<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to allow unidentifed and insufficient-data application in the policy ? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-allow-unidentifed-and-insufficient-data-application-in/m-p/41637#M30621</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well you could manually create an Application and base it on certain signature criteria. I have had to do this for certain Sharepoint sites to allow access to the files on there for my users. For that I based the signature on the sites HTTP-req-host-Header's and the ports it uses but you can base it on other things.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you do that and then add your newly created application to your allow rule it should in theory work. But you might have to play around with how you identify the application until you find a signature that correctly identifies it for you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 30 Oct 2012 11:43:07 GMT</pubDate>
    <dc:creator>JRussell</dc:creator>
    <dc:date>2012-10-30T11:43:07Z</dc:date>
    <item>
      <title>How to allow unidentifed and insufficient-data application in the policy ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-allow-unidentifed-and-insufficient-data-application-in/m-p/41636#M30620</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, I have some problem. As our design, we allow certain application in policies and deny all at the bottom. and we found that PAN device can't identify some app. so it is denied at the last rule.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How could we allow this unidentified app if we can't select this in application list?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Oct 2012 09:43:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-allow-unidentifed-and-insufficient-data-application-in/m-p/41636#M30620</guid>
      <dc:creator>mindterra</dc:creator>
      <dc:date>2012-10-30T09:43:40Z</dc:date>
    </item>
    <item>
      <title>Re: How to allow unidentifed and insufficient-data application in the policy ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-allow-unidentifed-and-insufficient-data-application-in/m-p/41637#M30621</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well you could manually create an Application and base it on certain signature criteria. I have had to do this for certain Sharepoint sites to allow access to the files on there for my users. For that I based the signature on the sites HTTP-req-host-Header's and the ports it uses but you can base it on other things.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you do that and then add your newly created application to your allow rule it should in theory work. But you might have to play around with how you identify the application until you find a signature that correctly identifies it for you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Oct 2012 11:43:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-allow-unidentifed-and-insufficient-data-application-in/m-p/41637#M30621</guid>
      <dc:creator>JRussell</dc:creator>
      <dc:date>2012-10-30T11:43:07Z</dc:date>
    </item>
    <item>
      <title>Re: How to allow unidentifed and insufficient-data application in the policy ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-allow-unidentifed-and-insufficient-data-application-in/m-p/41638#M30622</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thats the proper way of handling this (create custom appid).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As a workaround you can also use application override and instruct PA that traffic from srcip/range to dstip/range on a specific port lets say TCP80 should be identified as "web-browsing" instead of unknown or whatever.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Oct 2012 18:51:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-allow-unidentifed-and-insufficient-data-application-in/m-p/41638#M30622</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-10-30T18:51:18Z</dc:date>
    </item>
  </channel>
</rss>

