<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Applications On Non-Standard Ports in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/applications-on-non-standard-ports/m-p/73444#M41433</link>
    <description>&lt;P&gt;Thanks.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That's pretty much the solution I've used. I just wanted to know if I was missing something obvious.&lt;/P&gt;</description>
    <pubDate>Wed, 24 Feb 2016 16:02:00 GMT</pubDate>
    <dc:creator>MikeMeredith</dc:creator>
    <dc:date>2016-02-24T16:02:00Z</dc:date>
    <item>
      <title>Applications On Non-Standard Ports</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/applications-on-non-standard-ports/m-p/73421#M41428</link>
      <description>&lt;P&gt;It's perfectly possible I'm being unusually dumb here, but I can't see an elegant way of allowing application usage on non-standard ports - for example ssh on tcp/32777. The obvious way of doing it is to allow a rule that allows appid:ssh on service:ssh-ports (being a service group consisting of tcp/22 and tcp/32777).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That works fine, but is rather clumsy when you have a rule that has thousands of applications with service set to "application default" (you end up with dozens of rules to cope with all the non-standard ports).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I looked to see if you can change the 'application-default' for an application to add custom port numbers.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've tried creating a custom application which is tcp/32777 and a parent application of 'ssh'. Doesn't seem to work.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Am I missing something obvious? Or am I not trying hard enough with the custom application rule?&lt;/P&gt;</description>
      <pubDate>Wed, 24 Feb 2016 11:50:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/applications-on-non-standard-ports/m-p/73421#M41428</guid>
      <dc:creator>MikeMeredith</dc:creator>
      <dc:date>2016-02-24T11:50:05Z</dc:date>
    </item>
    <item>
      <title>Re: Applications On Non-Standard Ports</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/applications-on-non-standard-ports/m-p/73422#M41429</link>
      <description>&lt;P&gt;Hi Mike,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I think the best thing to do in this situation, if you want to allow non-standard ports, is to create separate rules for them so you allow SSH &amp;amp; service tcp 32777. You can apply content-ID &amp;amp; user-ID to make sure the traffic isn't dodgy (as long as decryption is enabled for SSH) and lock down the users so that only the required people can use this port for SSH.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;hope this helps!&lt;/P&gt;
&lt;P&gt;Ben&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Feb 2016 12:05:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/applications-on-non-standard-ports/m-p/73422#M41429</guid>
      <dc:creator>bmorris1</dc:creator>
      <dc:date>2016-02-24T12:05:09Z</dc:date>
    </item>
    <item>
      <title>Re: Applications On Non-Standard Ports</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/applications-on-non-standard-ports/m-p/73437#M41430</link>
      <description>&lt;P&gt;&amp;gt; I agree with bmorris1 and I don't think you will be able to add the custom app as a part of application-default group&lt;/P&gt;</description>
      <pubDate>Wed, 24 Feb 2016 15:14:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/applications-on-non-standard-ports/m-p/73437#M41430</guid>
      <dc:creator>vkalal</dc:creator>
      <dc:date>2016-02-24T15:14:57Z</dc:date>
    </item>
    <item>
      <title>Re: Applications On Non-Standard Ports</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/applications-on-non-standard-ports/m-p/73444#M41433</link>
      <description>&lt;P&gt;Thanks.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That's pretty much the solution I've used. I just wanted to know if I was missing something obvious.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Feb 2016 16:02:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/applications-on-non-standard-ports/m-p/73444#M41433</guid>
      <dc:creator>MikeMeredith</dc:creator>
      <dc:date>2016-02-24T16:02:00Z</dc:date>
    </item>
  </channel>
</rss>

