<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Windows-Remote-Management &amp;amp; Implicit Use of Web-Browsing in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/windows-remote-management-amp-implicit-use-of-web-browsing/m-p/1244729#M125763</link>
    <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/3296"&gt;@emr_1&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;I agree with you, and TAC is wrong.&lt;/P&gt;
&lt;P&gt;If I configured a rule as below:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2025-12-25 15 29 20.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/70215iA546A79341F35E25/image-size/large?v=v2&amp;amp;px=999" role="button" title="2025-12-25 15 29 20.png" alt="2025-12-25 15 29 20.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The rule on the box is recognized as below:&lt;/P&gt;
&lt;P&gt;)&amp;gt; show running security-policy&lt;/P&gt;
&lt;P&gt;"test; index: 1" {&lt;BR /&gt;from any;&lt;BR /&gt;source any;&lt;BR /&gt;source-region none;&lt;BR /&gt;to any;&lt;BR /&gt;destination any;&lt;BR /&gt;destination-region none;&lt;BR /&gt;user any;&lt;BR /&gt;source-device any;&lt;BR /&gt;destination-device any;&lt;BR /&gt;source-advanced-device any;&lt;BR /&gt;destination-advanced-device any;&lt;BR /&gt;category any;&lt;BR /&gt;application/service [0:windows-remote-ma/tcp/any/5985 1:windows-remote-ma/tcp/any/5986 ];&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;application/service(implicit) [0:web-browsing/tcp/any/5985 1:web-browsing/tcp/any/5986 ];&lt;/FONT&gt;&lt;BR /&gt;action allow;&lt;BR /&gt;icmp-unreachable: no&lt;BR /&gt;terminal yes;&lt;BR /&gt;}&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As you know, "&lt;FONT color="#FF0000"&gt;web-browsing/tcp/any/5985"&lt;FONT color="#000000"&gt; is "application/protocol/source-port/dest-port".&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;FONT color="#000000"&gt;By the way, I found issue from release note.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;FONT color="#000000"&gt;===&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;FONT color="#000000"&gt;&lt;STRONG class="ph b"&gt;PAN-194408&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;FONT color="#000000"&gt;Fixed an issue where, when policy rules had the apps that implicitly depended on web browsing configured with the service&amp;nbsp;&lt;A class="term" title="" href="https://bugidsearch.com/PAN-OS.html#" target="_self" data-format="dita" data-scope="" data-type=""&gt;application default&amp;nbsp;&lt;/A&gt;, traffic did not match the rule correctly.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;FONT color="#000000"&gt;===&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;FONT color="#000000"&gt;Even I don't know which version you are using, you should check you are hitting this or not.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;FONT color="#000000"&gt;&lt;SPAN&gt;I can find this bug-id on 10.1.6-h3,&amp;nbsp;10.1.7,10.2.3 release note&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/3296"&gt;@emr_1&lt;/a&gt;&amp;nbsp;-- thank you for this confirmation.&amp;nbsp; I'll be following up with our TAC team today and share the results.&amp;nbsp; Also appreciate the bug info.&amp;nbsp; FYI we're running 11.1.6h19.&lt;/P&gt;</description>
    <pubDate>Mon, 29 Dec 2025 14:32:39 GMT</pubDate>
    <dc:creator>Brandon_Wertz</dc:creator>
    <dc:date>2025-12-29T14:32:39Z</dc:date>
    <item>
      <title>Windows-Remote-Management &amp; Implicit Use of Web-Browsing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/windows-remote-management-amp-implicit-use-of-web-browsing/m-p/1244573#M125752</link>
