<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Avaya ports Blocking in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/avaya-ports-blocking/m-p/1249550#M126105</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="x_elementToProof" data-olk-copy-source="MessageBody"&gt;We recently installed&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Avaya UCS&lt;/STRONG&gt;&amp;nbsp;and are currently using the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Avaya Workplace&lt;/STRONG&gt;&amp;nbsp;application. For this setup, we configured the required security rules on our&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Palo Alto Networks PA-440 firewall&lt;/STRONG&gt;. However, we are experiencing an issue when applying specific ports in the security policy.&lt;/DIV&gt;
&lt;DIV class="x_elementToProof"&gt;We tested the following scenarios:&lt;/DIV&gt;
&lt;OL start="1" data-start="409" data-end="1247"&gt;
&lt;LI&gt;
&lt;DIV class="x_elementToProof" role="presentation"&gt;&lt;STRONG&gt;Security Rule Configuration&lt;/STRONG&gt;&lt;/DIV&gt;
&lt;/LI&gt;
&lt;UL data-start="449" data-end="688"&gt;
&lt;LI&gt;
&lt;DIV class="x_elementToProof" role="presentation"&gt;When the rule is configured with&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Application: application-default&lt;/STRONG&gt;&amp;nbsp;and&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Service: Any&lt;/STRONG&gt;, the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Avaya Workplace&lt;/STRONG&gt;&amp;nbsp;application works correctly.&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV class="x_elementToProof" role="presentation"&gt;However, when we specify ports in the service section, the application stops working.&lt;/DIV&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;LI&gt;
&lt;DIV class="x_elementToProof" role="presentation"&gt;&lt;STRONG&gt;Application-Based Rule&lt;/STRONG&gt;&lt;BR /&gt;We selected the following applications:&lt;/DIV&gt;
&lt;DIV class="x_elementToProof" role="presentation"&gt;Despite this, the application still does not work.&lt;/DIV&gt;
&lt;/LI&gt;
&lt;UL data-start="768" data-end="891"&gt;
&lt;LI&gt;
&lt;DIV class="x_elementToProof" role="presentation"&gt;avaya-phone-ring&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV class="x_elementToProof" role="presentation"&gt;avaya-webalive&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV class="x_elementToProof" role="presentation"&gt;avaya-weblive-voice&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV class="x_elementToProof" role="presentation"&gt;rtmp&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV class="x_elementToProof" role="presentation"&gt;sip&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV class="x_elementToProof" role="presentation"&gt;ssl&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV class="x_elementToProof" role="presentation"&gt;web-browsing&lt;/DIV&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;LI&gt;
&lt;DIV class="x_elementToProof" role="presentation"&gt;&lt;STRONG&gt;Service-Based Rule&lt;/STRONG&gt;&lt;BR /&gt;We also tried allowing the following ports/services:&lt;/DIV&gt;
&lt;DIV class="x_elementToProof" role="presentation"&gt;Even with these ports allowed, the application is still not functioning.&lt;/DIV&gt;
&lt;/LI&gt;
&lt;UL data-start="1035" data-end="1170"&gt;
&lt;LI&gt;
&lt;DIV class="x_elementToProof" role="presentation"&gt;5060/tcp&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV class="x_elementToProof" role="presentation"&gt;5060/udp&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV class="x_elementToProof" role="presentation"&gt;5061/tcp&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV class="x_elementToProof" role="presentation"&gt;16384–32767/tcp&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV class="x_elementToProof" role="presentation"&gt;16384–32767/udp&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV class="x_elementToProof" role="presentation"&gt;3389/tcp&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV class="x_elementToProof" role="presentation"&gt;80/tcp&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV class="x_elementToProof" role="presentation"&gt;443/tcp&lt;/DIV&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/OL&gt;
&lt;DIV class="x_elementToProof"&gt;Could you please advise on the correct&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;application and port requirements&lt;/STRONG&gt;&amp;nbsp;for the Avaya Workplace application.&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Satheesh&lt;/P&gt;</description>
    <pubDate>Thu, 05 Mar 2026 16:03:12 GMT</pubDate>
    <dc:creator>SatheeshAnirudhan</dc:creator>
    <dc:date>2026-03-05T16:03:12Z</dc:date>
    <item>
      <title>Avaya ports Blocking</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/avaya-ports-blocking/m-p/1249550#M126105</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="x_elementToProof" data-olk-copy-source="MessageBody"&gt;We recently installed&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Avaya UCS&lt;/STRONG&gt;&amp;nbsp;and are currently using the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Avaya Workplace&lt;/STRONG&gt;&amp;nbsp;application. For this setup, we configured the required security rules on our&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Palo Alto Networks PA-440 firewall&lt;/STRONG&gt;. However, we are experiencing an issue when applying specific ports in the security policy.&lt;/DIV&gt;
&lt;DIV class="x_elementToProof"&gt;We tested the following scenarios:&lt;/DIV&gt;
&lt;OL start="1" data-start="409" data-end="1247"&gt;
&lt;LI&gt;
