<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Permit related/inherited applications in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/permit-related-inherited-applications/m-p/38449#M28172</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Application filter will be best bet.&lt;/P&gt;&lt;P&gt;You can also allow app 'any' port '80' '443' like traditional port based firewall but it will allow all traffic on selected ports.&lt;/P&gt;&lt;P&gt;If you need help with custom app discussed in other thread, you can check at Dev center community.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 16 Jul 2013 01:48:50 GMT</pubDate>
    <dc:creator>ukhapre</dc:creator>
    <dc:date>2013-07-16T01:48:50Z</dc:date>
    <item>
      <title>Permit related/inherited applications</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/permit-related-inherited-applications/m-p/38447#M28170</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am looking to build a particular security policy where *all* web browsing is permitted, including any applications that the session gets transitioned to as a a result of App-ID figuring it out.&amp;nbsp; For example, a session may start out as a "web-browsing" application but then turn into a "google-maps" application as App-ID figures out what the user is trying to do.&amp;nbsp; I would like to permit *anything* that begins it's life as web-browsing...is there a way to do this with Application groups/filters, or do I have to bite the bullet, mark the application in my security policy as "Any", and set the service field of the policy to "service-http" and "service-https"?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My search-fu is not as honed this morning, so I apologize if this has already been answered.&amp;nbsp; Thanks in advance!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 14 Jul 2013 19:09:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/permit-related-inherited-applications/m-p/38447#M28170</guid>
      <dc:creator>krhayes</dc:creator>
      <dc:date>2013-07-14T19:09:45Z</dc:date>
    </item>
    <item>
      <title>Re: Permit related/inherited applications</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/permit-related-inherited-applications/m-p/38448#M28171</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Few methods to achieve this have been discussed in the&amp;nbsp; thread added below such as :&lt;/P&gt;&lt;P&gt;Creating an App-Group [( Application Filter for category General-Internet &amp;gt;technology &amp;gt;Characteristic -Widely Used Browser Based ) + (Application -ssl)]&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/message/17518#17518"&gt;https://live.paloaltonetworks.com/message/17518#17518&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But I think allowing app-any&amp;nbsp; and services- service-http and https would be the best bet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Jul 2013 08:37:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/permit-related-inherited-applications/m-p/38448#M28171</guid>
      <dc:creator>UhMayYeah</dc:creator>
      <dc:date>2013-07-15T08:37:15Z</dc:date>
    </item>
    <item>
      <title>Re: Permit related/inherited applications</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/permit-related-inherited-applications/m-p/38449#M28172</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Application filter will be best bet.&lt;/P&gt;&lt;P&gt;You can also allow app 'any' port '80' '443' like traditional port based firewall but it will allow all traffic on selected ports.&lt;/P&gt;&lt;P&gt;If you need help with custom app discussed in other thread, you can check at Dev center community.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Jul 2013 01:48:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/permit-related-inherited-applications/m-p/38449#M28172</guid>
      <dc:creator>ukhapre</dc:creator>
      <dc:date>2013-07-16T01:48:50Z</dc:date>
    </item>
  </channel>
</rss>