      <description>&lt;P&gt;I need your help with understanding this.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We've got a rule that was intermittently working.&amp;nbsp; We built a rule around the use of "windows-remote-management" which is using the standard port of 5985/tcp.&amp;nbsp; The rule is a service "application-default" rule.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When we look through the logs we see that some of the traffic that should be matching this rule is not matching this rule and is being denied.&amp;nbsp; It's being denied because "web-browsing" is being seen over port 5985.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I understand that the app-default port for web-browsing is 80/tcp, but given that the App-ID WRM was created to use the standard default port 5985, shouldn't web-browsing which is implicitly allowed on this app-id follow the default port of 5985?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've got an active support case on this topic, and TAC is telling me that is not the way it works, but this just doesn't make sense to me.&amp;nbsp; TAC is saying that eventhough web-browsing is implicitly allowed in the WRM app-id since web-browsing is being seen on the non-standard port of 5985 the traffic should be blocked.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If I build a rule intending to allow only "Windows Remote Management" and this traffic occurs over 5985/tcp shouldn't any other associated traffic also work and be allowed?&amp;nbsp; To me the implicit association of web-browsing with WRM is never going to work, w/o the rule being a service "any" rule.&amp;nbsp; Meaning web-browsing should be a "depends-on" and not an "implicit use" application.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Brandon_Wertz_0-1766598734776.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/70206i352708A37373F389/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Brandon_Wertz_0-1766598734776.png" alt="Brandon_Wertz_0-1766598734776.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Dec 2025 18:00:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/windows-remote-management-amp-implicit-use-of-web-browsing/m-p/1244573#M125752</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2025-12-24T18:00:13Z</dc:date>
    </item>
    <item>
      <title>Re: Windows-Remote-Management &amp; Implicit Use of Web-Browsing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/windows-remote-management-amp-implicit-use-of-web-browsing/m-p/1244616#M125756</link>
      <description>&lt;P&gt;I agree with you, and TAC is wrong.&lt;/P&gt;
&lt;P&gt;If I configured a rule as below:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2025-12-25 15 29 20.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/70215iA546A79341F35E25/image-size/large?v=v2&amp;amp;px=999" role="button" title="2025-12-25 15 29 20.png" alt="2025-12-25 15 29 20.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The rule on the box is recognized as below:&lt;/P&gt;
&lt;P&gt;)&amp;gt; show running security-policy&lt;/P&gt;
&lt;P&gt;"test; index: 1" {&lt;BR /&gt;from any;&lt;BR /&gt;source any;&lt;BR /&gt;source-region none;&lt;BR /&gt;to any;&lt;BR /&gt;destination any;&lt;BR /&gt;destination-region none;&lt;BR /&gt;user any;&lt;BR /&gt;source-device any;&lt;BR /&gt;destination-device any;&lt;BR /&gt;source-advanced-device any;&lt;BR /&gt;destination-advanced-device any;&lt;BR /&gt;category any;&lt;BR /&gt;application/service [0:windows-remote-ma/tcp/any/5985 1:windows-remote-ma/tcp/any/5986 ];&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;application/service(implicit) [0:web-browsing/tcp/any/5985 1:web-browsing/tcp/any/5986 ];&lt;/FONT&gt;&lt;BR /&gt;action allow;&lt;BR /&gt;icmp-unreachable: no&lt;BR /&gt;terminal yes;&lt;BR /&gt;}&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As you know, "&lt;FONT color="#FF0000"&gt;web-browsing/tcp/any/5985"&lt;FONT color="#000000"&gt; is "application/protocol/source-port/dest-port".&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;FONT color="#000000"&gt;By the way, I found issue from release note.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;FONT color="#000000"&gt;===&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;FONT color="#000000"&gt;&lt;STRONG class="ph b"&gt;PAN-194408&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;FONT color="#000000"&gt;Fixed an issue where, when policy rules had the apps that implicitly depended on web browsing configured with the service&amp;nbsp;&lt;A class="term" title="" href="https://bugidsearch.com/PAN-OS.html#" target="_self" data-format="dita" data-scope="" data-type=""&gt;application default&amp;nbsp;&lt;/A&gt;, traffic did not match the rule correctly.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;FONT color="#000000"&gt;===&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;FONT color="#000000"&gt;Even I don't know which version you are using, you should check you are hitting this or not.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;FONT color="#000000"&gt;&lt;SPAN&gt;I can find this bug-id on 10.1.6-h3,&amp;nbsp;10.1.7,10.2.3 release note&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Dec 2025 06:39:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/windows-remote-management-amp-implicit-use-of-web-browsing/m-p/1244616#M125756</guid>
