<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic connection interrupt in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/connection-interrupt/m-p/40151#M29445</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;An internal application is used for databese.It's default port is 5520&lt;/P&gt;&lt;P&gt;when we saw this behaviour we wrote an application override rule for that tcp port and named a new application.&lt;/P&gt;&lt;P&gt;after that we saw issue behaviour not changed(user is disconnectet from application sometimes, not everytime) but from logs we saw 2 applications match this traffic.&lt;/P&gt;&lt;P&gt;that was strange.if byte is big it is seen other app.&lt;/P&gt;&lt;P&gt;if it is small it see our app id which we created.&lt;/P&gt;&lt;P&gt;any ideas ? thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 17 Jun 2013 12:38:59 GMT</pubDate>
    <dc:creator>Retired Member</dc:creator>
    <dc:date>2013-06-17T12:38:59Z</dc:date>
    <item>
      <title>connection interrupt</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/connection-interrupt/m-p/40151#M29445</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;An internal application is used for databese.It's default port is 5520&lt;/P&gt;&lt;P&gt;when we saw this behaviour we wrote an application override rule for that tcp port and named a new application.&lt;/P&gt;&lt;P&gt;after that we saw issue behaviour not changed(user is disconnectet from application sometimes, not everytime) but from logs we saw 2 applications match this traffic.&lt;/P&gt;&lt;P&gt;that was strange.if byte is big it is seen other app.&lt;/P&gt;&lt;P&gt;if it is small it see our app id which we created.&lt;/P&gt;&lt;P&gt;any ideas ? thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Jun 2013 12:38:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/connection-interrupt/m-p/40151#M29445</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-06-17T12:38:59Z</dc:date>
    </item>
    <item>
      <title>Re: connection interrupt</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/connection-interrupt/m-p/40152#M29446</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It's a known bug in using application overrides - I ran into it recently myself.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rather than use an application override, just create a custom port and allow that in your rule.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Something like this&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="unreal.jpg" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/6956_unreal.jpg" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In this rule, the service ports "unreal_tcp1" and "unreal_tcp2" refer to the two specific ports used by this application, and are defined as services objects. The rest of the rule simply locks down source and destination as required.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you need other applications on the same server, then make a *separate* rule for them. You need to keep this rule on its own because you need to restrict the custom service ports (otherwise, other applications would be blocked because they didn't match the ports defined as "unreal_tcp1" and "unreal_tcp2").&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;cheers.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Jun 2013 02:52:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/connection-interrupt/m-p/40152#M29446</guid>
      <dc:creator>darren_g</dc:creator>
      <dc:date>2013-06-18T02:52:11Z</dc:date>
    </item>
  </channel>
</rss>

