<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GMAIL Base and SMTP - WTF?? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/gmail-base-and-smtp-wtf/m-p/37499#M27493</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You're preaching to the converted, my friend.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 05 Jun 2013 00:02:45 GMT</pubDate>
    <dc:creator>darren_g</dc:creator>
    <dc:date>2013-06-05T00:02:45Z</dc:date>
    <item>
      <title>GMAIL Base and SMTP - WTF??</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gmail-base-and-smtp-wtf/m-p/37487#M27481</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Folks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The latest content update (pushed today, my time) gave me the following warning in the task when I installed it&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;VSYS1: Rule 'Outbound_Traffic' application dependency warning: Application 'gmail-base' requires 'smtp' to be allowed, but 'smtp' is denied by rule 'Outbound_Bad'&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;WTF? Since when does GMail require SMTP? The local installations don't use SMTP - they connect to GMail over HTTP/HTPS, and the GMail back-end servers do the SMTP stuff. Why does Palo Alto now think GMail requires SMTP? I should add that I have checked the release notes for this content release and they mention *nothing* about there being a change to the gmail-base app signature.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm not allowing SMTP outbound from everything, because the idiots who run crap like iJunk get my outbound address into blackholes by using misconfigured junk which identifies itself as "localhost.localdomain" in the SMTP EHLO sessions - yet I need GMail for regular use.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone know what the hell is going on here? Impressed I am not.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 May 2013 00:41:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gmail-base-and-smtp-wtf/m-p/37487#M27481</guid>
      <dc:creator>darren_g</dc:creator>
      <dc:date>2013-05-29T00:41:32Z</dc:date>
    </item>
    <item>
      <title>Re: GMAIL Base and SMTP - WTF??</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gmail-base-and-smtp-wtf/m-p/37488#M27482</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I see the same behavior in my lab device too. I did not see anything mentioned in the release notes stating that any changes are made to application "gmail". This looks like a bug, please open a ticket with support for a resolution.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 May 2013 02:19:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gmail-base-and-smtp-wtf/m-p/37488#M27482</guid>
      <dc:creator>sdurga</dc:creator>
      <dc:date>2013-05-29T02:19:51Z</dc:date>
    </item>
    <item>
      <title>Re: GMAIL Base and SMTP - WTF??</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gmail-base-and-smtp-wtf/m-p/37489#M27483</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I already have.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yet another Palo Alto QA failure right here, boys and girls.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I find your lack of Quality....disturbing.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 May 2013 02:25:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gmail-base-and-smtp-wtf/m-p/37489#M27483</guid>
      <dc:creator>darren_g</dc:creator>
      <dc:date>2013-05-29T02:25:02Z</dc:date>
    </item>
    <item>
      <title>Re: GMAIL Base and SMTP - WTF??</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gmail-base-and-smtp-wtf/m-p/37490#M27484</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can I ask for the case number that was opened for this issue?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 May 2013 18:48:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gmail-base-and-smtp-wtf/m-p/37490#M27484</guid>
      <dc:creator>ggutierrez</dc:creator>
      <dc:date>2013-05-29T18:48:35Z</dc:date>
    </item>
    <item>
      <title>Re: GMAIL Base and SMTP - WTF??</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gmail-base-and-smtp-wtf/m-p/37491#M27485</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No, because they haven't given me one yet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The joys of partner support.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you from Palo Alto, or do you just want to reference it for your own case?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 May 2013 22:07:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gmail-base-and-smtp-wtf/m-p/37491#M27485</guid>
      <dc:creator>darren_g</dc:creator>
      <dc:date>2013-05-29T22:07:23Z</dc:date>
    </item>
    <item>
      <title>Re: GMAIL Base and SMTP - WTF??</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gmail-base-and-smtp-wtf/m-p/37492#M27486</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When using clients to access Gmail, the outgoing mail server is smtp.gmail.com and this uses SMTP over SSL or StartTLS. This traffic will be identifed as smtp when using StartTLS or when the SSL session is decrypted.&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.google.com/mail/answer/13287?hl=en" title="https://support.google.com/mail/answer/13287?hl=en"&gt;https://support.google.com/mail/answer/13287?hl=en&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Jun 2013 20:32:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gmail-base-and-smtp-wtf/m-p/37492#M27486</guid>
      <dc:creator>SRA</dc:creator>
      <dc:date>2013-06-03T20:32:07Z</dc:date>
    </item>
    <item>
      <title>Re: GMAIL Base and SMTP - WTF??</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gmail-base-and-smtp-wtf/m-p/37493#M27487</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;He directly addressed this in his original description of the question... he's not using actual clients, he's using strictly web-based Gmail:&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote" modifiedtitle="true"&gt;
