<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Clarification on App Rule - I thought I understood this in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/clarification-on-app-rule-i-thought-i-understood-this/m-p/545125#M111511</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/272860"&gt;@TonyDeHart&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The ssl traffic that you see being denied.&amp;nbsp; Is it port 443 or 3978?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
    <pubDate>Wed, 07 Jun 2023 16:28:24 GMT</pubDate>
    <dc:creator>TomYoung</dc:creator>
    <dc:date>2023-06-07T16:28:24Z</dc:date>
    <item>
      <title>Clarification on App Rule - I thought I understood this</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/clarification-on-app-rule-i-thought-i-understood-this/m-p/544920#M111477</link>
      <description>&lt;P&gt;I recently moved a firewall into being managed by Panorama.&amp;nbsp; I setup an Application rule specifying the application as PANORAMA which includes the ports necessary (I assumed) for Panorama communications but the firewall could not be added successfully until I allowed port 3978 traffic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The logs showed 3978 being recognized as SSL initially and being denied as it wasn't getting included in the rule.&amp;nbsp; What I don't understand or I guess I misunderstand, why isn't SSL allowed under that rule until the service is recognized as Panorama?&amp;nbsp; SSL is implicitly allowed under the PANORAMA application so I thought it was allowed initially under that rule on the ports the application supports.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What am I missing?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I thought I understood it based on this article but this isn't how it seems to be working:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PLLICA4" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PLLICA4&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jun 2023 12:43:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/clarification-on-app-rule-i-thought-i-understood-this/m-p/544920#M111477</guid>
      <dc:creator>TonyDeHart</dc:creator>
      <dc:date>2023-06-06T12:43:32Z</dc:date>
    </item>
    <item>
      <title>Re: Clarification on App Rule - I thought I understood this</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/clarification-on-app-rule-i-thought-i-understood-this/m-p/545091#M111505</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/272860"&gt;@TonyDeHart&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could it be because application defaults is being used ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;SSL appllication default is port 443.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;/P&gt;
&lt;P&gt;-Kim.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jun 2023 12:37:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/clarification-on-app-rule-i-thought-i-understood-this/m-p/545091#M111505</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2023-06-07T12:37:56Z</dc:date>
    </item>
    <item>
      <title>Re: Clarification on App Rule - I thought I understood this</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/clarification-on-app-rule-i-thought-i-understood-this/m-p/545099#M111506</link>
      <description>&lt;P&gt;I guess I was assuming APPLICATION-DEFAULTS needs to be set to make sure it is using the correct ports for the applications as listed.&amp;nbsp; I assume it is failing because of that since SSL wouldn't fail otherwise but if I add SSL and don't specify a port or application default then SSL can run on any port. Do I just need a separate rule for SSL on that specific PORT then? What's the point of the implicit applications then?&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jun 2023 13:35:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/clarification-on-app-rule-i-thought-i-understood-this/m-p/545099#M111506</guid>
      <dc:creator>TonyDeHart</dc:creator>
      <dc:date>2023-06-07T13:35:30Z</dc:date>
    </item>
    <item>
      <title>Re: Clarification on App Rule - I thought I understood this</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/clarification-on-app-rule-i-thought-i-understood-this/m-p/545105#M111507</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/272860"&gt;@TonyDeHart&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I had the same question. Is your ssl traffic on port 443 or 3978?&amp;nbsp; If it is on 3978, it should not be blocked and should application shift to panorama.&amp;nbsp; If it is on 443, then it is a separate app that will need to be allowed by rule.&amp;nbsp; I believe your current rule will only allow ssl on 3978 until it shifts.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;PANW does not tells us what apps are required between Panorama and the managed NGFW, but they do give us this list of ports -&amp;gt; &lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/firewall-administration/reference-port-number-usage/ports-used-for-panorama" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/firewall-administration/reference-port-number-usage/ports-used-for-panorama&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There is a separate tcp/443 listed which seems to indicate to me that ssl needs to be added to the list of applications in your rule.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jun 2023 14:35:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/clarification-on-app-rule-i-thought-i-understood-this/m-p/545105#M111507</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-06-07T14:35:27Z</dc:date>
