<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Adding a Custom Application/Ports to Security Policy in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/adding-a-custom-application-ports-to-security-policy/m-p/44352#M32552</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Maybe my thought process is wrong so I am hoping somebody can set me straight. I have a few non-standard ports that need to be opened on the firewall. They don't belong to any application so I need to allow the ports. What I have done is created custom applications with basically just a name and the ports used (no signatures). I created an application override for these custom applications as well. I then added these custom applications to the security policy along with other known applications that need access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this the best way to open a port on the Palo Altos?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 01 Oct 2013 23:05:24 GMT</pubDate>
    <dc:creator>mario11584</dc:creator>
    <dc:date>2013-10-01T23:05:24Z</dc:date>
    <item>
      <title>Adding a Custom Application/Ports to Security Policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/adding-a-custom-application-ports-to-security-policy/m-p/44352#M32552</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Maybe my thought process is wrong so I am hoping somebody can set me straight. I have a few non-standard ports that need to be opened on the firewall. They don't belong to any application so I need to allow the ports. What I have done is created custom applications with basically just a name and the ports used (no signatures). I created an application override for these custom applications as well. I then added these custom applications to the security policy along with other known applications that need access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this the best way to open a port on the Palo Altos?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Oct 2013 23:05:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/adding-a-custom-application-ports-to-security-policy/m-p/44352#M32552</guid>
      <dc:creator>mario11584</dc:creator>
      <dc:date>2013-10-01T23:05:24Z</dc:date>
    </item>
    <item>
      <title>Re: Adding a Custom Application/Ports to Security Policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/adding-a-custom-application-ports-to-security-policy/m-p/44353#M32553</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What you're doing will work, but you don't have to do an application override for this traffic. You can just configure a security policy, with application set to 'any' or 'custom-app' and define the service ports to allow this traffic through. By doing so you can also add security profiles to the traffic to enable inspection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;app-override will not perform any scanning on the traffic and this can cause threat especially if the traffic is to/from Internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Refer:&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-2344"&gt;Does application override adversely affect Threat ID?&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps,&lt;/P&gt;&lt;P&gt;Aditi&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Oct 2013 03:15:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/adding-a-custom-application-ports-to-security-policy/m-p/44353#M32553</guid>
      <dc:creator>apasupulati</dc:creator>
      <dc:date>2013-10-07T03:15:35Z</dc:date>
    </item>
    <item>
      <title>Re: Adding a Custom Application/Ports to Security Policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/adding-a-custom-application-ports-to-security-policy/m-p/44354#M32554</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That's exactly the information I was looking for. Thanks so much for the help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Oct 2013 15:35:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/adding-a-custom-application-ports-to-security-policy/m-p/44354#M32554</guid>
      <dc:creator>mario11584</dc:creator>
      <dc:date>2013-10-07T15:35:35Z</dc:date>
    </item>
    <item>
      <title>Re: Adding a Custom Application/Ports to Security Policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/adding-a-custom-application-ports-to-security-policy/m-p/44355#M32555</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Another quick question, I am wondering if I can have applications and service ports being used on the same policy? For example, if I use the web-browsing application and create and use a service using ports 60000-65000, will it allow http traffic as well as traffic on ports 60000-65000? Or should I create a policy that allows web-browsing then a separate rule for the service?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Nov 2013 00:31:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/adding-a-custom-application-ports-to-security-policy/m-p/44355#M32555</guid>
      <dc:creator>mario11584</dc:creator>
      <dc:date>2013-11-20T00:31:29Z</dc:date>
    </item>
    <item>
      <title>Re: Adding a Custom Application/Ports to Security Policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/adding-a-custom-application-ports-to-security-policy/m-p/44356#M32556</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Mario,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you include web-browsing in the application column and 60000-65000 in the service column, that security policy would only allow web-browsing traffic on ports 60000-65000. You would need a separate rule to allow web-browsing on its default port (80). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best would be to include web-browsing in the application column and mention all the ports in the service column (standard and non-standard ).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and regards,&lt;/P&gt;&lt;P&gt;Kunal Adak&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Nov 2013 01:11:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/adding-a-custom-application-ports-to-security-policy/m-p/44356#M32556</guid>
      <dc:creator>kadak</dc:creator>
      <dc:date>2013-11-21T01:11:10Z</dc:date>
    </item>
    <item>
      <title>Re: Adding a Custom Application/Ports to Security Policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/adding-a-custom-application-ports-to-security-policy/m-p/44357#M32557</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks again for the help. I just went ahead and created a second rule with a service using the ports 60000-65000 right after the policy I mentioned previously using web-browsing. My thought is traffic for 60000-65000 won't match the previous policy but will match the very next one which contains these ports. Seems like it's working! Thanks again! &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Nov 2013 16:37:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/adding-a-custom-application-ports-to-security-policy/m-p/44357#M32557</guid>
      <dc:creator>mario11584</dc:creator>
      <dc:date>2013-11-21T16:37:17Z</dc:date>
    </item>
  </channel>
</rss>

