<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Has anybody encountered a situation where a rule was configured for one application but matched other applications? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/has-anybody-encountered-a-situation-where-a-rule-was-configured/m-p/17105#M12485</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have the following rule&lt;/P&gt;&lt;P&gt;&lt;IMG alt="rule.png" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/14915_rule.png" style="width: 620px; height: 97px;" /&gt;&lt;/P&gt;&lt;P&gt;I used 'any' as the service because we have web servers running on multiple ports and not just on the default.&lt;/P&gt;&lt;P&gt;While it does match ssl and web-browsing traffic as expected,&amp;nbsp; it also matches unexpected application traffic like the following&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="traffic.png" class="image-1 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/14916_traffic.png" style="width: 620px; height: 75px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't understand why it would match oracle traffic.&amp;nbsp; Any ideas?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 13 Aug 2014 11:17:14 GMT</pubDate>
    <dc:creator>palo_al</dc:creator>
    <dc:date>2014-08-13T11:17:14Z</dc:date>
    <item>
      <title>Has anybody encountered a situation where a rule was configured for one application but matched other applications?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/has-anybody-encountered-a-situation-where-a-rule-was-configured/m-p/17105#M12485</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have the following rule&lt;/P&gt;&lt;P&gt;&lt;IMG alt="rule.png" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/14915_rule.png" style="width: 620px; height: 97px;" /&gt;&lt;/P&gt;&lt;P&gt;I used 'any' as the service because we have web servers running on multiple ports and not just on the default.&lt;/P&gt;&lt;P&gt;While it does match ssl and web-browsing traffic as expected,&amp;nbsp; it also matches unexpected application traffic like the following&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="traffic.png" class="image-1 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/14916_traffic.png" style="width: 620px; height: 75px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't understand why it would match oracle traffic.&amp;nbsp; Any ideas?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Aug 2014 11:17:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/has-anybody-encountered-a-situation-where-a-rule-was-configured/m-p/17105#M12485</guid>
      <dc:creator>palo_al</dc:creator>
      <dc:date>2014-08-13T11:17:14Z</dc:date>
    </item>
    <item>
      <title>Re: Has anybody encountered a situation where a rule was configured for one application but matched other applications?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/has-anybody-encountered-a-situation-where-a-rule-was-configured/m-p/17106#M12486</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It's because You put ANY as a service. Please put there app-default and oracle shouldnt hitted this rule.&lt;/P&gt;&lt;P&gt;Explanation is that oracle using probably SSL. Corect me if I'm wrong.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Slawek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Aug 2014 11:20:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/has-anybody-encountered-a-situation-where-a-rule-was-configured/m-p/17106#M12486</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2014-08-13T11:20:36Z</dc:date>
    </item>
    <item>
      <title>Re: Has anybody encountered a situation where a rule was configured for one application but matched other applications?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/has-anybody-encountered-a-situation-where-a-rule-was-configured/m-p/17107#M12487</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The reason we have any is we have a few dozen virtual web servers running on different ports so I was hoping not to enumerate every single port.... I guess I'll have to start typing then :smileygrin:&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Aug 2014 11:26:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/has-anybody-encountered-a-situation-where-a-rule-was-configured/m-p/17107#M12487</guid>
      <dc:creator>palo_al</dc:creator>
      <dc:date>2014-08-13T11:26:31Z</dc:date>
    </item>
    <item>
      <title>Re: Has anybody encountered a situation where a rule was configured for one application but matched other applications?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/has-anybody-encountered-a-situation-where-a-rule-was-configured/m-p/17108#M12488</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes ... or create more security rules, ie. one per server with this server in Destination address field.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Aug 2014 11:31:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/has-anybody-encountered-a-situation-where-a-rule-was-configured/m-p/17108#M12488</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2014-08-13T11:31:21Z</dc:date>
    </item>
    <item>
