M3596</guid>
      <dc:creator>LizaRajjab</dc:creator>
      <dc:date>2024-08-15T04:19:37Z</dc:date>
    </item>
  </channel>
</rss>

