<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Having trouble granting access for an application in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/having-trouble-granting-access-for-an-application/m-p/18460#M13486</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thought I found a solution, but this didn't work either:&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/message/33140"&gt;Adding a Custom Application/Ports to Security Policy&lt;/A&gt;&lt;BR /&gt;&lt;IMG __jive_id="14681" alt="security.PNG" class="image-0 jive-image" height="34" src="https://live.paloaltonetworks.com/legacyfs/online/14681_security.PNG" style="height: 33.770967741935486px; width: 722px;" width="722" /&gt;&lt;/P&gt;&lt;P&gt;Added the services without the RDP at first, noticing the connection was terminated, and was re-established when I added it. So there must be something I'm missing in regards to the other ports.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 25 Jul 2014 12:30:52 GMT</pubDate>
    <dc:creator>pasmartin</dc:creator>
    <dc:date>2014-07-25T12:30:52Z</dc:date>
    <item>
      <title>Having trouble granting access for an application</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/having-trouble-granting-access-for-an-application/m-p/18459#M13485</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One of our customers have RDP access to a server, works like a charm. &lt;/P&gt;&lt;P&gt;And now I was about to grant access to an application using port 4850 and 4851, but it would seem that this wouldn't be that simple.&lt;/P&gt;&lt;P&gt;I've attached the NAT of the working RDP, and the non-working OPC application:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="nat.PNG" class="image-0 jive-image" height="106" src="https://live.paloaltonetworks.com/legacyfs/online/14680_nat.PNG" style="height: 106px; width: 1113.8983050847457px;" width="1114" /&gt;&lt;/P&gt;&lt;P&gt;(I've also added the newly created application to the existing Security rule that allows RDP.)&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I want to add that the newly created application has not been given any signatures - only properties, characteristics, timeouts and the ports itself. But even if the application somehow is "wrongly" created, at least the ports should be registered open?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone have any clue as to what I might have forgotten, or rather have done wrong?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'll provide more information if needed.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Jul 2014 11:50:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/having-trouble-granting-access-for-an-application/m-p/18459#M13485</guid>
      <dc:creator>pasmartin</dc:creator>
      <dc:date>2014-07-25T11:50:55Z</dc:date>
    </item>
    <item>
      <title>Re: Having trouble granting access for an application</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/having-trouble-granting-access-for-an-application/m-p/18460#M13486</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thought I found a solution, but this didn't work either:&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/message/33140"&gt;Adding a Custom Application/Ports to Security Policy&lt;/A&gt;&lt;BR /&gt;&lt;IMG __jive_id="14681" alt="security.PNG" class="image-0 jive-image" height="34" src="https://live.paloaltonetworks.com/legacyfs/online/14681_security.PNG" style="height: 33.770967741935486px; width: 722px;" width="722" /&gt;&lt;/P&gt;&lt;P&gt;Added the services without the RDP at first, noticing the connection was terminated, and was re-established when I added it. So there must be something I'm missing in regards to the other ports.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Jul 2014 12:30:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/having-trouble-granting-access-for-an-application/m-p/18460#M13486</guid>
      <dc:creator>pasmartin</dc:creator>
      <dc:date>2014-07-25T12:30:52Z</dc:date>
    </item>
    <item>
      <title>Re: Having trouble granting access for an application</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/having-trouble-granting-access-for-an-application/m-p/18461#M13487</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Create an "Application Override" policy for your new application for traffic destined to the server's IP and port....&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Jul 2014 13:34:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/having-trouble-granting-access-for-an-application/m-p/18461#M13487</guid>
      <dc:creator>ajbool</dc:creator>
      <dc:date>2014-07-25T13:34:15Z</dc:date>
    </item>
    <item>