    </item>
    <item>
      <title>Re: Clarification on App Rule - I thought I understood this</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/clarification-on-app-rule-i-thought-i-understood-this/m-p/545118#M111508</link>
      <description>&lt;P&gt;I guess my question has more to do with why the Implied App isn't actually used in this case.&amp;nbsp; If I have a rule that specifies PANORAMA as an application and SSL is implicit to that I don't understand why SSL isn't allowed automatically and needs to be explicitly allowed in the rule itself.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jun 2023 15:46:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/clarification-on-app-rule-i-thought-i-understood-this/m-p/545118#M111508</guid>
      <dc:creator>TonyDeHart</dc:creator>
      <dc:date>2023-06-07T15:46:33Z</dc:date>
    </item>
    <item>
      <title>Re: Clarification on App Rule - I thought I understood this</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/clarification-on-app-rule-i-thought-i-understood-this/m-p/545123#M111509</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/272860"&gt;@TonyDeHart&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;SSL is only implicitly allowed &lt;EM&gt;until&lt;/EM&gt; the NGFW identifies the application as panorama.&amp;nbsp; Here are explanations of the cases from the URL you posted:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Case 1:&amp;nbsp; SSL traffic is allowed by rule and still alowed when it shifts to sharepoint-online.&lt;/LI&gt;
&lt;LI&gt;Case 2:&amp;nbsp; SSL traffic to &lt;A href="http://www.example.com" target="_blank"&gt;www.example.com&lt;/A&gt; is allowed temporarily but denied because it never shifts to sharepoint-online.&lt;/LI&gt;
&lt;LI&gt;Case 3:&amp;nbsp; SSL traffic to &lt;A href="http://www.facebook.com" target="_blank"&gt;www.facebook.com&lt;/A&gt; is allowed temporarily but denied after it shifts to facebook-base.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;This is the desired behavior as we do not want a L7 rule allowing also panorama to allow all ssl.&amp;nbsp; We want it to allow only the selected application.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jun 2023 16:12:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/clarification-on-app-rule-i-thought-i-understood-this/m-p/545123#M111509</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-06-07T16:12:42Z</dc:date>
    </item>
    <item>
      <title>Re: Clarification on App Rule - I thought I understood this</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/clarification-on-app-rule-i-thought-i-understood-this/m-p/545124#M111510</link>
      <description>&lt;P&gt;So why doesn't CASE 1 apply here? It is SSL traffic and then shifts to PANORAMA was my assumption here.&amp;nbsp; Not doubting your answer just trying to understand as that was how I was reading it - the SSL is implicitly allowed until identified and what I see in the logs is this initial SSL communications on 3978 and then the shift to PANORAMA.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jun 2023 16:16:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/clarification-on-app-rule-i-thought-i-understood-this/m-p/545124#M111510</guid>
      <dc:creator>TonyDeHart</dc:creator>
      <dc:date>2023-06-07T16:16:54Z</dc:date>
    </item>
    <item>
      <title>Re: Clarification on App Rule - I thought I understood this</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/clarification-on-app-rule-i-thought-i-understood-this/m-p/545125#M111511</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/272860"&gt;@TonyDeHart&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The ssl traffic that you see being denied.&amp;nbsp; Is it port 443 or 3978?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jun 2023 16:28:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/clarification-on-app-rule-i-thought-i-understood-this/m-p/545125#M111511</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-06-07T16:28:24Z</dc:date>
    </item>
    <item>
      <title>Re: Clarification on App Rule - I thought I understood this</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/clarification-on-app-rule-i-thought-i-understood-this/m-p/545130#M111512</link>
