<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: App-ID updates break existing rules in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/app-id-updates-break-existing-rules/m-p/29803#M21780</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mike, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can always go to the release notes before upgrading. That will have the modified decoders and the latest added or changed applications.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;Numan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 09 Oct 2013 23:05:43 GMT</pubDate>
    <dc:creator>mbutt</dc:creator>
    <dc:date>2013-10-09T23:05:43Z</dc:date>
    <item>
      <title>App-ID updates break existing rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/app-id-updates-break-existing-rules/m-p/29796#M21773</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Howdy,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How do most of you manage situations where App-ID updates break functioning rules?&amp;nbsp; This just happened to me: I have Lync 2010 and the internal clients need to connect to the edge server.&amp;nbsp; I had a rule in place that allowed ms-lync, ssl, and stun.&amp;nbsp; That worked fine until last weeks update (396), at which point ssl was now identified as "ms-lync-online".&amp;nbsp; So the rule started blocking traffic to external clients who shared a resource.&amp;nbsp; The fix was to observe internal client traffic to the Lync edge server to see that traffic was now denied, then add the application to the list of allowed traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So that is one instance, I bet others out there have found issues too.&amp;nbsp; What are people doing to protect functioning policies from breaking after app-id updates?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Oct 2013 18:53:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/app-id-updates-break-existing-rules/m-p/29796#M21773</guid>
      <dc:creator>msullivan</dc:creator>
      <dc:date>2013-10-07T18:53:46Z</dc:date>
    </item>
    <item>
      <title>Re: App-ID updates break existing rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/app-id-updates-break-existing-rules/m-p/29797#M21774</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/message/31004"&gt;What happens when a previously unknown App-ID gets added to PA through dynamic updates? How are others handling this sit…&lt;/A&gt; is a thread I started back in August asking this exact same question. All the answers were basically "use change control and monitor the App-IDs that get added."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How in the world we're expected to remember all the App-IDs in use and somehow just "know" that a new App-ID will identify traffic traversing our firewall I have no idea... &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I guess for really business critical "it can never break" rules that you build, you can just use App-ID 'Any' and specific a port in the service column. That's the best thing I can come up with for rules that I build that "can't ever break."&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Oct 2013 19:24:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/app-id-updates-break-existing-rules/m-p/29797#M21774</guid>
      <dc:creator>ericgearhart</dc:creator>
      <dc:date>2013-10-07T19:24:23Z</dc:date>
    </item>
    <item>
      <title>Re: App-ID updates break existing rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/app-id-updates-break-existing-rules/m-p/29798#M21775</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Usually I experience this after my first commit.&amp;nbsp; Usually it is a scramble to quickly put in the new applications to unbreak things before people find out.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Oct 2013 03:44:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/app-id-updates-break-existing-rules/m-p/29798#M21775</guid>
      <dc:creator>gheimer</dc:creator>
      <dc:date>2013-10-08T03:44:08Z</dc:date>
    </item>
    <item>
      <title>Re: App-ID updates break existing rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/app-id-updates-break-existing-rules/m-p/29799#M21776</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the reply's.&amp;nbsp; I guess I'm not alone on this. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;@PAN - you need to figure out a way to merge these databases without breaking production environments.&amp;nbsp; My devices are in a data center, so it isn't pretty when something like this happens.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Oct 2013 21:47:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/app-id-updates-break-existing-rules/m-p/29799#M21776</guid>
      <dc:creator>msullivan</dc:creator>
      <dc:date>2013-10-08T21:47:39Z</dc:date>
    </item>
    <item>
      <title>Re: App-ID updates break existing rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/app-id-updates-break-existing-rules/m-p/29800#M21777</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Welcome to my world.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I got bitten by the exact same update - broke my MS-Lync implementation - and added a metric shitload of dependencies into the rule for accessing the edge server from outside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best you can do is subscribe to the upgrade notifications, and check every single one before applying the content upgrade. I don't allow my firewall to auto-apply content updates (virus and web filtering fine, but not content) for exactly this reason.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PAN are kind of between a rock and a hard place here - people want new apps identified to give better control - but they can't do that without breaking some older implementations which were basically work-arounds because the app wasn't identified.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maybe some kind of pre-parsing of content upgrades which checks against affected rules and notifies before applying - like they do if you try and delete an object which is referenced elsewhere - but I don't know how feasible this would be, especially if you've got a lot of rules to check against.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Oct 2013 03:46:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/app-id-updates-break-existing-rules/m-p/29800#M21777</guid>
      <dc:creator>darren_g</dc:creator>
      <dc:date>2013-10-09T03:46:15Z</dc:date>
    </item>
    <item>
      <title>Re: App-ID updates break existing rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/app-id-updates-break-existing-rules/m-p/29801#M21778</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;+1&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Oct 2013 15:09:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/app-id-updates-break-existing-rules/m-p/29801#M21778</guid>
      <dc:creator>msullivan</dc:creator>
      <dc:date>2013-10-09T15:09:58Z</dc:date>
    </item>
    <item>
      <title>Re: App-ID updates break existing rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/app-id-updates-break-existing-rules/m-p/29802#M21779</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If they broke out App-ID updates from threat updates that would be nice too. I'd like to not be missing threat updates that have come out just because I'm holding off on updating my App-ID version... right now the two are intertwined. I'd rather see them split apart.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Oct 2013 19:35:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/app-id-updates-break-existing-rules/m-p/29802#M21779</guid>
      <dc:creator>ericgearhart</dc:creator>
      <dc:date>2013-10-09T19:35:09Z</dc:date>
    </item>
    <item>
      <title>Re: App-ID updates break existing rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/app-id-updates-break-existing-rules/m-p/29803#M21780</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mike, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can always go to the release notes before upgrading. That will have the modified decoders and the latest added or changed applications.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;Numan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Oct 2013 23:05:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/app-id-updates-break-existing-rules/m-p/29803#M21780</guid>
      <dc:creator>mbutt</dc:creator>
      <dc:date>2013-10-09T23:05:43Z</dc:date>
    </item>
    <item>
      <title>Re: App-ID updates break existing rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/app-id-updates-break-existing-rules/m-p/29804#M21781</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is about the best option and best description of the circumstances&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Oct 2013 00:31:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/app-id-updates-break-existing-rules/m-p/29804#M21781</guid>
      <dc:creator>kalebw</dc:creator>
      <dc:date>2013-10-10T00:31:36Z</dc:date>
    </item>
  </channel>
</rss>