      <title>Re: Having trouble granting access for an application</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/having-trouble-granting-access-for-an-application/m-p/18462#M13488</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Pred-martin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-size: 10pt; font-family: inherit;"&gt;(1) Could you please check, if there is any session available on the PAN firewall, Use CLI by using '&lt;STRONG&gt;&amp;gt;show session all filter &lt;/STRONG&gt;&lt;/SPAN&gt;&lt;STRONG style="font-size: 10pt; font-style: inherit; font-family: inherit;"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;source&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-size: 10pt; font-family: inherit;"&gt;&lt;STRONG&gt; IP_ADD_OF_THE_TESTING_PC destination IP_ADD_OF_THE_DESTINATION'. ( Collect the session ID)&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-size: 10pt; font-family: inherit;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-size: 10pt; font-family: inherit;"&gt;(2) If there is &lt;SPAN class="GINGER_SOFTWARE_mark" style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;a&lt;/SPAN&gt; session exist for the same traffic,&amp;nbsp; then please &lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;apply&amp;nbsp; CLI command PAN&amp;gt; show session id XYZ&amp;nbsp;&amp;nbsp; &amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; to get detailed information about that session, &lt;/SPAN&gt;&lt;SPAN class="GINGER_SOFTWARE_mark" style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark" style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;i.e Application, port,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt; NAT rule, security rule, ingress/egress interface etc.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;(3)&amp;nbsp;&amp;nbsp; &lt;SPAN class="GINGER_SOFTWARE_mark" style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;verify&lt;/SPAN&gt;&lt;/SPAN&gt; the global counters, if a specific "DRP" counter is increasing rapidly. &lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;- Create a packet filter under GUI &amp;gt; Monitor &amp;gt; Packet capture&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;-Apply below mentioned command multiple times, while &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;try&lt;/SPAN&gt; to establish the RDP connection. ( &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;with&lt;/SPAN&gt; 2 &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;seconds&lt;/SPAN&gt; interval)&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;STRONG&gt;&amp;gt; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;show&lt;/SPAN&gt; counter global filter packet-filter yes delta yes&lt;/STRONG&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;The command &lt;/SPAN&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: 'courier new', courier;"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark" style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;show&lt;/SPAN&gt;&lt;/SPAN&gt; counter global&lt;/SPAN&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt; provides information about the processes/actions taken on the packets going through the device; if they are dropped, &lt;SPAN class="GINGER_SOFTWARE_mark" style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;nat&lt;/SPAN&gt;&lt;/SPAN&gt;-&lt;SPAN class="GINGER_SOFTWARE_mark" style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;ed&lt;/SPAN&gt;&lt;/SPAN&gt;, decrypted etc.&amp;nbsp; These counters are for all the traffic going through the device and are useful in troubleshooting issues; like packet loss. It is advised to use the command &lt;/SPAN&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: 'courier new', courier;"&gt;show counter global filter packet-filter yes delta yes&lt;/SPAN&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt; in conjunction with filters to obtain meaningful data.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;For more information, you can follow the DOC &lt;A _jive_internal="true" data-containerid="2027" data-containertype="14" data-objectid="4650" data-objecttype="102" href="https://live.paloaltonetworks.com/docs/DOC-4650" style="font-weight: inherit; font-style: inherit; font-family: inherit; color: #006595;"&gt;What is the Significance of Global Counters?&lt;/A&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;(4) Could you please share the custom service details ( snapshot) for OPC-UA-4850, &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;OPC-UA-4851, RDP-3390.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Hope this helps.&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Jul 2014 15:39:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/having-trouble-granting-access-for-an-application/m-p/18462#M13488</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-07-25T15:39:54Z</dc:date>
    </item>
    <item>
      <title>Re: Having trouble granting access for an application</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/having-trouble-granting-access-for-an-application/m-p/18463#M13489</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry for my delayed response to your help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried the Application Override, to no avail. I also conferred with a "local" support, who claimed everything looked like it should be. &lt;BR /&gt;As for your "CLI option", HULK, I didn't get any results. Don't know whether that was due to wrong input or something else, b&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;ut I couldn't use more time on the issue, so I just added the external IP to the server in question, which solved everything. Guess I must have missed a detail in regards to the NAT-ing(?!), but the question is what. The setup was indentical to the working RDP.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks anyway &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Jul 2014 08:50:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/having-trouble-granting-access-for-an-application/m-p/18463#M13489</guid>
      <dc:creator>pasmartin</dc:creator>
      <dc:date>2014-07-31T08:50:03Z</dc:date>
    </item>
  </channel>
</rss>