&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;The local installations don't use SMTP - they connect to GMail over HTTP/HTPS, and the GMail back-end servers do the SMTP stuff. Why does Palo Alto now think GMail requires SMTP? I should add that I have checked the release notes for this content release and they mention *nothing* about there being a change to the gmail-base app signature.&lt;/SPAN&gt;&lt;/P&gt;
&lt;/PRE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Jun 2013 20:52:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gmail-base-and-smtp-wtf/m-p/37493#M27487</guid>
      <dc:creator>ericgearhart</dc:creator>
      <dc:date>2013-06-03T20:52:25Z</dc:date>
    </item>
    <item>
      <title>Re: GMAIL Base and SMTP - WTF??</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gmail-base-and-smtp-wtf/m-p/37494#M27488</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The warning message identifies application dependencies for all potential app usage scenarios. If your particular scenario does not need the dependency, you can ignore the warning.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Jun 2013 20:57:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gmail-base-and-smtp-wtf/m-p/37494#M27488</guid>
      <dc:creator>SRA</dc:creator>
      <dc:date>2013-06-03T20:57:41Z</dc:date>
    </item>
    <item>
      <title>Re: GMAIL Base and SMTP - WTF??</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gmail-base-and-smtp-wtf/m-p/37495#M27489</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If that's the case, why have I *never* seen this warning before the last content package pushed to my device (375-1810).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have not changed my rulebase. I have not changed my filtering parameters. I have been manually installing content updates since day dot (I have been bitten with automatic upgrades before, and I refuse to allow them to install automatically), and I have never once seen this warning on content install.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There was no mention of this change in the release notes. There's no comment anywhere that I can find from Palo Alto which says, or has said, that SMTP is a requirement. The previous application definition release has NO mention of SMTP being a dependency in the gmail app, or in any of its sub-apps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't believe that SMTP is required at all for the Gmail web app - indeed, I've never seen a single packet going to Gmail which is identified as "SMTP" by the Palo Alto.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So for Palo Alto to suddenly push an app content release which links SMTP to Gmail without notice is a fail on their part, plain and simple.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Jun 2013 22:04:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gmail-base-and-smtp-wtf/m-p/37495#M27489</guid>
      <dc:creator>darren_g</dc:creator>
      <dc:date>2013-06-03T22:04:26Z</dc:date>
    </item>
    <item>
      <title>Re: GMAIL Base and SMTP - WTF??</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gmail-base-and-smtp-wtf/m-p/37496#M27490</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That change was done in content version 375 and I definitely agree with you that it should have been listed in the content release notes. We are investigating why it missed the release notes and will try to prevent it in the future.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Jun 2013 22:43:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gmail-base-and-smtp-wtf/m-p/37496#M27490</guid>
      <dc:creator>SRA</dc:creator>
      <dc:date>2013-06-03T22:43:44Z</dc:date>
    </item>
    <item>
      <title>Re: GMAIL Base and SMTP - WTF??</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gmail-base-and-smtp-wtf/m-p/37497#M27491</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well, got my answer back from PA support.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Apparently, this was done to make some crApple device work properly, no doubt it broke as part of the on-going wars between Google and Apple.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the last reply&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;===&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif';"&gt;To clarify further, Bug 52402 has already been filed with the category of resolved. &lt;BR /&gt; &lt;BR /&gt; The reason for this dependency is that when using gmail on iPhone, the traffic goes out through smtp. After some live tests, it was decided to add smtp as the dependency app. Since this change is minor (no signature change but app definition change only), our release note generation script didn't automatically pick this up properly by adding gmail in the modified app release note section. &lt;BR /&gt; &lt;BR /&gt; We will work with QA to make sure this shouldn't happen again in the future! &lt;BR /&gt; &lt;BR /&gt; ===&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif';"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif';"&gt;So I re-applied the update (which crashed the management plane, but that's maybe because of the quick upgrade/rollback I did in the first place), got the same warning - but web-based Gmail still works.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif';"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif';"&gt;So now, I get a bloody warning every time I commit a policy change. Yay.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Jun 2013 02:57:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gmail-base-and-smtp-wtf/m-p/37497#M27491</guid>
      <dc:creator>darren_g</dc:creator>
      <dc:date>2013-06-04T02:57:49Z</dc:date>
    </item>
    <item>
