<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: unauthorized application goes to specific rule in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/unauthorized-application-goes-to-specific-rule/m-p/245#M200</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Laurent,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You should not see web-browsing as an application that uses the same security rule as the one set for allowing pings.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to block everything except ping , you may keep an explicit deny rule at the bottom.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Parth&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 11 Nov 2011 09:14:08 GMT</pubDate>
    <dc:creator>ppatel</dc:creator>
    <dc:date>2011-11-11T09:14:08Z</dc:date>
    <item>
      <title>unauthorized application goes to specific rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unauthorized-application-goes-to-specific-rule/m-p/244#M199</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have defined a rule that allow pings (using the "ping" application). However there are a lots of other applications that flows through this rule, even "web-browsing" !!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How is this possible ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Laurent&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Nov 2011 08:39:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unauthorized-application-goes-to-specific-rule/m-p/244#M199</guid>
      <dc:creator>ldormond</dc:creator>
      <dc:date>2011-11-11T08:39:08Z</dc:date>
    </item>
    <item>
      <title>Re: unauthorized application goes to specific rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unauthorized-application-goes-to-specific-rule/m-p/245#M200</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Laurent,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You should not see web-browsing as an application that uses the same security rule as the one set for allowing pings.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to block everything except ping , you may keep an explicit deny rule at the bottom.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Parth&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Nov 2011 09:14:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unauthorized-application-goes-to-specific-rule/m-p/245#M200</guid>
      <dc:creator>ppatel</dc:creator>
      <dc:date>2011-11-11T09:14:08Z</dc:date>
    </item>
    <item>
      <title>Re: unauthorized application goes to specific rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unauthorized-application-goes-to-specific-rule/m-p/246#M201</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want to know why I have other applications that are matched by my ping rule. See printscreen attached.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Laurent&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Nov 2011 09:45:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unauthorized-application-goes-to-specific-rule/m-p/246#M201</guid>
      <dc:creator>ldormond</dc:creator>
      <dc:date>2011-11-11T09:45:41Z</dc:date>
    </item>
    <item>
      <title>Re: unauthorized application goes to specific rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unauthorized-application-goes-to-specific-rule/m-p/247#M202</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Looking at your traffic log and the rule I would advise you to open a case with support. This merits closer examination.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Benjamin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Nov 2011 21:17:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unauthorized-application-goes-to-specific-rule/m-p/247#M202</guid>
      <dc:creator>bpappas</dc:creator>
      <dc:date>2011-11-11T21:17:34Z</dc:date>
    </item>
    <item>
      <title>Re: unauthorized application goes to specific rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unauthorized-application-goes-to-specific-rule/m-p/248#M203</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Laurent,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you change the service to use application default and appliction to ping and try to see what results you get.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can set an application and then "any" service, our App-ID engine will filter based on application regardless of ports. Also, most applications have an "application default" option for service. For instance, if you set application "ssl" and selected "application default" for service, it would only allow the ssl application on port 443. If it detected ssl traffic on an irregular port it would not be processed under that rule. Likewise, if you set application to "any", you could then specify services and it would only apply the policy to those services (ports) regardless of application.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also I see that following ip addresses come from the same zone XDMZ. Is this the intended setup?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Logs show&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(1) 10.120.134.28 that uses application SiteScope Jmx collection&lt;/P&gt;&lt;P&gt;(2)&amp;nbsp; 10.120.120.56 that uses application ping&lt;/P&gt;&lt;P&gt;(3) 145.232.250.140/141&amp;nbsp; that uses web-browsing&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Parth&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Nov 2011 21:35:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unauthorized-application-goes-to-specific-rule/m-p/248#M203</guid>
