<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is New App ID Rule Setup Correctly? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/is-new-app-id-rule-setup-correctly/m-p/537118#M110303</link>
    <description>&lt;P&gt;Any Ideas as to why it would have so many hits on this rule? All the traffic hitting this rule is unable to identify the application.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 30 Mar 2023 15:31:13 GMT</pubDate>
    <dc:creator>DuggiFresh</dc:creator>
    <dc:date>2023-03-30T15:31:13Z</dc:date>
    <item>
      <title>Is New App ID Rule Setup Correctly?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-new-app-id-rule-setup-correctly/m-p/536835#M110259</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Its getting a lot of hits, I setup Application filter for new app IDs and added them to their own Security Policy rule. Does this look correctly? Im confused as to why its getting so many hits.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DuggiFresh_0-1680043214733.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/49076i688CBCBEE94C9081/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="DuggiFresh_0-1680043214733.png" alt="DuggiFresh_0-1680043214733.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Mar 2023 22:40:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-new-app-id-rule-setup-correctly/m-p/536835#M110259</guid>
      <dc:creator>DuggiFresh</dc:creator>
      <dc:date>2023-03-28T22:40:30Z</dc:date>
    </item>
    <item>
      <title>Re: Is New App ID Rule Setup Correctly?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-new-app-id-rule-setup-correctly/m-p/537118#M110303</link>
      <description>&lt;P&gt;Any Ideas as to why it would have so many hits on this rule? All the traffic hitting this rule is unable to identify the application.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Mar 2023 15:31:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-new-app-id-rule-setup-correctly/m-p/537118#M110303</guid>
      <dc:creator>DuggiFresh</dc:creator>
      <dc:date>2023-03-30T15:31:13Z</dc:date>
    </item>
    <item>
      <title>Re: Is New App ID Rule Setup Correctly?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-new-app-id-rule-setup-correctly/m-p/537120#M110305</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/247570"&gt;@DuggiFresh&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Gonna go out on a limb and say that this is the first app-id based rule that you have in your rulebase? If that's the case, that'll match a whole lot of traffic as the firewall needs to allow enough traffic to identify the application. As soon as the application is identified, the firewall will reanlyze the rulebase and pass the traffic to the corresponding entry.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As long as this is the first app-id based rule that is in your rulebase, or is the first for at least a subset of your users, this is expected behavior.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Mar 2023 15:40:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-new-app-id-rule-setup-correctly/m-p/537120#M110305</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2023-03-30T15:40:59Z</dc:date>
    </item>
    <item>
      <title>Re: Is New App ID Rule Setup Correctly?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-new-app-id-rule-setup-correctly/m-p/537121#M110306</link>
      <description>&lt;P&gt;All outgoing connections that don't get past TCP 3way handshake will match your New Apps rule.&lt;/P&gt;
&lt;P&gt;Find application that you permit out anyway and add rule above it to collect all incompletes.&lt;/P&gt;
&lt;P&gt;Example below with traceroute.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Source - inside&lt;/P&gt;
&lt;P&gt;Destination - outside&lt;/P&gt;
&lt;P&gt;Application - traceroute&lt;/P&gt;
&lt;P&gt;Service - any&lt;/P&gt;
&lt;P&gt;Action - allow&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This will collect all incomlete sessions and your chosen app and keep New Apps rule clean.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Mar 2023 15:49:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-new-app-id-rule-setup-correctly/m-p/537121#M110306</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-03-30T15:49:04Z</dc:date>
    </item>
    <item>
      <title>Re: Is New App ID Rule Setup Correctly?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-new-app-id-rule-setup-correctly/m-p/537122#M110307</link>
      <description>&lt;P&gt;So this rule should be near the bottom of my policies, below my identified apps? I have my applications identified in my policies.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Mar 2023 15:55:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-new-app-id-rule-setup-correctly/m-p/537122#M110307</guid>
      <dc:creator>DuggiFresh</dc:creator>
      <dc:date>2023-03-30T15:55:14Z</dc:date>
    </item>
    <item>
      <title>Re: Is New App ID Rule Setup Correctly?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-new-app-id-rule-setup-correctly/m-p/537125#M110308</link>
      <description>&lt;P&gt;New Apps rule should be before any of other outgoing rules if you want to have correct reporting.&lt;/P&gt;
&lt;P&gt;If you want to keep New Apps rule log clean you need to add incomplete collector rule above it according to my example from previous post.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Mar 2023 15:57:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-new-app-id-rule-setup-correctly/m-p/537125#M110308</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-03-30T15:57:55Z</dc:date>
    </item>
    <item>
      <title>Re: Is New App ID Rule Setup Correctly?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-new-app-id-rule-setup-correctly/m-p/537126#M110309</link>
      <description>&lt;P&gt;Thank you, Do I need new app ID rule for Inside to inside?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Mar 2023 16:07:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-new-app-id-rule-setup-correctly/m-p/537126#M110309</guid>
      <dc:creator>DuggiFresh</dc:creator>
      <dc:date>2023-03-30T16:07:55Z</dc:date>
    </item>
  </channel>
</rss>

