<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: dependency warning - how to force it? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/dependency-warning-how-to-force-it/m-p/19398#M14169</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, Slawek&lt;/P&gt;&lt;P&gt;For a clean configuration without any warning messages, you would have to add the applications that the PANFW is complaining about.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Karthik&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 25 Jun 2013 13:22:04 GMT</pubDate>
    <dc:creator>kprakash</dc:creator>
    <dc:date>2013-06-25T13:22:04Z</dc:date>
    <item>
      <title>dependency warning - how to force it?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dependency-warning-how-to-force-it/m-p/19394#M14165</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm bit confused about dependency ...&lt;/P&gt;&lt;P&gt;During commit i have:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; vsys1: Rule 'XXXXXXXXXXX' application dependency warning:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Application 'gmail-base' requires 'imap' be allowed, but 'imap' is denied in Rule 'Scholastycy - deny rest'&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Application 'gmail-base' requires 'pop3' be allowed, but 'pop3' is denied in Rule 'Scholastycy - deny rest'&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Application 'gmail-base' requires 'smtp' be allowed, but 'smtp' is denied in Rule 'Scholastycy - deny rest'&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; vsys1: Rule 'YYYYYYYY' application dependency warning:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Application 'msrpc' requires 'ms-ds-smb' be allowed &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Application 'msrpc' requires 'netbios-ss' be allowed &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Application 'msrpc' requires 'ms-ds-smb' be allowed &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Application 'msrpc' requires 'netbios-ss' be allowed &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Both of this rules are working as expected. XXXXXXX allowing sending email from multifunction printer. I'm sure that imap/pop3 isn't nessesary for sending emails.&lt;/P&gt;&lt;P&gt;The YYYYYYY has aplication: ms-kms. ms-rdp, msrpc and t.120 and this is enought for RDP and activating Office 2010&amp;nbsp; and Windows 7.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do I'm able to stop complaining about it during commit?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Jun 2013 12:19:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dependency-warning-how-to-force-it/m-p/19394#M14165</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2013-06-25T12:19:24Z</dc:date>
    </item>
    <item>
      <title>Re: dependency warning - how to force it?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dependency-warning-how-to-force-it/m-p/19395#M14166</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Are the PANFWs still in 4.1.x versions? Most of the dependency warning messages are gone under the 5.0.x PANOS versions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can also find a mention about it under the release notes of 5.0.0:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;APPLICATION IDENTIFICATION FEATURES&lt;/P&gt;&lt;P&gt;• Application Dependency Enhancement – For some protocols, you can allow an application in security policy without explicitly allowing its underlying protocol. This support is available if the application can be identified within a pre-determined point in &lt;/P&gt;&lt;P&gt;the session, and has a dependency on any of the following applications: HTTP, SSL, MSRPC, RPC, t.120, RTSP, RTMP, and NETBIOS-SS. Custom applications based on HTTP, SSL, MS-RPC, or RTSP can also be allowed in security policy without explicitly allowing the underlying protocol. For example, if you want to allow Java software updates, which use HTTP (web-browsing), you no longer have to allow web-browsing. This feature will reduce the overall number of rules needed to manage policies.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;Usually these warnings advise the administrator there is an application configured on a policy that may not function fully because another application (or applications) is needed. For example, if you enable the “facebook-base” application on a policy by itself, you may get an application dependency warning advising that “web-browsing” is required.&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;These application dependency warnings are derived from the research of the Palo Alto Networks development team responsible for content. The intent of these warnings is to aid the administrator in properly configuring policies, and avoid any inconsistent behavior by the application.&amp;nbsp; It is important to understand these are just warnings and not errors that will fail your commit.&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;The below document explains the causes for getting the dependency warning messages:&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;A _jive_internal="true" class="active_link" href="https://live.paloaltonetworks.com/docs/DOC-1654"&gt;https://live.paloaltonetworks.com/docs/DOC-1654&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Jun 2013 12:44:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dependency-warning-how-to-force-it/m-p/19395#M14166</guid>
      <dc:creator>kprakash</dc:creator>
      <dc:date>2013-06-25T12:44:52Z</dc:date>
    </item>
    <item>
      <title>Re: dependency warning - how to force it?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dependency-warning-how-to-force-it/m-p/19396#M14167</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Also found this in our forums that:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;The dependencies are only open for the amount of packets needed in order to detect the main application.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;For example where you previously was forced to have both appx and web-browsing open forever you now only add appx and the web-browsing will only be allowed for the amount of packets needed to detect appx, if appx is not detected after this amount then the web-browsing session is denied.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Jun 2013 13:06:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dependency-warning-how-to-force-it/m-p/19396#M14167</guid>
      <dc:creator>kprakash</dc:creator>
      <dc:date>2013-06-25T13:06:52Z</dc:date>
    </item>
    <item>
      <title>Re: dependency warning - how to force it?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dependency-warning-how-to-force-it/m-p/19397#M14168</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm using 5.0.5 PAN, warnings related to gmail comes after some automatic update (not after upgrade from 5.0.3 to 5.0.5 in my example).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As I understand this is feature and it can't be switched off - I have to get used to or add such aplication to the rules - Do I'm a right?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Slawek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Jun 2013 13:07:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dependency-warning-how-to-force-it/m-p/19397#M14168</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2013-06-25T13:07:11Z</dc:date>
    </item>
    <item>
      <title>Re: dependency warning - how to force it?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dependency-warning-how-to-force-it/m-p/19398#M14169</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, Slawek&lt;/P&gt;&lt;P&gt;For a clean configuration without any warning messages, you would have to add the applications that the PANFW is complaining about.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Karthik&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Jun 2013 13:22:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dependency-warning-how-to-force-it/m-p/19398#M14169</guid>
      <dc:creator>kprakash</dc:creator>
      <dc:date>2013-06-25T13:22:04Z</dc:date>
    </item>
  </channel>
</rss>

