<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: smtp/pop3 over SSL - how to configure security rules? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/smtp-pop3-over-ssl-how-to-configure-security-rules/m-p/1345#M1036</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The policy is correct. You allow all applications that are identified as SSL on the 3 ports 465,993,995 in your scenario.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is no way to modify the app id because the traffic is encrypted. The system can not see what app is trying e.g. to use port 465. So there is only one app called SSL. The only way for the system to identify the app is to use ssl decryption policy. Then you would see which app is using this port.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 08 Nov 2013 10:00:27 GMT</pubDate>
    <dc:creator>kbe</dc:creator>
    <dc:date>2013-11-08T10:00:27Z</dc:date>
    <item>
      <title>smtp/pop3 over SSL - how to configure security rules?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/smtp-pop3-over-ssl-how-to-configure-security-rules/m-p/1340#M1031</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I moved my email serwer from untrust to DMZ. Everything almost is working fine, almost ...&lt;/P&gt;&lt;P&gt;This server has ftp and webmail function too, so my security rules looks:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="2013-11-07_083113.png" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/9667_2013-11-07_083113.png" style="width: 620px; height: 102px;" /&gt;&lt;/P&gt;&lt;P&gt;I checked on aplipedia for aplication smtp and pop3. Accroding to aplipedia smtp uses tcp/25,587&amp;nbsp; and pop3 tcp/110.&lt;/P&gt;&lt;P&gt;Thats true for on secure connections. But how _properly_ pass SSL traffic?&lt;/P&gt;&lt;P&gt;On my server I use ports 465 (smtp) 993 (imap) 995 (pop3) for secures connections.&lt;/P&gt;&lt;P&gt;I'd like to use aplications insted of services like I use now.&lt;/P&gt;&lt;P&gt;I do this as a temporary solution.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please give my advice how to properly cinfigured security rules in such situations.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With Regards&lt;/P&gt;&lt;P&gt;Slawek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Nov 2013 07:37:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/smtp-pop3-over-ssl-how-to-configure-security-rules/m-p/1340#M1031</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2013-11-07T07:37:11Z</dc:date>
    </item>
    <item>
      <title>Re: smtp/pop3 over SSL - how to configure security rules?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/smtp-pop3-over-ssl-how-to-configure-security-rules/m-p/1341#M1032</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;Slawek&lt;/SPAN&gt;,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since according to applipedia, SMTP and POP3 are not incorporating SSL ports like 995 and 465, you can write a separate rule to include smtp and pop3 and have service as 'any'&amp;nbsp; instead of application-default. In that way, you can make sure that your other applications ftp, dns and web-browsing are still riding on their default ports while allowing SMTP and POP3 on all ports.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and regards,&lt;BR /&gt;Kunal Adak&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Nov 2013 15:23:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/smtp-pop3-over-ssl-how-to-configure-security-rules/m-p/1341#M1032</guid>
      <dc:creator>kadak</dc:creator>
      <dc:date>2013-11-07T15:23:45Z</dc:date>
    </item>
    <item>
      <title>Re: smtp/pop3 over SSL - how to configure security rules?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/smtp-pop3-over-ssl-how-to-configure-security-rules/m-p/1342#M1033</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Kadak&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank You for sugestion, I changed my policy.&lt;/P&gt;&lt;P&gt;But I have dubt that this is a right way to make workaround in _such_ simple problem.&lt;/P&gt;&lt;P&gt;I wonder that maybe will be better to change aplication definition and add there my ports. Port that I use are standart and many administrator use the same.&lt;/P&gt;&lt;P&gt;I sow many time on this forum and tech doc's that it's important to use aplication default in service field of policy - because using "any" could be "dangerous".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With Regards&lt;/P&gt;&lt;P&gt;SLawek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Nov 2013 16:34:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/smtp-pop3-over-ssl-how-to-configure-security-rules/m-p/1342#M1033</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2013-11-07T16:34:10Z</dc:date>
    </item>
    <item>
      <title>Re: smtp/pop3 over SSL - how to configure security rules?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/smtp-pop3-over-ssl-how-to-configure-security-rules/m-p/1343#M1034</link>
      <description>&lt;P&gt;Hell Slawek,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Some more investigation lead me to the following document which answers your scenario:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClHqCAK" target="_self"&gt;App-IDs for SSL-Secured Versions of Well-Known Services&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope the above document helps you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks and regards,&lt;/P&gt;
