<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Application filters in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/application-filters/m-p/38818#M28472</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for sharing, it is nice to hear what others are doing.&amp;nbsp;&amp;nbsp; I am really struggling with the complexity piece (all have different times and filtering rules):&lt;/P&gt;&lt;P&gt;Lots of international kids.&lt;/P&gt;&lt;P&gt;Lower school&lt;/P&gt;&lt;P&gt;Middle school&lt;/P&gt;&lt;P&gt;Upper school&lt;/P&gt;&lt;P&gt;Boarding students (some are 7x24 with school and personal devices)&lt;/P&gt;&lt;P&gt;Dorm Parents (7x24 with school and personal devices).&lt;/P&gt;&lt;P&gt;Employees (school and personal devices)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Not to mention the guests streaming in and out on weekends and summer....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I could go on, but thus my interest in how others are handling apps and rules.&lt;/P&gt;&lt;P&gt;Bob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 23 May 2012 23:30:25 GMT</pubDate>
    <dc:creator>BobW</dc:creator>
    <dc:date>2012-05-23T23:30:25Z</dc:date>
    <item>
      <title>Application filters</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-filters/m-p/38811#M28465</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have been trying to use the application filter functionality as I am setting up our PA with little luck.&amp;nbsp; Example being:&amp;nbsp; I would like to allow pretty much everything under "business" systems", "office programs".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;First problem I am running into is it does not include the dependcies.&amp;nbsp; OK I can get around that and create an applicatio group for the dependencies.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The second problem is one item has some dependencies which are a bit excessive (SMTP for example) AND these dependencies are for a program my users will never use (ariel in my case).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unless I am missing something, there does not appear to be a way to create a filter but exclude some items and that programs dependencies.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does the above sound correct?&lt;/P&gt;&lt;P&gt;If so, is anyone bothering to use the "application filter" option or are you just creating your own groups?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Bob&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PS&amp;nbsp; It would be nice to create a filter and exclude certain applications from that filter with a check box per application.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 May 2012 17:21:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-filters/m-p/38811#M28465</guid>
      <dc:creator>BobW</dc:creator>
      <dc:date>2012-05-16T17:21:52Z</dc:date>
    </item>
    <item>
      <title>Re: Application filters</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-filters/m-p/38812#M28466</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The tricky part with application filter comparing to custom groups is the danger of new application(s) (you are in the hands of what PA thinks).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Having that said I have heard some rumours that PANOS 5.0 (I think it was) will fix some of the dependency jungle out there for the appid.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 May 2012 17:06:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-filters/m-p/38812#M28466</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-05-17T17:06:58Z</dc:date>
    </item>
    <item>
      <title>Re: Application filters</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-filters/m-p/38813#M28467</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We use application filters based on subcategory.&amp;nbsp; When deciding to allow or block a subcategory, we ask ourselves:&amp;nbsp; &lt;SPAN style="line-height: 115%; font-family: &amp;amp;quot;Calibri&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;; font-size: 11pt; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: &amp;amp;quot;Times New Roman&amp;amp;quot;; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;"&gt;if Palo Alto created a new application definition that you haven’t heard of before and added it to the subcategory, should it be allowed or blocked?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="line-height: 115%; font-family: &amp;amp;quot;Calibri&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;; font-size: 11pt; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: &amp;amp;quot;Times New Roman&amp;amp;quot;; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;"&gt;Then we create application groups for the exceptions in a subcategory.&amp;nbsp; We have about 200 exceptions in our application groups currently.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="line-height: 115%; font-family: &amp;amp;quot;Calibri&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;; font-size: 11pt; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: &amp;amp;quot;Times New Roman&amp;amp;quot;; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="line-height: 115%; font-family: &amp;amp;quot;Calibri&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;; font-size: 11pt; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: &amp;amp;quot;Times New Roman&amp;amp;quot;; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 May 2012 18:32:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-filters/m-p/38813#M28467</guid>
      <dc:creator>bstapleton</dc:creator>
      <dc:date>2012-05-22T18:32:52Z</dc:date>
    </item>
    <item>
      <title>Re: Application filters</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-filters/m-p/38814#M28468</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am using a different way : I reviewed all applications once and decided which ones I wanted to ban. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Every week I receive an email from PA with a list newly created apps. I review each of them and decide which ones I want to ban and add them to my application ban group.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 May 2012 20:52:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-filters/m-p/38814#M28468</guid>
