<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Creating Custom Applications - Dummies Guide? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/creating-custom-applications-dummies-guide/m-p/5406#M3972</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is there a dummies guide to creating custom application please?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a couple of "in-house" apps that always pass traffic on certain ports, always to/from a certain IP range, and I'm struggling to see how to put "something" in place that says "If this traffic is between source A and destination B and is on port XYZ it is CustomApp"?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Equally we have a couple of apps that need a stupid amount combination of ports/port-ranges open.&amp;nbsp; AIUI with a custom app you can only specify one port at a time?&amp;nbsp; How would this work if your source and destination are always the same but the ports could be one of several hundred i.e. the app uses port(s) 7000-76500 TCP/UDP?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Essentially I just want to not have "Unknown TCP/UDP" in the ACC for traffic matching those policies if possible.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 24 Feb 2010 16:16:16 GMT</pubDate>
    <dc:creator>networkadmin</dc:creator>
    <dc:date>2010-02-24T16:16:16Z</dc:date>
    <item>
      <title>Creating Custom Applications - Dummies Guide?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/creating-custom-applications-dummies-guide/m-p/5406#M3972</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is there a dummies guide to creating custom application please?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a couple of "in-house" apps that always pass traffic on certain ports, always to/from a certain IP range, and I'm struggling to see how to put "something" in place that says "If this traffic is between source A and destination B and is on port XYZ it is CustomApp"?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Equally we have a couple of apps that need a stupid amount combination of ports/port-ranges open.&amp;nbsp; AIUI with a custom app you can only specify one port at a time?&amp;nbsp; How would this work if your source and destination are always the same but the ports could be one of several hundred i.e. the app uses port(s) 7000-76500 TCP/UDP?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Essentially I just want to not have "Unknown TCP/UDP" in the ACC for traffic matching those policies if possible.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Feb 2010 16:16:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/creating-custom-applications-dummies-guide/m-p/5406#M3972</guid>
      <dc:creator>networkadmin</dc:creator>
      <dc:date>2010-02-24T16:16:16Z</dc:date>
    </item>
    <item>
      <title>Re: Creating Custom Applications - Dummies Guide?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/creating-custom-applications-dummies-guide/m-p/5407#M3973</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The way to do this is to use Application Override rules. You can specify a source/destination address as well as a destination port or port range and map that to a specific application. In your example you would create a custom app (don't work about the port definition or any signatures) called CustomApp and map all traffic from you given src/dest on ports 7000-76500 to this application using an Application Override rule.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Feb 2010 16:33:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/creating-custom-applications-dummies-guide/m-p/5407#M3973</guid>
      <dc:creator>mjacobsen</dc:creator>
      <dc:date>2010-02-24T16:33:09Z</dc:date>
    </item>
    <item>
      <title>Re: Creating Custom Applications - Dummies Guide?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/creating-custom-applications-dummies-guide/m-p/5408#M3974</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Brilliant thanks Mike - I was coming at it from the wrong angle and assuming I'd need to know a lot of low-level detail to create the custom app, so all I've done is fill in the new app detail using the basics and used the starting TCP port as it won't let me specify a range in an app.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Right now this isn't an issue, but is there any way to define an override against a URL/set of URLs vs. a "raw" IP address or network?&amp;nbsp; It's something I can foresee for a couple of things we may be using.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Feb 2010 17:35:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/creating-custom-applications-dummies-guide/m-p/5408#M3974</guid>
      <dc:creator>networkadmin</dc:creator>
      <dc:date>2010-02-24T17:35:06Z</dc:date>
    </item>
    <item>
      <title>Re: Creating Custom Applications - Dummies Guide?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/creating-custom-applications-dummies-guide/m-p/5409#M3975</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hmm I spoke a little too soon - the rule works and classifies traffic, but on the ACC page all I have for "risk" is a little white square - there is no risk rating listed, even though on the objects/applications it shows with the expected green "1" icon.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Why might this be please?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried changing the risk to "2" just to see if it's some weird caching/rendering thing but it does it consistently in Chrome/Firefox/IE, just a white box.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I look at the properties of the white box it's "risk_0.gif" though when I click the application to break down the ACC view it definitely shows with whatever risk level I give it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Feb 2010 19:35:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/creating-custom-applications-dummies-guide/m-p/5409#M3975</guid>
      <dc:creator>networkadmin</dc:creator>
      <dc:date>2010-02-24T19:35:53Z</dc:date>
    </item>
    <item>
      <title>Re: Creating Custom Applications - Dummies Guide?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/creating-custom-applications-dummies-guide/m-p/5410#M3976</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is a known bug. It has been addressed in the upcoming PAN-OS 3.1. It should not effect the behavior of the application, only the displayed risk in ACC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Feb 2010 21:55:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/creating-custom-applications-dummies-guide/m-p/5410#M3976</guid>
      <dc:creator>mjacobsen</dc:creator>
      <dc:date>2010-02-24T21:55:42Z</dc:date>
    </item>
  </channel>
</rss>