      <title>Re: GMAIL Base and SMTP - WTF??</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gmail-base-and-smtp-wtf/m-p/37498#M27492</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It'd be nice if maybe a rule had a "don't warn me about dependencies" checkbox or something... I run into this every day too, because I don't have IPsec turned on for my GlobalProtect rule. I don't ever want to use IPSec... I only want to use SSL based VPN.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Jun 2013 13:31:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gmail-base-and-smtp-wtf/m-p/37498#M27492</guid>
      <dc:creator>ericgearhart</dc:creator>
      <dc:date>2013-06-04T13:31:56Z</dc:date>
    </item>
    <item>
      <title>Re: GMAIL Base and SMTP - WTF??</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gmail-base-and-smtp-wtf/m-p/37499#M27493</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You're preaching to the converted, my friend.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Jun 2013 00:02:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gmail-base-and-smtp-wtf/m-p/37499#M27493</guid>
      <dc:creator>darren_g</dc:creator>
      <dc:date>2013-06-05T00:02:45Z</dc:date>
    </item>
    <item>
      <title>Re: GMAIL Base and SMTP - WTF??</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gmail-base-and-smtp-wtf/m-p/37500#M27494</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;v5 removes all the app dependency warnings.&amp;nbsp; Any required dependencies are included in the app.&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Aug 2013 22:03:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gmail-base-and-smtp-wtf/m-p/37500#M27494</guid>
      <dc:creator>Licensing-CICP</dc:creator>
      <dc:date>2013-08-05T22:03:49Z</dc:date>
    </item>
    <item>
      <title>Re: GMAIL Base and SMTP - WTF??</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gmail-base-and-smtp-wtf/m-p/37501#M27495</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Really? So how come I still get the following every time I commit a config change?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="commit_details"&gt;&lt;SPAN class="commit_details"&gt;VSYS1&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="commit_common"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; vsys1: Rule 'Outbound_Traffic' application dependency warning:&lt;/P&gt;&lt;P class="commit_common"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Application 'gmail-base' requires 'smtp' be allowed, but 'smtp' is denied in Rule 'Outbound_Bad'&lt;/P&gt;&lt;P class="commit_common"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Application 'gmail-base' requires 'smtp' be allowed, but 'smtp' is denied in Rule 'Outbound_Bad'&lt;/P&gt;&lt;P class="commit_common"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Application 'gmail-base' requires 'smtp' be allowed, but 'smtp' is denied in Rule 'Outbound_Bad'&lt;/P&gt;&lt;P class="commit_common"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Application 'gmail-base' requires 'smtp' be allowed, but 'smtp' is denied in Rule 'Outbound_Bad'&lt;/P&gt;&lt;P class="commit_common"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Application 'gmail-base' requires 'smtp' be allowed, but 'smtp' is denied in Rule 'Outbound_Bad'&lt;/P&gt;&lt;P class="commit_common"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Application 'gmail-base' requires 'smtp' be allowed, but 'smtp' is denied in Rule 'Outbound_Bad'&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Aug 2013 23:27:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gmail-base-and-smtp-wtf/m-p/37501#M27495</guid>
      <dc:creator>darren_g</dc:creator>
      <dc:date>2013-08-05T23:27:34Z</dc:date>
    </item>
    <item>
      <title>Re: GMAIL Base and SMTP - WTF??</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gmail-base-and-smtp-wtf/m-p/37502#M27496</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P class="commit_common"&gt;vsys1: Rule 'new' application dependency warning:&lt;/P&gt;&lt;P class="commit_common"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Application 'gmail-base' requires 'smtp' be allowed, but 'smtp' is denied in Rule 'rule3'&lt;/P&gt;&lt;P class="commit_common"&gt;(Module: device)&lt;/P&gt;&lt;P class="commit_common"&gt;&lt;/P&gt;&lt;P class="commit_common"&gt;same with us&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Aug 2013 06:21:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gmail-base-and-smtp-wtf/m-p/37502#M27496</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-08-06T06:21:51Z</dc:date>
    </item>
    <item>
      <title>Re: GMAIL Base and SMTP - WTF??</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gmail-base-and-smtp-wtf/m-p/37503#M27497</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Gmail-base has a dependency on smtp.&amp;nbsp; If you are on v5, smtp should be automatically included as a dependency with gmail-base by PAN OS if you don't specify it. Any smtp traffic related to gmail would be caught by your rule.&amp;nbsp; The dependency warning appears to be a bug. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It looks like you have a default allow rule and then only block "bad" apps.&amp;nbsp; By default the firewall will block any traffic so you really don't need that rule. Instead you could just add a rule to merely log what was blocked.&amp;nbsp; But since you specified the smtp app, it is triggering the dependency warning.&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Aug 2013 14:08:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gmail-base-and-smtp-wtf/m-p/37503#M27497</guid>
      <dc:creator>Licensing-CICP</dc:creator>
      <dc:date>2013-08-06T14:08:12Z</dc:date>
    </item>
    <item>
      <title>Re: GMAIL Base and SMTP - WTF??</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gmail-base-and-smtp-wtf/m-p/37504#M27498</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote" modifiedtitle="true"&gt;