      <description>&lt;P&gt;It is on port 3978 but now that I've sat on this a while and looked at the logs again, it appears there may be legitimate SSL traffic on 3978 as not all the traffic is identified as Panorama.&amp;nbsp; Some it appears to be remaining as SSL over the long term.&amp;nbsp; When I had initially set this up the SSL was switching over to Panorama so I assume it was ALL identified a Panorama but there appears to be a good deal of both here.&amp;nbsp; Just seems strange to me that Panorama's own traffic wouldn't be identified as just that and not generically as SSL.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jun 2023 16:52:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/clarification-on-app-rule-i-thought-i-understood-this/m-p/545130#M111512</guid>
      <dc:creator>TonyDeHart</dc:creator>
      <dc:date>2023-06-07T16:52:43Z</dc:date>
    </item>
    <item>
      <title>Re: Clarification on App Rule - I thought I understood this</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/clarification-on-app-rule-i-thought-i-understood-this/m-p/545132#M111513</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/272860"&gt;@TonyDeHart&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes, that is strange.&amp;nbsp; Looking at the URL I posted with the ports, I would think you would need to allow SSL on 443 as well.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jun 2023 16:57:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/clarification-on-app-rule-i-thought-i-understood-this/m-p/545132#M111513</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-06-07T16:57:07Z</dc:date>
    </item>
    <item>
      <title>Re: Clarification on App Rule - I thought I understood this</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/clarification-on-app-rule-i-thought-i-understood-this/m-p/545344#M111533</link>
      <description>&lt;P&gt;Interestingly, to add to this, traffic from other firewalls to Panorama is properly tagged as Panorama traffic and NOT SSL.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Palo support is scratching their head over this too so I now don't feel so bad. If I find out what's going on I'll post it here.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jun 2023 19:16:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/clarification-on-app-rule-i-thought-i-understood-this/m-p/545344#M111533</guid>
      <dc:creator>TonyDeHart</dc:creator>
      <dc:date>2023-06-08T19:16:15Z</dc:date>
    </item>
    <item>
      <title>Re: Clarification on App Rule - I thought I understood this</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/clarification-on-app-rule-i-thought-i-understood-this/m-p/545652#M111574</link>
      <description>&lt;P&gt;After some conversation with Palo support it turns out there are situations now with 10.2 and above that Panorama traffic is NOT identified as Panorama and is only identified as SSL traffic. According to Palo Alto support, this requires that SSL on 3978 be EXPLICITLY allowed for communications with Panorama. Supposedly, this was originally identified as a bug some time ago but for technical reasons has to be this way.&amp;nbsp; A rule with SSL/PANORAMA on port 3978 is necessary.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jun 2023 20:26:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/clarification-on-app-rule-i-thought-i-understood-this/m-p/545652#M111574</guid>
      <dc:creator>TonyDeHart</dc:creator>
      <dc:date>2023-06-12T20:26:39Z</dc:date>
    </item>
    <item>
      <title>Re: Clarification on App Rule - I thought I understood this</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/clarification-on-app-rule-i-thought-i-understood-this/m-p/546194#M111642</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/272860"&gt;@TonyDeHart&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I just had a customer upgrade his Panorama to 10.2 and this change in App-ID BROKE his existing rule which only had the panorama App-ID.&amp;nbsp; We had to create a new rule allowing ssl on tcp/3978.&amp;nbsp; The NGFW was also upgraded to 10.2.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It was working before, but the upgrade broke the connectivity to the remote NGFWs.&amp;nbsp; I quickly looked through the 10.2 known issues, and I did not find this bug.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for the info!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jun 2023 14:27:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/clarification-on-app-rule-i-thought-i-understood-this/m-p/546194#M111642</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-06-16T14:27:30Z</dc:date>
    </item>
    <item>
      <title>Re: Clarification on App Rule - I thought I understood this</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/clarification-on-app-rule-i-thought-i-understood-this/m-p/546238#M111647</link>
      <description>&lt;P&gt;Glad it helped!&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jun 2023 11:15:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/clarification-on-app-rule-i-thought-i-understood-this/m-p/546238#M111647</guid>
      <dc:creator>TonyDeHart</dc:creator>
      <dc:date>2023-06-16T11:15:38Z</dc:date>
    </item>
    <item>
      <title>Re: Clarification on App Rule - I thought I understood this</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/clarification-on-app-rule-i-thought-i-understood-this/m-p/546310#M111666</link>