      <title>Re: Has anybody encountered a situation where a rule was configured for one application but matched other applications?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/has-anybody-encountered-a-situation-where-a-rule-was-configured/m-p/17109#M12489</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Excuse me but this is a totally bogus explanation... so what if he put service any? The whole point of App-ID is to be port agnostic, that's how the product was sold to us. The replies above make no sense to me.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Aug 2014 11:41:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/has-anybody-encountered-a-situation-where-a-rule-was-configured/m-p/17109#M12489</guid>
      <dc:creator>ericgearhart</dc:creator>
      <dc:date>2014-08-13T11:41:02Z</dc:date>
    </item>
    <item>
      <title>Re: Has anybody encountered a situation where a rule was configured for one application but matched other applications?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/has-anybody-encountered-a-situation-where-a-rule-was-configured/m-p/17110#M12490</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Ericgearhart&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I'm wrong - please put here Your explanations.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So in your opinion its improperly identyfied aplication or so?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Slawek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Aug 2014 11:44:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/has-anybody-encountered-a-situation-where-a-rule-was-configured/m-p/17110#M12490</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2014-08-13T11:44:07Z</dc:date>
    </item>
    <item>
      <title>Re: Has anybody encountered a situation where a rule was configured for one application but matched other applications?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/has-anybody-encountered-a-situation-where-a-rule-was-configured/m-p/17111#M12491</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;out of curiousity, would you mind checking if you have log "at start" enabled and if the logs you see hitting the wrong rule are start or end logs&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Aug 2014 11:49:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/has-anybody-encountered-a-situation-where-a-rule-was-configured/m-p/17111#M12491</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2014-08-13T11:49:21Z</dc:date>
    </item>
    <item>
      <title>Re: Has anybody encountered a situation where a rule was configured for one application but matched other applications?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/has-anybody-encountered-a-situation-where-a-rule-was-configured/m-p/17112#M12492</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I must correct Slawek, if you put ANY to service, it's mean this application WITH any Port and not ANY application on any port. So you did it right.&lt;/P&gt;&lt;P&gt;The Problem what Slawek think, is the dependence in the Applications, if you put for example the application icq to the rule it will be automaticly allow the application ssl &amp;amp; web-browsing. But only if you don't have a deny any Rule at the end.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Back to your Problem with Oracle, with version do you have installed? PAN-OS and Application&amp;amp;Threats?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Aug 2014 11:50:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/has-anybody-encountered-a-situation-where-a-rule-was-configured/m-p/17112#M12492</guid>
      <dc:creator>FJU-ITCS</dc:creator>
      <dc:date>2014-08-13T11:50:33Z</dc:date>
    </item>
    <item>
      <title>Re: Has anybody encountered a situation where a rule was configured for one application but matched other applications?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/has-anybody-encountered-a-situation-where-a-rule-was-configured/m-p/17113#M12493</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/u1/13469"&gt;slv&lt;/A&gt; - see &lt;A href="https://live.paloaltonetworks.com/u1/21529"&gt;FJU&lt;/A&gt;'s response below. I totally agree with what FJU says below&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Aug 2014 12:03:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/has-anybody-encountered-a-situation-where-a-rule-was-configured/m-p/17113#M12493</guid>
      <dc:creator>ericgearhart</dc:creator>
      <dc:date>2014-08-13T12:03:11Z</dc:date>
    </item>
    <item>
      <title>Re: Has anybody encountered a situation where a rule was configured for one application but matched other applications?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/has-anybody-encountered-a-situation-where-a-rule-was-configured/m-p/17114#M12494</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I only have 'log at session end' enabled&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Aug 2014 12:18:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/has-anybody-encountered-a-situation-where-a-rule-was-configured/m-p/17114#M12494</guid>
      <dc:creator>palo_al</dc:creator>
      <dc:date>2014-08-13T12:18:33Z</dc:date>
    </item>
    <item>
      <title>Re: Has anybody encountered a situation where a rule was configured for one application but matched other applications?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/has-anybody-encountered-a-situation-where-a-rule-was-configured/m-p/17115#M12495</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;PAN OS version 6.0.3 , Apps version 449-2321&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Aug 2014 12:21:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/has-anybody-encountered-a-situation-where-a-rule-was-configured/m-p/17115#M12495</guid>