      <dc:creator>emr_1</dc:creator>
      <dc:date>2025-12-25T06:39:04Z</dc:date>
    </item>
    <item>
      <title>Re: Windows-Remote-Management &amp; Implicit Use of Web-Browsing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/windows-remote-management-amp-implicit-use-of-web-browsing/m-p/1244729#M125763</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/3296"&gt;@emr_1&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;I agree with you, and TAC is wrong.&lt;/P&gt;
&lt;P&gt;If I configured a rule as below:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2025-12-25 15 29 20.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/70215iA546A79341F35E25/image-size/large?v=v2&amp;amp;px=999" role="button" title="2025-12-25 15 29 20.png" alt="2025-12-25 15 29 20.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The rule on the box is recognized as below:&lt;/P&gt;
&lt;P&gt;)&amp;gt; show running security-policy&lt;/P&gt;
&lt;P&gt;"test; index: 1" {&lt;BR /&gt;from any;&lt;BR /&gt;source any;&lt;BR /&gt;source-region none;&lt;BR /&gt;to any;&lt;BR /&gt;destination any;&lt;BR /&gt;destination-region none;&lt;BR /&gt;user any;&lt;BR /&gt;source-device any;&lt;BR /&gt;destination-device any;&lt;BR /&gt;source-advanced-device any;&lt;BR /&gt;destination-advanced-device any;&lt;BR /&gt;category any;&lt;BR /&gt;application/service [0:windows-remote-ma/tcp/any/5985 1:windows-remote-ma/tcp/any/5986 ];&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;application/service(implicit) [0:web-browsing/tcp/any/5985 1:web-browsing/tcp/any/5986 ];&lt;/FONT&gt;&lt;BR /&gt;action allow;&lt;BR /&gt;icmp-unreachable: no&lt;BR /&gt;terminal yes;&lt;BR /&gt;}&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As you know, "&lt;FONT color="#FF0000"&gt;web-browsing/tcp/any/5985"&lt;FONT color="#000000"&gt; is "application/protocol/source-port/dest-port".&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;FONT color="#000000"&gt;By the way, I found issue from release note.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;FONT color="#000000"&gt;===&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;FONT color="#000000"&gt;&lt;STRONG class="ph b"&gt;PAN-194408&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;FONT color="#000000"&gt;Fixed an issue where, when policy rules had the apps that implicitly depended on web browsing configured with the service&amp;nbsp;&lt;A class="term" title="" href="https://bugidsearch.com/PAN-OS.html#" target="_self" data-format="dita" data-scope="" data-type=""&gt;application default&amp;nbsp;&lt;/A&gt;, traffic did not match the rule correctly.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;FONT color="#000000"&gt;===&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;FONT color="#000000"&gt;Even I don't know which version you are using, you should check you are hitting this or not.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;FONT color="#000000"&gt;&lt;SPAN&gt;I can find this bug-id on 10.1.6-h3,&amp;nbsp;10.1.7,10.2.3 release note&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/3296"&gt;@emr_1&lt;/a&gt;&amp;nbsp;-- thank you for this confirmation.&amp;nbsp; I'll be following up with our TAC team today and share the results.&amp;nbsp; Also appreciate the bug info.&amp;nbsp; FYI we're running 11.1.6h19.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Dec 2025 14:32:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/windows-remote-management-amp-implicit-use-of-web-browsing/m-p/1244729#M125763</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2025-12-29T14:32:39Z</dc:date>
    </item>
  </channel>
</rss>

