<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Service Port overwrites  Application default provided  port (?) in Panorama Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/panorama-discussions/service-port-overwrites-application-default-provided-port/m-p/606282#M2533</link>
    <description>&lt;P&gt;Let me rephrase my question.&lt;/P&gt;
&lt;P&gt;If you add "mysql" is application, which by default is associated with port 3306.&lt;/P&gt;
&lt;P&gt;And in same rule you would add server TCP 58740.&lt;/P&gt;
&lt;P&gt;Where would Palo look first - at Layer 7 - "mysql" or Layer 4 TCP Port 58740.&lt;/P&gt;
&lt;P&gt;Would it break the association with port 3306. And Palo would only allow traffic on TCP Port 58740 and not application "MySQL". In other words, it would break the rule for allowing traffic for Application "MySQL"?&lt;/P&gt;</description>
    <pubDate>Thu, 17 Oct 2024 17:34:55 GMT</pubDate>
    <dc:creator>Martin2K</dc:creator>
    <dc:date>2024-10-17T17:34:55Z</dc:date>
    <item>
      <title>Service Port overwrites  Application default provided  port (?)</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/service-port-overwrites-application-default-provided-port/m-p/600926#M2512</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I would like to get a better understanding about the relationship Service vs Application when setting up FW rules:&lt;/P&gt;
&lt;P&gt;Example:&lt;/P&gt;
&lt;P style="margin: 0in; background: white;"&gt;&lt;SPAN&gt;"mysql" is provided with service TCP port 3306.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in; background: white;"&gt;&lt;SPAN&gt;If a rule is created using service TCP Port 58740 and in same rule under application "mysql" is added, would it cause the PA to associate application "mysql" with port 58740 system-wide. In other words, it would have a global effect on all rules using "mysql".&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in; background: white;"&gt;&lt;SPAN&gt;I would appreciate, if someone could shed some light on it.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in; background: white;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; background: white;"&gt;&lt;SPAN&gt;Thanks,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in; background: white;"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Oct 2024 23:31:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/service-port-overwrites-application-default-provided-port/m-p/600926#M2512</guid>
      <dc:creator>Martin2K</dc:creator>
      <dc:date>2024-10-15T23:31:43Z</dc:date>
    </item>
    <item>
      <title>Re: Service Port overwrites  Application default provided  port (?)</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/service-port-overwrites-application-default-provided-port/m-p/606282#M2533</link>
      <description>&lt;P&gt;Let me rephrase my question.&lt;/P&gt;
&lt;P&gt;If you add "mysql" is application, which by default is associated with port 3306.&lt;/P&gt;
&lt;P&gt;And in same rule you would add server TCP 58740.&lt;/P&gt;
&lt;P&gt;Where would Palo look first - at Layer 7 - "mysql" or Layer 4 TCP Port 58740.&lt;/P&gt;
&lt;P&gt;Would it break the association with port 3306. And Palo would only allow traffic on TCP Port 58740 and not application "MySQL". In other words, it would break the rule for allowing traffic for Application "MySQL"?&lt;/P&gt;</description>
      <pubDate>Thu, 17 Oct 2024 17:34:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/service-port-overwrites-application-default-provided-port/m-p/606282#M2533</guid>
      <dc:creator>Martin2K</dc:creator>
      <dc:date>2024-10-17T17:34:55Z</dc:date>
    </item>
    <item>
      <title>Re: Service Port overwrites  Application default provided  port (?)</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/service-port-overwrites-application-default-provided-port/m-p/606736#M2537</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Security rules are evaluated left to right and from top to bottom&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;Source Address | User | Device | Zone |&lt;/P&gt;
&lt;P&gt;Destination Address | Device Application | Service | Action | Profile Options Target&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/network-security/security-policy/administration/security-rules#" target="_blank"&gt;https://docs.paloaltonetworks.com/network-security/security-policy/administration/security-rules#&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Based on this statement, is PA checking Application first, and if it matches for example "mysql", [default 3306],&amp;nbsp; PA would not&amp;nbsp; look further into the entry [TCP port 58740] added in Services? column?&lt;/P&gt;</description>
      <pubDate>Fri, 18 Oct 2024 03:27:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/service-port-overwrites-application-default-provided-port/m-p/606736#M2537</guid>
      <dc:creator>Martin2K</dc:creator>
      <dc:date>2024-10-18T03:27:58Z</dc:date>
    </item>
  </channel>
</rss>

