<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Restricting Application Port in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/restricting-application-port/m-p/24376#M17770</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would like to create a custom App for SMTP submission. All I really want to do is restrict the "smtp" App to use 587/tcp only. It's usual "default ports" action is to allow 25/tcp or 587/tcp.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I just tried to create a Custom App based on "smtp," but have the only default port be "tcp/587." As I seemed to vaguely recall the other times I've tried to do this, without a signature section, the App does not match anything. SMTP traffic still matches "smtp," not my App.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sure, I can create a whole new policy rule in the rule base with "smtp" as the application and a "submission" service on 587/tcp, but it would be a lot easier and more manageable to just drop a custom application into an existing application group.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a way to create a custom App to change the default port behavior of a built-in App? (Note that this is not an Application Override thing. (Right?) I still want the PAN to do it's App ID voodoo, just change the default ports allowed.)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 28 Jun 2013 18:13:02 GMT</pubDate>
    <dc:creator>cosx</dc:creator>
    <dc:date>2013-06-28T18:13:02Z</dc:date>
    <item>
      <title>Restricting Application Port</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/restricting-application-port/m-p/24376#M17770</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would like to create a custom App for SMTP submission. All I really want to do is restrict the "smtp" App to use 587/tcp only. It's usual "default ports" action is to allow 25/tcp or 587/tcp.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I just tried to create a Custom App based on "smtp," but have the only default port be "tcp/587." As I seemed to vaguely recall the other times I've tried to do this, without a signature section, the App does not match anything. SMTP traffic still matches "smtp," not my App.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sure, I can create a whole new policy rule in the rule base with "smtp" as the application and a "submission" service on 587/tcp, but it would be a lot easier and more manageable to just drop a custom application into an existing application group.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a way to create a custom App to change the default port behavior of a built-in App? (Note that this is not an Application Override thing. (Right?) I still want the PAN to do it's App ID voodoo, just change the default ports allowed.)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Jun 2013 18:13:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/restricting-application-port/m-p/24376#M17770</guid>
      <dc:creator>cosx</dc:creator>
      <dc:date>2013-06-28T18:13:02Z</dc:date>
    </item>
    <item>
      <title>Re: Restricting Application Port</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/restricting-application-port/m-p/24377#M17771</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you do not want to stop layer 7 processing then you can just create a security rule with SMTP allowed in it and specify the ports that you need in the service.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That way Palo Alto will detect SMTP based on layer 7 data but will only restrict the Application to be allowed when using the ports specified by you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;****Custom app without signature will work only if you override traffic on the expected port to your Customized APP.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Jun 2013 18:20:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/restricting-application-port/m-p/24377#M17771</guid>
      <dc:creator>Chatri</dc:creator>
      <dc:date>2013-06-28T18:20:38Z</dc:date>
    </item>
    <item>
      <title>Re: Restricting Application Port</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/restricting-application-port/m-p/24378#M17772</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I recently did something similar to this.&amp;nbsp; Since the appliance will detect all applications regardless of the port they are running on you can make a custom service object.&amp;nbsp; Instead of using Application Default with allows both 25 and 587, choose your custom service for just 587.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 01 Jul 2013 19:11:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/restricting-application-port/m-p/24378#M17772</guid>
      <dc:creator>nthen</dc:creator>
      <dc:date>2013-07-01T19:11:20Z</dc:date>
    </item>
  </channel>
</rss>