&lt;P&gt;CrashCart wrote:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Gmail-base has a dependency on smtp.&amp;nbsp; If you are on v5, smtp should be automatically included as a dependency with gmail-base by PAN OS if you don't specify it. Any smtp traffic related to gmail would be caught by your rule.&amp;nbsp; The dependency warning appears to be a bug. &lt;/P&gt;
&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yeah, another one. Ho hum.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote" modifiedtitle="true"&gt;
&lt;P&gt;It looks like you have a default allow rule and then only block "bad" apps.&amp;nbsp; By default the firewall will block any traffic so you really don't need that rule. Instead you could just add a rule to merely log what was blocked.&amp;nbsp; But since you specified the smtp app, it is triggering the dependency warning.&amp;nbsp; &lt;/P&gt;
&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Not true. My rulebase is setup this way for a reason.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have three rules for "general" (user) passage through the firewall (specific purpose rules not included - there are a number of them).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Approved apps - known_good - allow&lt;/P&gt;&lt;P&gt;2) Unapproved apps - known_bad - deny&lt;/P&gt;&lt;P&gt;3) Everything else - overflow - allow, but report daily to the administrator (me).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I cannot go to a "default-closed" environment because of the nature of our business - you'd be surprised how many apps come through the "overflow" report - apps recognised, but on non-standard ports (web browsing on 8080 is a classic example, SSL on 995 another) which do not match the first rule because that rule is configured "application default" on the service identifier.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This way, I don't stop my users from working (believe me, if I blocked web browsing on 8080, the brown sticky stuff would hit the rotating air distribution blades as nobody would be able to access resources at one of our biggest clients), but I look at the reports daily and add any "new" apps which don't have a business purpose to the known_bad application group and get them blocked, similarly any "new" apps which *do* have a business purpose to the "known_good" group and get them out of the report.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SMTP is specifically denied in the "known_bad" group except from approved nodes (our outbound mail relay) because of pieces of crap like iPhones which just pretend to be SMTP servers and connect to other SMTP servers, identifying themselves as "localhost.localdomain" - which promptly results in my outbound IP address being dumped in black holes, which means I can't send mail out - not a good thing.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Aug 2013 21:58:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gmail-base-and-smtp-wtf/m-p/37504#M27498</guid>
      <dc:creator>darren_g</dc:creator>
      <dc:date>2013-08-06T21:58:31Z</dc:date>
    </item>
    <item>
      <title>Re: GMAIL Base and SMTP - WTF??</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gmail-base-and-smtp-wtf/m-p/37505#M27499</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I cannot go to a "default-closed" environment because of the nature of our business - you'd be surprised how many apps come through the "overflow" report - apps recognised, but on non-standard ports (web browsing on 8080 is a classic example, SSL on 995 another) which do not match the first rule because that rule is configured "application default" on the service identifier.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We just deployed our first PAN device at an office after installing previous PAN devices at our data centers.&amp;nbsp; it is indeed much more difficult to deploy in an office setting.&amp;nbsp; I was also shocked to see all those apps show up, and on non-standard ports like SSL on 444 and 8200, webmail on 993, and of course web-browsing on 8080.&amp;nbsp; I was hoping to get to a default deny rule after observing traffic for a few weeks.&amp;nbsp; Not sure if and when that will happen. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Aug 2013 20:38:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gmail-base-and-smtp-wtf/m-p/37505#M27499</guid>
      <dc:creator>Licensing-CICP</dc:creator>
      <dc:date>2013-08-09T20:38:32Z</dc:date>
    </item>
    <item>
      <title>Re: GMAIL Base and SMTP - WTF??</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gmail-base-and-smtp-wtf/m-p/37506#M27500</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Which PANOS are you running?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Because even if 5.x is supposed to somewhat fix the dependency hell (inspired by the Microsoft dll hell? &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt; it seems that not all dependencies are being taken care of by the 5.x release.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Another issue with this "magic" auto dependency in the background is for how many packets should it allow traffic before the auto depedent appid is being blocked?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example smtp for the case of gmail should only be valid if the domain is .google.com (and whatever other domains google uses nowadays). It would be really bad if the auto depedency suddently, silently, allows any smtp to the rest of the world while you as an admin think you have only allowed gmail as appid... (sure, a workaround might be to add custom urldb that only allows this rule if the http host request matches but still).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 11 Aug 2013 18:57:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gmail-base-and-smtp-wtf/m-p/37506#M27500</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2013-08-11T18:57:49Z</dc:date>
    </item>
  </channel>
</rss>

