<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Policy Based Forwarding applications in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/policy-based-forwarding-applications/m-p/2711#M2020</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Here is a snippet from the admin guide for using apps with PBF:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;"The initial session on a given destination IP address and port that is associated with an application will not match an application-specific rule and will be forwarded according to &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;subsequentPBF&lt;/SPAN&gt; rules (that do not specify an application) or the virtual router’s forwarding table. &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;Allsubsequent&lt;/SPAN&gt; sessions on that destination IP address and port for the same application &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;willmatch&lt;/SPAN&gt; an application-specific rule. To ensure forwarding through PBF rules, application specific rules are not recommended."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;which&lt;/SPAN&gt; means the PBF rule will not match 100% of the time. PBF routing is determined by the first packet and most of the apps we &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;have are not identified&lt;/SPAN&gt; with the first packet which implies this will take the normal routing route. After the app is identified, the subsequent sessions of the same app with same &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;src&lt;/SPAN&gt; and &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;destn&lt;/SPAN&gt; will match the PBF rule. Again, it is not recommended to use apps with PBF.&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 04 Sep 2014 14:46:38 GMT</pubDate>
    <dc:creator>HULK</dc:creator>
    <dc:date>2014-09-04T14:46:38Z</dc:date>
    <item>
      <title>Policy Based Forwarding applications</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/policy-based-forwarding-applications/m-p/2709#M2018</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I realize that PBF application based routing is limited to a subset of applications supported.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We're specifically looking to use PBF for Outlook-Web-Online and it's not in the list but many other things are, like MS-OCS-* and SMTP, etc...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do we know why some applications are listed and why?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible to make a feature request to support this application?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thoughts?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Sep 2014 13:13:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/policy-based-forwarding-applications/m-p/2709#M2018</guid>
      <dc:creator>kk555</dc:creator>
      <dc:date>2014-09-04T13:13:03Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Based Forwarding applications</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/policy-based-forwarding-applications/m-p/2710#M2019</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Kk555,&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Not all Apps can be used for PBF, &lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;because&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt; the routing decision is made at &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;sessions start&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;, you can only use Apps that can be discovered at session start.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;STRONG&gt;For your example:&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;google&lt;/SPAN&gt;-docs-base has a dependency of web-browsing &amp;amp; SSL. &lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;At session start the PAN will discover web-browsing or SSL and make a routing decision&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Once this decision is made the PAN will keep it for this Session.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;This is why you can't select all Apps for PBF.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;/P&gt;&lt;P&gt;Please find below similar discussion thread:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/message/29056"&gt;Re: PBF rule - applications&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-1437"&gt; Using Applications in PBF&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/message/4701"&gt;PBF based on Apps&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/message/7562"&gt;Re: APP limitation using PBF&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/message/29211"&gt;Re: Policy Based Forwarding for Application "Ping"&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Sep 2014 14:45:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/policy-based-forwarding-applications/m-p/2710#M2019</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-09-04T14:45:22Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Based Forwarding applications</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/policy-based-forwarding-applications/m-p/2711#M2020</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Here is a snippet from the admin guide for using apps with PBF:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;"The initial session on a given destination IP address and port that is associated with an application will not match an application-specific rule and will be forwarded according to &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;subsequentPBF&lt;/SPAN&gt; rules (that do not specify an application) or the virtual router’s forwarding table. &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;Allsubsequent&lt;/SPAN&gt; sessions on that destination IP address and port for the same application &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;willmatch&lt;/SPAN&gt; an application-specific rule. To ensure forwarding through PBF rules, application specific rules are not recommended."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;which&lt;/SPAN&gt; means the PBF rule will not match 100% of the time. PBF routing is determined by the first packet and most of the apps we &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;have are not identified&lt;/SPAN&gt; with the first packet which implies this will take the normal routing route. After the app is identified, the subsequent sessions of the same app with same &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;src&lt;/SPAN&gt; and &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;destn&lt;/SPAN&gt; will match the PBF rule. Again, it is not recommended to use apps with PBF.&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Sep 2014 14:46:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/policy-based-forwarding-applications/m-p/2711#M2020</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-09-04T14:46:38Z</dc:date>
    </item>
  </channel>
</rss>