      <dc:creator>ppatel</dc:creator>
      <dc:date>2011-11-11T21:35:23Z</dc:date>
    </item>
    <item>
      <title>Re: unauthorized application goes to specific rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unauthorized-application-goes-to-specific-rule/m-p/249#M204</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Parth,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Indeed, when setting service to "application-default" it's much better. No more heterogenous traffic. The only other traffic I get is "incomplete".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However I don't really understand why application signature was not sufficient in this case...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Laurent&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Nov 2011 08:13:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unauthorized-application-goes-to-specific-rule/m-p/249#M204</guid>
      <dc:creator>ldormond</dc:creator>
      <dc:date>2011-11-15T08:13:02Z</dc:date>
    </item>
    <item>
      <title>Re: unauthorized application goes to specific rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unauthorized-application-goes-to-specific-rule/m-p/250#M205</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Do you have any news on that topic.&lt;/P&gt;&lt;P&gt;We experienced the same issue here in 4.1.6 version.&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Joseph&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Nov 2012 11:06:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unauthorized-application-goes-to-specific-rule/m-p/250#M205</guid>
      <dc:creator>joseph.morel</dc:creator>
      <dc:date>2012-11-07T11:06:19Z</dc:date>
    </item>
    <item>
      <title>Re: unauthorized application goes to specific rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unauthorized-application-goes-to-specific-rule/m-p/251#M206</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are my eyes playing with me or isnt the second to last rule basically an "any any allow" (which would explain why traffic is let through) looking at the picture provided by&amp;nbsp; &lt;SPAN class="j-post-author "&gt;&lt;STRONG&gt;&lt;A _jive_internal="true" class="jiveTT-hover-user jive-username-link" data-avatarid="-1" data-externalid="" data-presence="null" data-userid="4718" data-username="ldormond" href="https://live.paloaltonetworks.com/people/ldormond" id="jive-471823630074060957943"&gt;ldormond&lt;/A&gt;&amp;nbsp; &lt;/STRONG&gt;&amp;nbsp; Nov 11, 2011 10:45 AM &lt;/SPAN&gt;?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Nov 2012 11:47:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unauthorized-application-goes-to-specific-rule/m-p/251#M206</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-11-07T11:47:36Z</dc:date>
    </item>
    <item>
      <title>Re: unauthorized application goes to specific rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unauthorized-application-goes-to-specific-rule/m-p/252#M207</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes but the rule which is matched in the log is the ping one&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Nov 2012 12:34:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unauthorized-application-goes-to-specific-rule/m-p/252#M207</guid>
      <dc:creator>joseph.morel</dc:creator>
      <dc:date>2012-11-07T12:34:09Z</dc:date>
    </item>
    <item>
      <title>Re: unauthorized application goes to specific rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unauthorized-application-goes-to-specific-rule/m-p/253#M208</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ahh &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What if you 1) ping 2) do some web-browsing (or whatever) from a srcip which belongs to grp-cisco-css towards a dstip which belongs to grp-addi-web?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Will the traffic log then (for the 2nd case above) display "Keep_Alive_CSS" as rulehit or "ALLOW ANY FROM XDMZ" (or whatever the rules are named in your case)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Im thinking that the compiler incorrectly merged (by optimization) the "any any allow" rule with the first occurance where this srcip/dstip combo exists (like some inverse shadow rule) so the wrong rulehit is displayed (I mean security wise its correct beause you do have a "any any accept" (which in most cases is bad) but the incorrect rule is being blamed for why traffic was let through)?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Nov 2012 04:24:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unauthorized-application-goes-to-specific-rule/m-p/253#M208</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-11-08T04:24:54Z</dc:date>
    </item>
    <item>
      <title>Re: unauthorized application goes to specific rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unauthorized-application-goes-to-specific-rule/m-p/254#M209</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help guys, but I currently have no more access to the device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But I had set the service to "application-default" instead of "any" as suggested by Parth and the issue was resolved.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Nov 2012 14:18:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unauthorized-application-goes-to-specific-rule/m-p/254#M209</guid>
      <dc:creator>ldormond</dc:creator>
      <dc:date>2012-11-21T14:18:51Z</dc:date>
    </item>
  </channel>
</rss>

