<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Palo Alto ALG (Application Level Gateway)  SIP dissable just for a particular source and destination IP addresses in a Security Policy? in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/palo-alto-alg-application-level-gateway-sip-dissable-just-for-a/m-p/520049#M532</link>
    <description>&lt;P&gt;Hello to All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From what I read about ALG (&lt;SPAN class="ILfuVd"&gt;&lt;SPAN class="hgKElc"&gt;Application Level Gateway&lt;/SPAN&gt;&lt;/SPAN&gt;) functions on the Palo Alto Firewalls this function if needed is disabled globaly for the SIP default application or with application overide policy but this will stop the SIP signature matches.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClEsCAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClEsCAK&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/app-id/disable-the-sip-application-level-gateway-alg" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/app-id/disable-the-sip-application-level-gateway-alg&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000004LyaCAE&amp;amp;lang=en_US%E2%80%A9" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000004LyaCAE&amp;amp;lang=en_US%E2%80%A9&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there a way to dissable the SIP ALG&amp;nbsp; function not globally and not and app overide policy? Maybe it is better to create a custom ALG is the option "&lt;STRONG&gt;Continue scanning for other Applications&lt;/STRONG&gt;"&amp;nbsp; but if the SIP ALG disabled globally will the "&lt;STRONG&gt;Continue scanning for other Applications&lt;/STRONG&gt;"&amp;nbsp; work as how is this different than the real ALG functons in the firewall ?&lt;/P&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClZmCAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClZmCAK&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also I think that custom ports can't be open on the firewall with custom application sifnatures but I could be wrong.&lt;/P&gt;</description>
    <pubDate>Wed, 02 Nov 2022 19:06:39 GMT</pubDate>
    <dc:creator>nikoolayy1</dc:creator>
    <dc:date>2022-11-02T19:06:39Z</dc:date>
    <item>
      <title>Palo Alto ALG (Application Level Gateway)  SIP dissable just for a particular source and destination IP addresses in a Security Policy?</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/palo-alto-alg-application-level-gateway-sip-dissable-just-for-a/m-p/520049#M532</link>
      <description>&lt;P&gt;Hello to All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From what I read about ALG (&lt;SPAN class="ILfuVd"&gt;&lt;SPAN class="hgKElc"&gt;Application Level Gateway&lt;/SPAN&gt;&lt;/SPAN&gt;) functions on the Palo Alto Firewalls this function if needed is disabled globaly for the SIP default application or with application overide policy but this will stop the SIP signature matches.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClEsCAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClEsCAK&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/app-id/disable-the-sip-application-level-gateway-alg" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/app-id/disable-the-sip-application-level-gateway-alg&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000004LyaCAE&amp;amp;lang=en_US%E2%80%A9" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000004LyaCAE&amp;amp;lang=en_US%E2%80%A9&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there a way to dissable the SIP ALG&amp;nbsp; function not globally and not and app overide policy? Maybe it is better to create a custom ALG is the option "&lt;STRONG&gt;Continue scanning for other Applications&lt;/STRONG&gt;"&amp;nbsp; but if the SIP ALG disabled globally will the "&lt;STRONG&gt;Continue scanning for other Applications&lt;/STRONG&gt;"&amp;nbsp; work as how is this different than the real ALG functons in the firewall ?&lt;/P&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClZmCAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClZmCAK&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also I think that custom ports can't be open on the firewall with custom application sifnatures but I could be wrong.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2022 19:06:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/palo-alto-alg-application-level-gateway-sip-dissable-just-for-a/m-p/520049#M532</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2022-11-02T19:06:39Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto ALG (Application Level Gateway)  SIP dissable just for a particular source and destination IP addresses in a Security Policy?</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/palo-alto-alg-application-level-gateway-sip-dissable-just-for-a/m-p/520483#M553</link>
      <description>&lt;P&gt;I am starting to thing that redirecting a specific traffic to a firewall that is with ALG dissabled could be the best way. With Prisma Access it will be harder as then different tenants will be needed&amp;nbsp; (there can't be more than one device group connected to a Prisma Access tenant) and tenant&amp;nbsp; to tenant routing seems like a nightmare and this is why I opened another question just to check it &lt;A href="https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-access-routing-between-tenants/m-p/520317" target="_blank" rel="noopener"&gt;https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-access-routing-between-tenants/m-p/520317&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The option "&lt;STRONG&gt;Continue scanning for other Applications&lt;/STRONG&gt;" seems nice in some cases but not this one as from what I think two custom application id's need to be created and you need match something in the packet as the Control Channel App ID can't tell the Data Channel App id which dynamic port needs to be opened like the true ALG functions do and opening all ports with a port range in the Custom App ID Advanced settings is a little risky.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If someone has more knowedge about ALG functios on Palo Alto please share it with me &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Nov 2022 09:51:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/palo-alto-alg-application-level-gateway-sip-dissable-just-for-a/m-p/520483#M553</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2022-11-07T09:51:06Z</dc:date>
    </item>
  </channel>
</rss>