&lt;DIV class="x_elementToProof" role="presentation"&gt;&lt;STRONG&gt;Security Rule Configuration&lt;/STRONG&gt;&lt;/DIV&gt;
&lt;/LI&gt;
&lt;UL data-start="449" data-end="688"&gt;
&lt;LI&gt;
&lt;DIV class="x_elementToProof" role="presentation"&gt;When the rule is configured with&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Application: application-default&lt;/STRONG&gt;&amp;nbsp;and&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Service: Any&lt;/STRONG&gt;, the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Avaya Workplace&lt;/STRONG&gt;&amp;nbsp;application works correctly.&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV class="x_elementToProof" role="presentation"&gt;However, when we specify ports in the service section, the application stops working.&lt;/DIV&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;LI&gt;
&lt;DIV class="x_elementToProof" role="presentation"&gt;&lt;STRONG&gt;Application-Based Rule&lt;/STRONG&gt;&lt;BR /&gt;We selected the following applications:&lt;/DIV&gt;
&lt;DIV class="x_elementToProof" role="presentation"&gt;Despite this, the application still does not work.&lt;/DIV&gt;
&lt;/LI&gt;
&lt;UL data-start="768" data-end="891"&gt;
&lt;LI&gt;
&lt;DIV class="x_elementToProof" role="presentation"&gt;avaya-phone-ring&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV class="x_elementToProof" role="presentation"&gt;avaya-webalive&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV class="x_elementToProof" role="presentation"&gt;avaya-weblive-voice&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV class="x_elementToProof" role="presentation"&gt;rtmp&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV class="x_elementToProof" role="presentation"&gt;sip&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV class="x_elementToProof" role="presentation"&gt;ssl&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV class="x_elementToProof" role="presentation"&gt;web-browsing&lt;/DIV&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;LI&gt;
&lt;DIV class="x_elementToProof" role="presentation"&gt;&lt;STRONG&gt;Service-Based Rule&lt;/STRONG&gt;&lt;BR /&gt;We also tried allowing the following ports/services:&lt;/DIV&gt;
&lt;DIV class="x_elementToProof" role="presentation"&gt;Even with these ports allowed, the application is still not functioning.&lt;/DIV&gt;
&lt;/LI&gt;
&lt;UL data-start="1035" data-end="1170"&gt;
&lt;LI&gt;
&lt;DIV class="x_elementToProof" role="presentation"&gt;5060/tcp&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV class="x_elementToProof" role="presentation"&gt;5060/udp&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV class="x_elementToProof" role="presentation"&gt;5061/tcp&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV class="x_elementToProof" role="presentation"&gt;16384–32767/tcp&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV class="x_elementToProof" role="presentation"&gt;16384–32767/udp&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV class="x_elementToProof" role="presentation"&gt;3389/tcp&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV class="x_elementToProof" role="presentation"&gt;80/tcp&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV class="x_elementToProof" role="presentation"&gt;443/tcp&lt;/DIV&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/OL&gt;
&lt;DIV class="x_elementToProof"&gt;Could you please advise on the correct&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;application and port requirements&lt;/STRONG&gt;&amp;nbsp;for the Avaya Workplace application.&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Satheesh&lt;/P&gt;</description>
      <pubDate>Thu, 05 Mar 2026 16:03:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/avaya-ports-blocking/m-p/1249550#M126105</guid>
      <dc:creator>SatheeshAnirudhan</dc:creator>
      <dc:date>2026-03-05T16:03:12Z</dc:date>
    </item>
    <item>
      <title>Re: Avaya ports Blocking</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/avaya-ports-blocking/m-p/1249553#M126107</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/230423"&gt;@SatheeshAnirudhan&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kudos to you for trying L7 rules!&amp;nbsp; That is the best practice.&amp;nbsp; As you have found, this can be very challenging.&amp;nbsp; The process that has worked very well for me is as follows:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Create an application-based rule with application-default as the service.&amp;nbsp; This rule is your rule #2.&lt;/LI&gt;
&lt;LI&gt;Create an application-based rule with specific ports as the service because you cannot combine application-default and specific ports in the same rule.&amp;nbsp; This rule is used for applications that use non-standard ports.&lt;/LI&gt;
&lt;LI&gt;Create a catch-all rule to find anything that I missed.&amp;nbsp; This rule is your rule #1.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;I put these 3 rules in order in the security policy.&amp;nbsp; The catch-all rule is used to identify the traffic that doesn't match the 1st 2 rules.&amp;nbsp; You can (1) mouse over the catch-all rule and use Log Viewer or you can use (2) Apps Seen column hyperlink to the Policy Optimizer to determine which traffic is not hitting the 1st 2 rules.&amp;nbsp; You modify rule 1 or 2 to include the new apps.&amp;nbsp; Repeat the process until you do not have any more hits on rule 3.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Thu, 05 Mar 2026 17:21:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/avaya-ports-blocking/m-p/1249553#M126107</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2026-03-05T17:21:55Z</dc:date>
    </item>
  </channel>
</rss>

