<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Basic question regarding policy in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/basic-question-regarding-policy/m-p/523173#M108357</link>
    <description>&lt;P&gt;Just trying to understand the policy a bit more.&lt;/P&gt;
&lt;P&gt;under the policy |&amp;nbsp; application, if I select FTP and select http/s under the service, I assume fw is expecting FTP to run on port 80/443?&lt;/P&gt;
&lt;P&gt;hence, if I select app default on services, it will then expect the ftp traffic on port 21?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;what I was looking into allow ftp/http/s. I end up creating 2 policies for this, 1. with http/s under services without applications selected&lt;/P&gt;
&lt;P&gt;2. application selected ftp and under services, I chose app default.&lt;/P&gt;
&lt;P&gt;I guess my thinking is ok?&lt;/P&gt;
&lt;P&gt;thank a lot&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 02 Dec 2022 20:28:59 GMT</pubDate>
    <dc:creator>Shadow</dc:creator>
    <dc:date>2022-12-02T20:28:59Z</dc:date>
    <item>
      <title>Basic question regarding policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/basic-question-regarding-policy/m-p/523173#M108357</link>
      <description>&lt;P&gt;Just trying to understand the policy a bit more.&lt;/P&gt;
&lt;P&gt;under the policy |&amp;nbsp; application, if I select FTP and select http/s under the service, I assume fw is expecting FTP to run on port 80/443?&lt;/P&gt;
&lt;P&gt;hence, if I select app default on services, it will then expect the ftp traffic on port 21?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;what I was looking into allow ftp/http/s. I end up creating 2 policies for this, 1. with http/s under services without applications selected&lt;/P&gt;
&lt;P&gt;2. application selected ftp and under services, I chose app default.&lt;/P&gt;
&lt;P&gt;I guess my thinking is ok?&lt;/P&gt;
&lt;P&gt;thank a lot&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Dec 2022 20:28:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/basic-question-regarding-policy/m-p/523173#M108357</guid>
      <dc:creator>Shadow</dc:creator>
      <dc:date>2022-12-02T20:28:59Z</dc:date>
    </item>
    <item>
      <title>Re: Basic question regarding policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/basic-question-regarding-policy/m-p/523181#M108360</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;You logic is sound with regards to the Applications and Services (ports). You can do it with two policies or with one:&lt;/P&gt;
&lt;P&gt;1. Select FTP as application and http/https as services ( this will allow the FTP application over ports 80,443), then second policy as FTP application and services as application default.&lt;/P&gt;
&lt;P&gt;2. Select FTP as the application, then http/https and port 21 as a service, ( cant recall if there is a 21 by default, so you might have to add it)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Your choice.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Dec 2022 20:56:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/basic-question-regarding-policy/m-p/523181#M108360</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2022-12-02T20:56:04Z</dc:date>
    </item>
    <item>
      <title>Re: Basic question regarding policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/basic-question-regarding-policy/m-p/523334#M108385</link>
      <description>&lt;P&gt;Thak you Otakarklier, can you also explain the relationship between "application &amp;amp; Service/URL"&lt;/P&gt;
&lt;P&gt;if I select Application = &amp;gt; "any" and select Service/URL =&amp;gt; http/https, my traffic seems to drop to google or Facebook.&lt;/P&gt;
&lt;P&gt;if I add web-browsing under the application, this will not work either, only if I select addplication-default under Service/URL&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;what I am trying to get done is to allow http/https from inside to outside. but it needs to be http/https using browser others get blocked&lt;/P&gt;
&lt;P&gt;any idea how to achieve this without using "any" in the rule set&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;much appreciated&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Dec 2022 18:57:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/basic-question-regarding-policy/m-p/523334#M108385</guid>
      <dc:creator>Shadow</dc:creator>
      <dc:date>2022-12-05T18:57:09Z</dc:date>
    </item>
    <item>
      <title>Re: Basic question regarding policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/basic-question-regarding-policy/m-p/523342#M108386</link>
      <description>&lt;P&gt;Ignore the above pls, I just forgot to allow DNS &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Dec 2022 20:43:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/basic-question-regarding-policy/m-p/523342#M108386</guid>
      <dc:creator>Shadow</dc:creator>
      <dc:date>2022-12-05T20:43:58Z</dc:date>
    </item>
  </channel>
</rss>

