<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Turn off Application ID globally? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/turn-off-application-id-globally/m-p/34523#M25328</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Would be nice if those numbers could be posted online &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Specially the case between appid override which disables everything vs "appid:any" which should be equal (at least securitywise).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think Network World got slightly lower throughput when they tried to "disable everything" and one of the theories back then was that a disable added one (or more) cpu-cycles within the PA which would end up with 1%'ish lower throughput. That is the PA will do AppID no matter what, when you disable/ignore the result from the AppID it will take one (or more) additional cpu/fpga/asic cycles to ignore the result.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 19 Aug 2013 07:42:17 GMT</pubDate>
    <dc:creator>mikand</dc:creator>
    <dc:date>2013-08-19T07:42:17Z</dc:date>
    <item>
      <title>Turn off Application ID globally?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/turn-off-application-id-globally/m-p/34518#M25323</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can one turn off the application awarenes globally to set up a PAN as a L4 firewall? Trying to get some comparison stats against the old L4 only (non PAN) firewall and the new PAN.&lt;/P&gt;&lt;P&gt;thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Aug 2013 02:27:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/turn-off-application-id-globally/m-p/34518#M25323</guid>
      <dc:creator>blarney</dc:creator>
      <dc:date>2013-08-16T02:27:57Z</dc:date>
    </item>
    <item>
      <title>Re: Turn off Application ID globally?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/turn-off-application-id-globally/m-p/34519#M25324</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don't believe there is a global setting to turn of appid, but you can configure two application override policies( &lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-1071"&gt;https://live.paloaltonetworks.com/docs/DOC-1071)&lt;/A&gt; and include all ports (1-65535) for&amp;nbsp; both tcp and udp.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Aug 2013 02:53:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/turn-off-application-id-globally/m-p/34519#M25324</guid>
      <dc:creator>sraghunandan</dc:creator>
      <dc:date>2013-08-16T02:53:09Z</dc:date>
    </item>
    <item>
      <title>Re: Turn off Application ID globally?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/turn-off-application-id-globally/m-p/34520#M25325</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So basically create two custom applications one for tcp(tcp/1-65535), the other for udp(udp/1-65535) and create two policies one for all tcp ports the other for all udp ports&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Aug 2013 03:44:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/turn-off-application-id-globally/m-p/34520#M25325</guid>
      <dc:creator>sraghunandan</dc:creator>
      <dc:date>2013-08-16T03:44:19Z</dc:date>
    </item>
    <item>
      <title>Re: Turn off Application ID globally?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/turn-off-application-id-globally/m-p/34521#M25326</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Haha wow I never thought about trying to benchmark App-ID versus non-App-ID in this way... yes this in theory should work, if you built app overrides for any to any traffic and bind them to the App-IDs that define every TCP port and every UDP port.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You'd have to build more specific app overrides for specific ports if you wanted to actually firewall I suppose... or I guess your rules could be defined as App 'any' and define specific services in the service column... this would in essence give you a traditional layer 4 firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Interesting stuff... I have a Breaking Point appliance, and it's tempting to go build this in the lab and see what kind of performance I get out of it compared to App-ID being on,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Aug 2013 14:28:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/turn-off-application-id-globally/m-p/34521#M25326</guid>
      <dc:creator>ericgearhart</dc:creator>
      <dc:date>2013-08-16T14:28:32Z</dc:date>
    </item>
    <item>
      <title>Re: Turn off Application ID globally?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/turn-off-application-id-globally/m-p/34522#M25327</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;keep in mind a&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt; rule with a custom application override does not pass through any of the URL, threat or anti-virus scanning engines.&amp;nbsp; The scanning engine will be used with an app-override if you use an existing built-in application such as web-browsing.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;The above information can also be found at the following link&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-1343"&gt;Application Override and Scanning Engines&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 12px; font-family: Arial, Helvetica, sans-serif;"&gt;Hope this helps.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 12px; font-family: Arial, Helvetica, sans-serif;"&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 12px; font-family: Arial, Helvetica, sans-serif;"&gt;Numan&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Aug 2013 15:49:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/turn-off-application-id-globally/m-p/34522#M25327</guid>
      <dc:creator>mbutt</dc:creator>
      <dc:date>2013-08-16T15:49:48Z</dc:date>
    </item>
    <item>
      <title>Re: Turn off Application ID globally?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/turn-off-application-id-globally/m-p/34523#M25328</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Would be nice if those numbers could be posted online &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Specially the case between appid override which disables everything vs "appid:any" which should be equal (at least securitywise).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think Network World got slightly lower throughput when they tried to "disable everything" and one of the theories back then was that a disable added one (or more) cpu-cycles within the PA which would end up with 1%'ish lower throughput. That is the PA will do AppID no matter what, when you disable/ignore the result from the AppID it will take one (or more) additional cpu/fpga/asic cycles to ignore the result.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Aug 2013 07:42:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/turn-off-application-id-globally/m-p/34523#M25328</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2013-08-19T07:42:17Z</dc:date>
    </item>
    <item>
      <title>Re: Turn off Application ID globally?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/turn-off-application-id-globally/m-p/34524#M25329</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm trying to get more throughput through my 2020.&amp;nbsp; I got the gig interfaces but the FW app ID performance are 500Mb.&amp;nbsp; I want to terminate a&amp;nbsp; Gig Eth circuit to the FW but don't want to impede performance.&amp;nbsp; The circuit carries our VM replication, TSM backup, file sharing, and management.&amp;nbsp; I was expecting that application override would be the best choice to implement, but the Network World comment had me guessing.&amp;nbsp; Any further thoughts or comments on this one?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Aug 2014 18:31:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/turn-off-application-id-globally/m-p/34524#M25329</guid>
      <dc:creator>treese</dc:creator>
      <dc:date>2014-08-12T18:31:33Z</dc:date>
    </item>
  </channel>
</rss>