      <dc:creator>essnet</dc:creator>
      <dc:date>2012-05-22T20:52:44Z</dc:date>
    </item>
    <item>
      <title>Re: Application filters</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-filters/m-p/38815#M28469</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your reply.&amp;nbsp; So if I understadn you correctly you have a couple rules:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Deny Banned apps (custom application group)&lt;/P&gt;&lt;P&gt;Allow (Application filter)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How do you handle the dependcies?&lt;/P&gt;&lt;P&gt;Doesn't the above give you a warning when you commit?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Bob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 May 2012 15:27:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-filters/m-p/38815#M28469</guid>
      <dc:creator>BobW</dc:creator>
      <dc:date>2012-05-23T15:27:26Z</dc:date>
    </item>
    <item>
      <title>Re: Application filters</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-filters/m-p/38816#M28470</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you enlighten me as to the order of your allow and deny rules and what order they are in?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;for example:&amp;nbsp; In my case I am trying to, for a single group of users us almost exclusivley allow rules:&lt;/P&gt;&lt;P&gt;Middle school-allow basic apps (app group as defined by myself)&lt;/P&gt;&lt;P&gt;Middle school-allow expanded apps before and after school only (app group as defined by myself)&lt;/P&gt;&lt;P&gt;Middle school deny-deny all apps for middle school users that are no allowed by teh above (mostly for logging purposes)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Bob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 May 2012 15:32:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-filters/m-p/38816#M28470</guid>
      <dc:creator>BobW</dc:creator>
      <dc:date>2012-05-23T15:32:23Z</dc:date>
    </item>
    <item>
      <title>Re: Application filters</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-filters/m-p/38817#M28471</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We're able to work out dependencies by looking at the errors and adding the dependent applications to our allow groups.&lt;/P&gt;&lt;P&gt;It seems we don't have the complexity regarding time of day that you do.&amp;nbsp; Our rule structure is this:&lt;/P&gt;&lt;P&gt;deny Block groups&lt;/P&gt;&lt;P&gt;allow Allow groups and Allow subcategory filters&lt;/P&gt;&lt;P&gt;deny Block subcategory filters&lt;/P&gt;&lt;P&gt;The key is that the Allow subcategory filters and Block subcategory filters never include each other's subcategories, but added together contain all subcategories.&lt;/P&gt;&lt;P&gt;Adding rules for allowing applications for off-hours depends on how much of the application structure changes policy for off-hours.&amp;nbsp; If the differences are just a few apps, I would put a scheduled rule like "allow Allow off-hours groups" before the first rule called deny Block groups.&lt;/P&gt;&lt;P&gt;If I wanted to allow a few subcategory filters for off-hours, I would consider copying the entire structure and placing those rules above the current structure:&lt;/P&gt;&lt;P&gt;deny Block off-hours groups&lt;/P&gt;&lt;P&gt;allow Allow off-hours groups and Allow off-hours subcategory filters&lt;/P&gt;&lt;P&gt;deny Block off-hours subcategory filters&lt;/P&gt;&lt;P&gt;deny Block groups&lt;/P&gt;&lt;P&gt;allow Allow groups and Allow subcategory filters&lt;/P&gt;&lt;P&gt;deny Block subcategory filters&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 May 2012 15:50:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-filters/m-p/38817#M28471</guid>
      <dc:creator>bstapleton</dc:creator>
      <dc:date>2012-05-23T15:50:15Z</dc:date>
    </item>
    <item>
      <title>Re: Application filters</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-filters/m-p/38818#M28472</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for sharing, it is nice to hear what others are doing.&amp;nbsp;&amp;nbsp; I am really struggling with the complexity piece (all have different times and filtering rules):&lt;/P&gt;&lt;P&gt;Lots of international kids.&lt;/P&gt;&lt;P&gt;Lower school&lt;/P&gt;&lt;P&gt;Middle school&lt;/P&gt;&lt;P&gt;Upper school&lt;/P&gt;&lt;P&gt;Boarding students (some are 7x24 with school and personal devices)&lt;/P&gt;&lt;P&gt;Dorm Parents (7x24 with school and personal devices).&lt;/P&gt;&lt;P&gt;Employees (school and personal devices)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Not to mention the guests streaming in and out on weekends and summer....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I could go on, but thus my interest in how others are handling apps and rules.&lt;/P&gt;&lt;P&gt;Bob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 May 2012 23:30:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-filters/m-p/38818#M28472</guid>
      <dc:creator>BobW</dc:creator>
      <dc:date>2012-05-23T23:30:25Z</dc:date>
    </item>
    <item>
      <title>Re: Application filters</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/application-filters/m-p/38819#M28473</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Wow - that's a lot of constituencies.&amp;nbsp; Hopefully, you'll find some commonality in the applications and subcategories that you allow and block between the constituencies so you can group the applications easily.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One other thing I thought of for dependencies:&amp;nbsp; we created groups for applications that have tons of them.&amp;nbsp; For ms-rdp, for example, we created a group called ms-rdp_suite and included netbios-ss, netbios-dg, etc. etc.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 May 2012 00:03:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/application-filters/m-p/38819#M28473</guid>
      <dc:creator>bstapleton</dc:creator>
      <dc:date>2012-05-24T00:03:53Z</dc:date>
    </item>
  </channel>
</rss>

