<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Webbrowsing on non-standard http ports.... in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/webbrowsing-on-non-standard-http-ports/m-p/19646#M14347</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What is the best way for me to implement a rule that allows http traffic over non standard ports?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Our security standards require that we use a feature similar to what is available in Checkpoint that allows us to lock the port down based on protocol. Ex: port 55000 is open and allowed assuming the traffic is http or https.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be appreciated.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 28 Aug 2013 20:56:29 GMT</pubDate>
    <dc:creator>smccall</dc:creator>
    <dc:date>2013-08-28T20:56:29Z</dc:date>
    <item>
      <title>Webbrowsing on non-standard http ports....</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/webbrowsing-on-non-standard-http-ports/m-p/19646#M14347</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What is the best way for me to implement a rule that allows http traffic over non standard ports?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Our security standards require that we use a feature similar to what is available in Checkpoint that allows us to lock the port down based on protocol. Ex: port 55000 is open and allowed assuming the traffic is http or https.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be appreciated.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Aug 2013 20:56:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/webbrowsing-on-non-standard-http-ports/m-p/19646#M14347</guid>
      <dc:creator>smccall</dc:creator>
      <dc:date>2013-08-28T20:56:29Z</dc:date>
    </item>
    <item>
      <title>Re: Webbrowsing on non-standard http ports....</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/webbrowsing-on-non-standard-http-ports/m-p/19647#M14348</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When creating security rules, in the Application section configure: Web Browsing but in the Service section refer to the ports you are interested in allowing.&lt;/P&gt;&lt;P&gt;You may have to create a custom service and allow these non standard ports and then call that custom service in the security rule (where it says service). That way when traffic is checked against the security rule, you'd have web browsing AND the port (allowed via service) and only if the two web browsing on that non standard port match, will the traffic be allowed&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So e.g.&amp;nbsp; your service would look like&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="services.PNG.png" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/7979_services.PNG.png" style="width: 620px; height: 65px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Where service-http goes to 80 and 8080&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and the security policy would be:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="security.PNG.png" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/7980_security.PNG.png" style="width: 620px; height: 9px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Aug 2013 21:22:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/webbrowsing-on-non-standard-http-ports/m-p/19647#M14348</guid>
      <dc:creator>sjamaluddin</dc:creator>
      <dc:date>2013-08-28T21:22:08Z</dc:date>
    </item>
    <item>
      <title>Re: Webbrowsing on non-standard http ports....</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/webbrowsing-on-non-standard-http-ports/m-p/19648#M14349</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would suggest you to set the application as any and service port as the non-standard port that you use. Once the traffic traverses the firewall the application would show up and then you can modify the rule to incorporate it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Aug 2013 21:23:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/webbrowsing-on-non-standard-http-ports/m-p/19648#M14349</guid>
      <dc:creator>sraghunandan</dc:creator>
      <dc:date>2013-08-28T21:23:21Z</dc:date>
    </item>
    <item>
      <title>Re: Webbrowsing on non-standard http ports....</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/webbrowsing-on-non-standard-http-ports/m-p/19649#M14350</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I goofed around a bit and figured this was the way to do it, but thank you very much for the response.&lt;/P&gt;&lt;P&gt;Nice to have someone confirm my thoughts.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Aug 2013 14:21:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/webbrowsing-on-non-standard-http-ports/m-p/19649#M14350</guid>
      <dc:creator>smccall</dc:creator>
      <dc:date>2013-08-29T14:21:23Z</dc:date>
    </item>
  </channel>
</rss>

