<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Looking for advice on App-id configuration in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/looking-for-advice-on-app-id-configuration/m-p/20834#M15214</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Looking through the white papers and documentation, I didn't really find much as to a recommendation on how to tackle the task of app-id configuration as a whole. Have any of you found any documentation that was helpful in this area? &lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;One approach I was considering was running a report to identify the most widely used applications within our organization and initially focusing on those that need to be addressed right away. But I can only imagine that eventually a decision point will have to be made on every app-id and future additions PA decides to make. I was also thinking I almost need to create some type of matrix that identifies all of the standardized applications App-id addresses along with all the controls and a decision point on if that control is turned on or not. What approach did you and your organization use to tackle App-id configuration? Rather than re-inventing the wheel, I thought I would ask for advice from my peers that have already gone through this process.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 04 Jun 2013 16:44:27 GMT</pubDate>
    <dc:creator>jbabcockii</dc:creator>
    <dc:date>2013-06-04T16:44:27Z</dc:date>
    <item>
      <title>Looking for advice on App-id configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/looking-for-advice-on-app-id-configuration/m-p/20834#M15214</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Looking through the white papers and documentation, I didn't really find much as to a recommendation on how to tackle the task of app-id configuration as a whole. Have any of you found any documentation that was helpful in this area? &lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;One approach I was considering was running a report to identify the most widely used applications within our organization and initially focusing on those that need to be addressed right away. But I can only imagine that eventually a decision point will have to be made on every app-id and future additions PA decides to make. I was also thinking I almost need to create some type of matrix that identifies all of the standardized applications App-id addresses along with all the controls and a decision point on if that control is turned on or not. What approach did you and your organization use to tackle App-id configuration? Rather than re-inventing the wheel, I thought I would ask for advice from my peers that have already gone through this process.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Jun 2013 16:44:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/looking-for-advice-on-app-id-configuration/m-p/20834#M15214</guid>
      <dc:creator>jbabcockii</dc:creator>
      <dc:date>2013-06-04T16:44:27Z</dc:date>
    </item>
    <item>
      <title>Re: Looking for advice on App-id configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/looking-for-advice-on-app-id-configuration/m-p/20835#M15215</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Starting from ACC will be good way to construct a secure way.&lt;/P&gt;&lt;P&gt;If you can do best is "positive security" model as you know.That is not possible for every environment but a best practice for me.&lt;/P&gt;&lt;P&gt;Over an implicity deny, only allow what app you need.And for policy rules , service option - application default.&lt;/P&gt;&lt;P&gt;This will take some time, but after then most secure.&lt;/P&gt;&lt;P&gt;Alternatively, if you can't do that, you should use app. filters by category and also it is a dynamic solution.&lt;/P&gt;&lt;P&gt;After that you should add any harmful apps to a group and write a deny rule for both.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Jun 2013 17:38:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/looking-for-advice-on-app-id-configuration/m-p/20835#M15215</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-06-04T17:38:05Z</dc:date>
    </item>
  </channel>
</rss>

