<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Custom App ID - Derived from usernames/http params in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/custom-app-id-derived-from-usernames-http-params/m-p/36165#M26584</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In the pattern you should put the pattern that you see in the packet capture, remember that must be bigger than 7 characters. But the app-user only is going to be detected when you try to log in, if you block the app you just block the login to the user definided in your app. Also you can try putting the rule above that the rule that accept the App-ID, creating custom signatures sometimes can be a headache. &lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 12 Oct 2013 16:18:01 GMT</pubDate>
    <dc:creator>GLastra</dc:creator>
    <dc:date>2013-10-12T16:18:01Z</dc:date>
    <item>
      <title>Custom App ID - Derived from usernames/http params</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-app-id-derived-from-usernames-http-params/m-p/36163#M26582</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am working with a client in an interesting situation..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are basically needing to limit sections of the network where certain users and login to a web server. For example, only admins can login from zone1 and only users can login from zone2. The application on the web server is not a custom one built by the client but there is no current ID for it in the app-id db. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Currently, we would like to make the policy decisions based on app.. and have a separate ID based on admins or users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I created an APP-ID for the application itself and tested it; it works! I also checked "Continue scanning for other applications".&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Next, I used a proxy to monitor the packets and found that the username is submitted via HTTP PARAMS. So, I cloned the original APP-ID and made a new one (we will call it App-User). I added an AND condition to the original signature and it looks for:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Context: http-req-params&lt;/P&gt;&lt;P&gt;pattern: user (I have also tried username=user).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Qualifier is http method = POST.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After committing this.. the PAN IDs the traffic as the original APP-ID but does NOT change the app identified once someone sends posts requests with the specific username identified.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Will this not work in the manner I think it would? Any better suggestions?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FWIW: I don't have to create an AND rule for each user. The user base all share a generic ID for this system. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Oct 2013 21:10:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-app-id-derived-from-usernames-http-params/m-p/36163#M26582</guid>
      <dc:creator>SDorsey</dc:creator>
      <dc:date>2013-10-08T21:10:06Z</dc:date>
    </item>
    <item>
      <title>Re: Custom App ID - Derived from usernames/http params</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-app-id-derived-from-usernames-http-params/m-p/36164#M26583</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You may want to put the question in Dev community for faster response.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Oct 2013 23:44:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-app-id-derived-from-usernames-http-params/m-p/36164#M26583</guid>
      <dc:creator>ukhapre</dc:creator>
      <dc:date>2013-10-09T23:44:20Z</dc:date>
    </item>
    <item>
      <title>Re: Custom App ID - Derived from usernames/http params</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-app-id-derived-from-usernames-http-params/m-p/36165#M26584</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In the pattern you should put the pattern that you see in the packet capture, remember that must be bigger than 7 characters. But the app-user only is going to be detected when you try to log in, if you block the app you just block the login to the user definided in your app. Also you can try putting the rule above that the rule that accept the App-ID, creating custom signatures sometimes can be a headache. &lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 12 Oct 2013 16:18:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-app-id-derived-from-usernames-http-params/m-p/36165#M26584</guid>
      <dc:creator>GLastra</dc:creator>
      <dc:date>2013-10-12T16:18:01Z</dc:date>
    </item>
  </channel>
</rss>