      <dc:creator>palo_al</dc:creator>
      <dc:date>2014-08-13T12:21:32Z</dc:date>
    </item>
    <item>
      <title>Re: Has anybody encountered a situation where a rule was configured for one application but matched other applications?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/has-anybody-encountered-a-situation-where-a-rule-was-configured/m-p/17116#M12496</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Incorrect sir...setting service to "ANY" will only allow for the traffic to traverse any port that still matches the specified application. Based off your logic, there would be no need to specify the application. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Aug 2014 12:26:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/has-anybody-encountered-a-situation-where-a-rule-was-configured/m-p/17116#M12496</guid>
      <dc:creator>DaveCorwin</dc:creator>
      <dc:date>2014-08-13T12:26:49Z</dc:date>
    </item>
    <item>
      <title>Re: Has anybody encountered a situation where a rule was configured for one application but matched other applications?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/has-anybody-encountered-a-situation-where-a-rule-was-configured/m-p/17117#M12497</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I just put in another rule to match the oracle traffic on port 1522. The traffic doesn't get matched by my ssl/web-browsing rule anymore.&lt;/P&gt;&lt;P&gt;It still doesn't explain how a rule configured with an ssl or web-browser application could match oracle traffic.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Aug 2014 16:05:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/has-anybody-encountered-a-situation-where-a-rule-was-configured/m-p/17117#M12497</guid>
      <dc:creator>palo_al</dc:creator>
      <dc:date>2014-08-14T16:05:41Z</dc:date>
    </item>
    <item>
      <title>Re: Has anybody encountered a situation where a rule was configured for one application but matched other applications?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/has-anybody-encountered-a-situation-where-a-rule-was-configured/m-p/17118#M12498</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The behavior is quite odd. Usually, if there is application shift i.e application is first identified as web-browsing and later after the firewall has seen more packets, the same traffic gets identified as oracle, it should trigger a second policy look-up. Clearly this is not happening. If the issue is still persisting, i would suggest opening up a ticket with support.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Aug 2014 04:51:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/has-anybody-encountered-a-situation-where-a-rule-was-configured/m-p/17118#M12498</guid>
      <dc:creator>tshiv</dc:creator>
      <dc:date>2014-08-15T04:51:34Z</dc:date>
    </item>
    <item>
      <title>Re: Has anybody encountered a situation where a rule was configured for one application but matched other applications?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/has-anybody-encountered-a-situation-where-a-rule-was-configured/m-p/17119#M12499</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi FJU&lt;/P&gt;&lt;P&gt;You read from my mind &lt;img id="smileywink" class="emoticon emoticon-smileywink" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-wink.png" alt="Smiley Wink" title="Smiley Wink" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I thought that Palo_al has more security rules (below is more narrow rules especially for oracle application) but was curious why this traffic hitting this rule.&lt;/P&gt;&lt;P&gt;So Your explanation is correct.&lt;/P&gt;&lt;P&gt;I'm fighting with support with ammy-admin and backup-exec application aren't correctly identified by PAN OS. So maybe it's happened to You too.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Slawek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Aug 2014 08:41:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/has-anybody-encountered-a-situation-where-a-rule-was-configured/m-p/17119#M12499</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2014-08-15T08:41:09Z</dc:date>
    </item>
    <item>
      <title>Re: Has anybody encountered a situation where a rule was configured for one application but matched other applications?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/has-anybody-encountered-a-situation-where-a-rule-was-configured/m-p/17120#M12500</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yup that doesn't make any sense. I suggest you open a case if you haven't. As a test, you can put a deny all rule at the bottom&amp;nbsp; and see if oracle is still being allowed but make sure you've allowed EVERYTHING that you need because you'll see a lot of blocked traffic which will cause issues with your users. Probably do that after hours. Hope that helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Aug 2014 17:20:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/has-anybody-encountered-a-situation-where-a-rule-was-configured/m-p/17120#M12500</guid>
      <dc:creator>x</dc:creator>
      <dc:date>2014-08-15T17:20:52Z</dc:date>
    </item>
  </channel>
</rss>