&lt;P&gt;Kunal Adak&lt;/P&gt;</description>
      <pubDate>Thu, 06 Apr 2023 15:03:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/smtp-pop3-over-ssl-how-to-configure-security-rules/m-p/1343#M1034</guid>
      <dc:creator>kadak</dc:creator>
      <dc:date>2023-04-06T15:03:10Z</dc:date>
    </item>
    <item>
      <title>Re: smtp/pop3 over SSL - how to configure security rules?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/smtp-pop3-over-ssl-how-to-configure-security-rules/m-p/1344#M1035</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Second point looks interesting:&lt;/P&gt;&lt;P&gt;"Create service objects for the SSL-variant ports, and allow 'ssl' App-ID in security policy on those services: SMTPS:TCP/465; IMAPS:TCP/993; POP3S:995; IMAPS:TCP/585."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is my policy correct?&lt;/P&gt;&lt;P&gt;&lt;IMG alt="2013-11-07_195431.png" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/9677_2013-11-07_195431.png" style="width: 620px; height: 32px;" /&gt;&lt;/P&gt;&lt;P&gt;ie. "Port 465" has tcp/465 enabled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;SLawek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Nov 2013 18:56:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/smtp-pop3-over-ssl-how-to-configure-security-rules/m-p/1344#M1035</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2013-11-07T18:56:40Z</dc:date>
    </item>
    <item>
      <title>Re: smtp/pop3 over SSL - how to configure security rules?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/smtp-pop3-over-ssl-how-to-configure-security-rules/m-p/1345#M1036</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The policy is correct. You allow all applications that are identified as SSL on the 3 ports 465,993,995 in your scenario.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is no way to modify the app id because the traffic is encrypted. The system can not see what app is trying e.g. to use port 465. So there is only one app called SSL. The only way for the system to identify the app is to use ssl decryption policy. Then you would see which app is using this port.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Nov 2013 10:00:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/smtp-pop3-over-ssl-how-to-configure-security-rules/m-p/1345#M1036</guid>
      <dc:creator>kbe</dc:creator>
      <dc:date>2013-11-08T10:00:27Z</dc:date>
    </item>
    <item>
      <title>Re: smtp/pop3 over SSL - how to configure security rules?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/smtp-pop3-over-ssl-how-to-configure-security-rules/m-p/1346#M1037</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I understand your explanation.&lt;/P&gt;&lt;P&gt;In my opinion it is mistake to put only one 586port and 25 as a ports for smtp. Most of Us using also different ports too.&lt;/P&gt;&lt;P&gt;Using workaround that provice Kadak we have to make another policy that PA have to process, so we have two policy in every situation where is SSL traffic and regular trafic but on different ports (like in my scenario).&lt;/P&gt;&lt;P&gt;If this is Palo Alto vision - I can't do anything with it &lt;SPAN __jive_emoticon_name="sad"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can't use decryption.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Slawek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Nov 2013 13:30:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/smtp-pop3-over-ssl-how-to-configure-security-rules/m-p/1346#M1037</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2013-11-08T13:30:03Z</dc:date>
    </item>
    <item>
      <title>Re: smtp/pop3 over SSL - how to configure security rules?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/smtp-pop3-over-ssl-how-to-configure-security-rules/m-p/1347#M1038</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Which other way do you see to implement inspection of encrypted data flow?&lt;/P&gt;&lt;P&gt;Have you looked at the data flow chart explaining how the PA dataplane handels traffic? Maybe that helps to understand.&lt;/P&gt;&lt;P&gt;I don´t think there is another vendor that can identify an application that sends encrypted traffic without breaking the encryption. How should this work?&lt;/P&gt;&lt;P&gt;And the ports 25 and 586 are the default ports for smtp (see RFC5321). No matter which other ports you are using.&lt;/P&gt;&lt;P&gt;And there is no problem by creating more than one rule to handle traffic that can not be handled by only one rule. I also created some own services to handle traffic that is not caught by the app-default setting. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don´t see the main problem you seem to have with the PA way.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;cu&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Nov 2013 14:02:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/smtp-pop3-over-ssl-how-to-configure-security-rules/m-p/1347#M1038</guid>
      <dc:creator>kbe</dc:creator>
      <dc:date>2013-11-08T14:02:20Z</dc:date>
    </item>
  </channel>
</rss>

