<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Custom APP based on existing in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/custom-app-based-on-existing/m-p/19502#M14234</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think Application override is not the right approach as I don't have particular destibnation ip or source ip. It is really a news app based on existing one.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if I use web-browsing as Parent app it means that all traffic from the site will be classified as custom application, my intend was to recognize as custom application only phpproxy traffic type.&lt;/P&gt;&lt;P&gt;Anyway I don't understand why if I definine phpproxy app as parent the web-browsing traffic is recognized by the custom app.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;suggestion ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 29 Jul 2013 08:13:21 GMT</pubDate>
    <dc:creator>helenio.sartori</dc:creator>
    <dc:date>2013-07-29T08:13:21Z</dc:date>
    <item>
      <title>Custom APP based on existing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-app-based-on-existing/m-p/19499#M14231</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;BR /&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a policy that block phpproxy application for security reason.&lt;/P&gt;&lt;P&gt;There is a web site &lt;A href="http://www.sac-cas.ch/"&gt;http://www.sac-cas.ch&lt;/A&gt; (shop tab) is blocked because some request are recognised as phpproxy application.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'd like to build an application that allow phpproxy when host is &lt;A href="http://www.sac-cas.ch/"&gt;www.sac-cas.ch&lt;/A&gt; in a way to bypass the block.&lt;/P&gt;&lt;P&gt;Here below the custom application&amp;nbsp; I created for this purposed.&lt;/P&gt;&lt;P&gt;Basically the application has as parent app phpproxy and signature match host &lt;A class="active_link" href="http://www.sac-cas.ch/"&gt;www.sac-cas.ch&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't know why but it seams that this customer application in recognized not only when application is phpproxy but eve if the traffic i web browsing. Where I'm doing wrong ? It somethong related to App dependencies ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="CAS1.png" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/7442_CAS1.png" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="CAS2.png" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/7443_CAS2.png" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="CAS3.png" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/7444_CAS3.png" width="450" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Jul 2013 09:18:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-app-based-on-existing/m-p/19499#M14231</guid>
      <dc:creator>helenio.sartori</dc:creator>
      <dc:date>2013-07-26T09:18:42Z</dc:date>
    </item>
    <item>
      <title>Re: Custom APP based on existing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-app-based-on-existing/m-p/19500#M14232</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello, you need to setup 'Application Override policy' to allow custom application get identified.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="App Override.PNG" class="jive-image-thumbnail jive-image" height="201" src="https://live.paloaltonetworks.com/legacyfs/online/7451_App Override.PNG" style="width: 747.5206611570247px; height: 201px;" width="748" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;SPAN style="text-decoration: underline;"&gt;Also make sure to add custom application in the security policy to allow traffic&lt;/SPAN&gt;.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unnati&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Jul 2013 19:09:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-app-based-on-existing/m-p/19500#M14232</guid>
      <dc:creator>ukhapre</dc:creator>
      <dc:date>2013-07-26T19:09:48Z</dc:date>
    </item>
    <item>
      <title>Re: Custom APP based on existing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-app-based-on-existing/m-p/19501#M14233</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As php-proxy in turn&amp;nbsp; depends web-browsing try using Parent App as Web-browsing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Reasoning : &lt;/STRONG&gt;The App-ID engine processes applications in a hierarchy that looks for web-browsing, then web-based applications such as php-proxy and then custom http applications. &lt;/P&gt;&lt;P&gt;By choosing web-browsing ,an application that is lower in the hierarchy, the PAN-OS&amp;nbsp; is forced to recognize and react to that traffic earlier than it normally would for a custom http application.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Jul 2013 21:44:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-app-based-on-existing/m-p/19501#M14233</guid>
      <dc:creator>UhMayYeah</dc:creator>
      <dc:date>2013-07-26T21:44:15Z</dc:date>
    </item>
    <item>
      <title>Re: Custom APP based on existing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-app-based-on-existing/m-p/19502#M14234</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think Application override is not the right approach as I don't have particular destibnation ip or source ip. It is really a news app based on existing one.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if I use web-browsing as Parent app it means that all traffic from the site will be classified as custom application, my intend was to recognize as custom application only phpproxy traffic type.&lt;/P&gt;&lt;P&gt;Anyway I don't understand why if I definine phpproxy app as parent the web-browsing traffic is recognized by the custom app.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;suggestion ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Jul 2013 08:13:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-app-based-on-existing/m-p/19502#M14234</guid>
      <dc:creator>helenio.sartori</dc:creator>
      <dc:date>2013-07-29T08:13:21Z</dc:date>
    </item>
    <item>
      <title>Re: Custom APP based on existing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-app-based-on-existing/m-p/19503#M14235</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry to bump this after so long but what I wanted to do is relevant.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I wanted to just change ports on an existing app without having to use 'Any' or have to list all ports for the application and it's dependencies.&amp;nbsp; I was hoping to create a custom app with the original app as the parent and just list the port it would use. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I believe the Application Override suggestion above would be needed.&amp;nbsp; From reading the documentation, you have to include a signature in the custom app.&amp;nbsp; The only time you do not is if you're using it in an Application Override policy.&amp;nbsp; That's kinda a bummer.&amp;nbsp; Thought I'd get off easy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I'm hoping is that I can build a custom app with the built-in app as the parent, create an Application Override just for that new app and in the security policy add the built in app &amp;amp; the custom app.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've seen custom apps built without signatures and they always end up including all the ports from the original app, an Application Override created and the original app then not used.&amp;nbsp; This seems to be no different than just creating a Service Object because signatures are no longer used; just ports.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is where being able to clone a built in app would be helpful.&amp;nbsp; :smileylaugh:&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Mar 2015 00:50:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-app-based-on-existing/m-p/19503#M14235</guid>
      <dc:creator>CafNetMatt</dc:creator>
      <dc:date>2015-03-19T00:50:43Z</dc:date>
    </item>
  </channel>
</rss>

