<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic active-directory-base application isn't match traffic when services/URL Category is set to &amp;quot;application-default&amp;quot; in security rule in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/active-directory-base-application-isn-t-match-traffic-when/m-p/467013#M102742</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I use a Firewall at version 10.0.8-h8. I wrote a rule to allow the application "active-directory-base" (which contains several ports) in the application section then "application-default" in the services/URL category section as recommended by PA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The observation I made is that the flow never matches this rule. It is even dropped by the inter-zone rule.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I change "application-default" by "any" in the services/URL category table, it works fine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you have an explanation for this behavior?&lt;/P&gt;&lt;P&gt;#strata&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 20 Feb 2022 11:46:57 GMT</pubDate>
    <dc:creator>Ouattara</dc:creator>
    <dc:date>2022-02-20T11:46:57Z</dc:date>
    <item>
      <title>active-directory-base application isn't match traffic when services/URL Category is set to "application-default" in security rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-directory-base-application-isn-t-match-traffic-when/m-p/467013#M102742</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I use a Firewall at version 10.0.8-h8. I wrote a rule to allow the application "active-directory-base" (which contains several ports) in the application section then "application-default" in the services/URL category section as recommended by PA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The observation I made is that the flow never matches this rule. It is even dropped by the inter-zone rule.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I change "application-default" by "any" in the services/URL category table, it works fine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you have an explanation for this behavior?&lt;/P&gt;&lt;P&gt;#strata&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 20 Feb 2022 11:46:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-directory-base-application-isn-t-match-traffic-when/m-p/467013#M102742</guid>
      <dc:creator>Ouattara</dc:creator>
      <dc:date>2022-02-20T11:46:57Z</dc:date>
    </item>
    <item>
      <title>Re: active-directory-base application isn't match traffic when services/URL Category is set to "application-default" in security rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-directory-base-application-isn-t-match-traffic-when/m-p/467190#M102764</link>
      <description>&lt;P&gt;do the ports used by the sessions match the default ports listed in active-directory-base&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;LABEL id="ext-gen2292" class="x-form-item-label" for="ext-comp-2345"&gt;&lt;STRONG&gt;Standard Ports:&amp;nbsp;&amp;nbsp;&lt;/STRONG&gt;&lt;/LABEL&gt;&lt;/P&gt;
&lt;DIV id="x-form-el-ext-comp-2345" class="x-form-element"&gt;
&lt;DIV id="ext-comp-2345" class=" x-form-display-field"&gt;tcp/1025-5000, tcp/135,138,139,389,445,464,636, tcp/49152-65535, tcp/5722,9389, udp/88,123,137,138,389,445,464,2535&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;and did you allow the dependencies in another rule?&lt;/P&gt;
&lt;P&gt;&lt;LABEL id="ext-gen2296" class="x-form-item-label" for="ext-comp-2349"&gt;&lt;STRONG&gt;Depends on:&amp;nbsp;&amp;nbsp;&lt;/STRONG&gt;&lt;/LABEL&gt;&lt;/P&gt;
&lt;DIV id="x-form-el-ext-comp-2349" class="x-form-element"&gt;
&lt;DIV id="ext-comp-2349" class=" x-form-display-field"&gt;kerberos, ms-ds-smb-base, ms-netlogon, netbios-dg, netbios-ns, netbios-ss&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Mon, 21 Feb 2022 11:57:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-directory-base-application-isn-t-match-traffic-when/m-p/467190#M102764</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2022-02-21T11:57:08Z</dc:date>
    </item>
  </channel>
</rss>