      <description>&lt;TABLE class="table colsep rowsep  table-striped"&gt;
&lt;TBODY class="tbody"&gt;
&lt;TR class="row rowsep"&gt;
&lt;TD class="entry"&gt;
&lt;DIV&gt;
&lt;DIV class="p"&gt;
&lt;DIV&gt;
&lt;DIV&gt;PAN-192930&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/TD&gt;
&lt;TD class="entry relcol"&gt;
&lt;DIV&gt;
&lt;DIV class="p"&gt;
&lt;DIV&gt;Fixed an issue where, when the default port was not TCP/443, implicitly used SSL applications were blocked by the Security policy as an SSL application and did not shift to the correct application.&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;</description>
      <pubDate>Sat, 17 Jun 2023 09:34:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/clarification-on-app-rule-i-thought-i-understood-this/m-p/546310#M111666</guid>
      <dc:creator>dmifsud</dc:creator>
      <dc:date>2023-06-17T09:34:08Z</dc:date>
    </item>
    <item>
      <title>Re: Clarification on App Rule - I thought I understood this</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/clarification-on-app-rule-i-thought-i-understood-this/m-p/546401#M111686</link>
      <description>&lt;P&gt;Thank you &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/131231"&gt;@dmifsud&lt;/a&gt; !&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For whatever reason, this customer upgraded to 10.2.0 only.&amp;nbsp; Once he upgrades to the preferred release, we will check if the original rule works again.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jun 2023 21:26:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/clarification-on-app-rule-i-thought-i-understood-this/m-p/546401#M111686</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-06-19T21:26:44Z</dc:date>
    </item>
    <item>
      <title>Re: Clarification on App Rule - I thought I understood this</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/clarification-on-app-rule-i-thought-i-understood-this/m-p/547261#M111800</link>
      <description>&lt;P&gt;What release did they fix that in (PAN-192930).&amp;nbsp; The engineer I was on the phone with before had notes he showed me from internal conversations that said it was working as intended and they didn't plan to patch/fix it.&amp;nbsp; I'd like to update him on which version this is in.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jun 2023 12:54:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/clarification-on-app-rule-i-thought-i-understood-this/m-p/547261#M111800</guid>
      <dc:creator>TonyDeHart</dc:creator>
      <dc:date>2023-06-26T12:54:12Z</dc:date>
    </item>
    <item>
      <title>Re: Clarification on App Rule - I thought I understood this</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/clarification-on-app-rule-i-thought-i-understood-this/m-p/547262#M111801</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/272860"&gt;@TonyDeHart&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I googled PAN-192930 and found it "addressed" (fixed) in 10.1.6 and 10.2.2.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jun 2023 12:57:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/clarification-on-app-rule-i-thought-i-understood-this/m-p/547262#M111801</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-06-26T12:57:08Z</dc:date>
    </item>
    <item>
      <title>Re: Clarification on App Rule - I thought I understood this</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/clarification-on-app-rule-i-thought-i-understood-this/m-p/547267#M111802</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/77347"&gt;@TomYoung&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/272860"&gt;@TonyDeHart&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I googled PAN-192930 and found it "addressed" (fixed) in 10.1.6 and 10.2.2.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Sorry I guess I could have done that...&amp;nbsp; Thank you!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So now the only problem is we are running 10.2.3-h4 and 10.1.9-h1 and that doesn't work.&amp;nbsp; Not sure what is fixed unless the discussion the engineer pointed out was related to this "fix" not actually being fixed.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jun 2023 13:12:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/clarification-on-app-rule-i-thought-i-understood-this/m-p/547267#M111802</guid>
      <dc:creator>TonyDeHart</dc:creator>
      <dc:date>2023-06-26T13:12:31Z</dc:date>
    </item>
    <item>
      <title>Re: Clarification on App Rule - I thought I understood this</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/clarification-on-app-rule-i-thought-i-understood-this/m-p/547351#M111807</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/272860"&gt;@TonyDeHart&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Good to know.&amp;nbsp; I am waiting to hear back from the customer.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jun 2023 04:09:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/clarification-on-app-rule-i-thought-i-understood-this/m-p/547351#M111807</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-06-27T04:09:48Z</dc:date>
    </item>
  </channel>
</rss>

